Bring Your Own Device: How to do it well
Updated NCSC guidance on enabling your staff to use their own devices for work.

filadendron via Getty Images
Thanks to COVID, remote working is not just more commonplace, it's an essential capability.
In many cases, BYOD may have been introduced as a short term measure to deal with the pandemic, but it has become apparent that BYOD is here to stay.
In light of this, we have updated our BYOD guidance to ensure you have the level of detail necessary to design, put in place, and manage, this potentially difficult IT set up.
Reality check
Before we go any further, I have to get this public service announcement out of the way.
You cannot do all your organisation's functions securely with just BYOD, no matter how well your solution may be configured.
If you’ve given BYOD users admin access to company resources, revoke that access immediately, then come back.
If you need to know why this is necessary, take a look at our Secure system administration guidance.
No matter what, it is important to note:
- New BYOD deployments require planning
- Existing BYOD deployments need review. Potentially, you need to undo some of those quick-fixes and start afresh
So, what is BYOD, exactly?
Bring Your Own Device (BYOD) is the idea of allowing employees to use their personally owned devices for work purposes.
'Work purposes' can mean anything from answering a few emails, through to managing critical services and hardware. This makes BYOD is a potentially complex topic.
The water is muddied further by the fact that the same technologies are often used to underpin BYOD and other flexible working solutions. The only difference is a matter of configuration.
Fortunately, our new guidance will help you understand how and when to adopt a BYOD policy. We also highlight where the choice of appropriate configurations will be essential.
Time is up for, “Just make it work"
When COVID-19 first hit, we were all faced with so many unknowns:
- How will my organisation function?
- How do I do my job?
- How long will things be like this?
Enter, BYOD – a knight in shining armour for organisations during COVID-19, even if rushing it into place meant it carrying a few 'flesh wounds'.
This 'just make it work' mentality is entirely understandable, but the time has come to deal with those wounds.
Fear-free BYOD
BYOD, in one form or another, has been around for some time. Like so many other technology solutions, it started out with a threat-less utopian dream:
- Work with the device of your choice to do what you need to, whenever and wherever.
The problem is, modern technology, marvellous though it may be, is not invulnerable to cyber attack. In fact, threats are pretty much ubiquitous.
Don't hide your phone under the sofa just yet though. BYOD solutions and approaches continue to evolve, with a lot of features and controls to help keep you and your organisation safe, whilst still enabling and empowering your employees. The catch is, BYOD needs to be done properly to be effective and secure.
Our new guidance provides an overview of the technical controls that are available for the different types of BYOD deployments, so you can get this right.
So what can you do with BYOD?
Rather unhelpfully this really depends on your organisation. Our guidance solves this riddle by equipping you with the right questions to ask:
- What do your employees need to do?
- What do your employees need to do from an office?
- What do your employees need to do from a device that the organisation requires full visibility and management of, and what can they do that doesn’t need this?
- What can your employees do that balances your need to protect data, and their privacy? After all, it’s their device.
Answering such questions will form the backbone of your BYOD response.
How to use the new guidance
The guidance provides a set of steps that will help you to decide:
- Is BYOD right for me?
- What type of BYOD deployment method is right for me?
- Do I need anything else?
- How do I use BYOD appropriately (and legally!)?
Each deployment method is explained. If you know or have been told what kind of BYOD you need, you can jump to the appropriate section, but each action will still be required.
If you do already have BYOD in place, reviewing the guidance will help you to assess if your deployment is appropriate for how you’re using it.
Is Zero Trust the next step?
Frequently, the concept of Zero Trust is brought up in conversations about BYOD deployments, but there are many misconceptions about what Zero Trust is. Our Zero Trust Principles and blogs will help you get to grips with this rapidly developing approach to network security.
Many of the technical controls for BYOD are similar to those used in Zero Trust Architecture, but there are important differences. Just having the BYOD mechanisms in place does not mean that you are automatically able to migrate to Zero Trust, or that any Zero Trust architecture you have in place is ready for BYOD deployments.
Zero Trust is maturing (quickly), but in its current state there are still challenges to overcome before it can be considered suitable for everything and everyone.
Remember, BYOD is complex, so take your time
BYOD can be a very empowering solution, but it can also be complex.
Take the time to read through the new guidance and use it to help you get it right. Be prepared for changes to the technology and your organisation.


