Originally adapted from The Technology Press. Substantially reviewed and updated 15 September 2026.
Business access travels with the phone
A phone may hold email, files and authentication access. Its security needs to fit the way people actually work, including whether the device belongs to the company or the employee.
Agree the management boundary before enrolment. Staff should understand what IT can see and which remote actions are authorised. A personal phone is not permission to erase someone’s personal information.

Use a supported, appropriately configured phone.
Company and personal ownership differControl how work information is accessed.
Permissions and application controls matterKnow what happens if it is lost.
A prompt report helpsPractical checkpoints, not a guarantee of security or compliance.
What to check
1–3. Define ownership, updates and locking
Set a clear policy and use supported software and a strong screen lock.
What to check
Make the required configuration understandable and review exceptions with IT.
4–6. Control apps, access and sharing
Use reputable apps, proportionate permissions and approved work access.
What to check
Mobile device or application management can support the design; available controls depend on platform, enrolment and licensing.
7–9. Prepare for loss, scams and departure
Give staff a reporting route and review access when their role ends.
What to check
Unexpected sign-in requests need independent verification. Lost-device response should consider accounts and work data, not only locating the handset.
Sources & further reading
Make the next step practical
Talk to ITFR about your business, priorities and the controls that fit.









