Metaluxo
← Insights

Startups & SMEs

Mobile Device Management for BYOD Companies

That balances security and privacy for BYOD.

The founder wants to save money. “Everyone has a phone. Let’s use them for work.” The security person winces. “BYOD is a nightmare.” Both are right.

At Metaluxo we design BYOD policies for SMEs. The goal is not to lock down every device. It is to protect company data on devices you do not own, without turning the company into Big Brother.


The BYOD risk landscape

Personal devices are inherently riskier than company-owned ones:

  • No guaranteed patch level
  • No guaranteed encryption
  • Family members may use the device
  • Apps from untrusted sources
  • No central visibility or control
  • Lost or stolen without reporting

But the cost savings are real. A company-provided phone costs £600–£1,000 per user plus monthly contracts. For a 20-person company, BYOD saves £15K–£25K annually.


The containerised approach

The modern solution is containerisation: work data lives in an encrypted, managed container. Personal data lives outside it.

What the container enforces:

  • PIN or biometric lock
  • Encryption
  • Prevent screen capture
  • Prevent copy-paste to personal apps
  • Remote wipe of container only (not the whole device)

What the container does not do:

  • Access personal photos, messages, or apps
  • Track location outside work hours
  • Monitor personal browsing
  • Wipe the whole device

Tools: Microsoft Intune app protection, Google Workspace mobile management, VMware Workspace ONE, MobileIron.


The minimum viable BYOD policy

For a company under 30 people, you do not need enterprise MDM. You need:

  1. A written BYOD policy — what is allowed, what is required, what happens if the device is lost
  2. App-level protection — work email and documents in managed apps only
  3. No local storage of sensitive data — work documents in cloud storage, not downloaded to the device
  4. Automatic lock — 5-minute timeout
  5. Reporting requirement — lost or stolen devices reported within 4 hours
  6. Exit procedure — work data and accounts removed when employment ends

What not to do

  • Full device management on personal phones. Employees will resist, and in some jurisdictions it may violate privacy law.
  • Mandating specific devices. This defeats the cost-saving purpose of BYOD.
  • Ignoring tablets and smartwatches. If work email syncs to an Apple Watch, that watch is in scope.
  • No offboarding process. When someone leaves, their personal device still has company data unless you remove it.

At Metaluxo we design BYOD policies for SMEs as part of our vCISO engagements. If your team uses personal devices for work and you are not sure how to secure them, book a free 30-minute consultation and we will design a proportionate policy.

Common questions

Can we require employees to install MDM on personal phones?

Yes, but only for work-related apps and data. Containerised MDM solutions keep work data separate from personal data. Full device wipe capabilities on personal devices raise legal and privacy concerns.

What is the minimum BYOD security requirement?

Device passcode, encrypted storage, automatic lock, remote wipe of work data, and separation of work and personal apps. No jailbroken or rooted devices.

Do we need MDM for a 10-person company?

Not necessarily. For very small teams, app-level controls (Microsoft Intune app protection, Google Workspace mobile management) may be sufficient and less intrusive.

Related reading

Send us a message
Message us Book now