← Back to list

Your Staff’s Phones Are in Scope: BYOD and Mobile Devices Under Cyber Essentials (and CE Plus)

Most small and medium‑sized enterprises (SMEs) think Cyber Essentials is about laptops, servers and maybe the firewall in a cupboard. Then…

Laurentiu Barbu · 2025-12-17 00:07 · 0 claps · 5.0 min read
#byod #cyber-essentials #cybersecurity #small-business #medium-business
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

Your Staff’s Phones Are in Scope: BYOD and Mobile Devices Under Cyber Essentials (and CE Plus)

Most small and medium‑sized enterprises (SMEs) think Cyber Essentials is about laptops, servers and maybe the firewall in a cupboard. Then Cyber Essentials Plus day arrives, the assessor looks at Microsoft 365 sign‑ins and device data, and suddenly, half the staff’s personal laptops and phones are in the assessor’s sight and, worse, many are non‑compliant. This is one of the most common and painful ways otherwise organised organisations stumble.

This article explains, in plain English, why BYOD (bring your own device) — including user‑owned PCs and mobiles— matters so much for Cyber Essentials, what the scheme actually expects, and how to fix the problem before an assessment forces you to redo everything.

Why BYOD devices are in scope

Cyber Essentials applies to any device that connects to the internet within your defined boundary and is used to access organisational data or services. That covers:

  • Company‑owned desktops, laptops, tablets and phones
  • User‑owned desktops and laptops used for work
  • User‑owned smartphones and tablets used for work email, Teams, VPNs or SaaS apps

If someone uses their home PC to log into Microsoft 365, or their own iPhone to read work email, those devices are in‑scope end‑user devices under Cyber Essentials, regardless of who owns them or who pays the bill. Pretending they “don’t count” just means the scheme’s controls are not being applied where they should be.

What Cyber Essentials expects from BYOD laptops and mobiles

The Cyber Essentials requirements do not demand bank‑level hardening, but they do require a sensible baseline across all in‑scope devices.

In practice, that means for both company‑owned and user‑owned devices:

  • Supported operating systems and updates — Windows, macOS, iOS and Android must be on supported versions and receive security updates in line with the scheme’s patching timelines (maximum 14 days).

  • Secure configuration — no default accounts or passwords, unnecessary services removed or disabled, and basic hardening applied.
  • User access control — unique user accounts, no casual sharing of logins, and limited local admin rights on PCs, and most importantly, no privilege elevation.
  • Malware protection — up‑to‑date anti‑malware or application control on laptops and desktops; mobiles must not be rooted or jailbroken and should install apps only from official stores.
  • Screen lock and encryption — a PIN, password, or biometric unlock on mobiles; encryption enabled on PCs and laptops (for example, BitLocker or FileVault) so lost devices do not expose data.

If you use Microsoft 365 or similar, the easiest way to enforce many of these controls on both corporate and personal devices is via device or application management (for example, Intune policies and app protection).

What CE Plus actually checks

For Cyber Essentials Plus, the assessor doesn’t just trust the questionnaire; they verify controls through testing and sampling. They are not running a full “Wi‑Fi war‑drive”, but they will look at:

  • Device and sign‑in information from Microsoft 365 / Entra ID or other identity platforms
  • Endpoint management or MDM dashboards showing which PCs and mobiles are enrolled and compliant

If those logs show user‑owned laptops or phones accessing corporate services, but those devices were left out of your Cyber Essentials scope, the assessor cannot simply “expand” the scope and carry on. The application is technically incorrect, and the right outcome is to redo Cyber Essentials with the proper scope and controls applied.

That is why so many organisations feel blindsided: the devices have been there all along, but nobody treated them as part of the estate.

The most common BYOD failures

Across SMEs, the same issues appear repeatedly:

  • “We forgot BYOD” on the asset list — corporate laptops and servers are listed, but there is no mention of home PCs, personal MacBooks, tablets or phones, even though staff use them daily for work.
  • Unmanaged home PCs and phones — users access 365 from personal devices with no disk encryption, weak or reused passwords, and outdated operating systems.
  • No joiners/leavers process for BYOD — ex‑employees keep access to email and files on personal devices for months because nothing forces removal.
  • “If staff own it, it’s not our problem” — ownership of the hardware does not remove your responsibility for protecting the organisation’s data on that hardware.

These issues don’t just threaten Cyber Essentials; they show up in actual incidents and insurance discussions.

A simple BYOD policy that passes Cyber Essentials

You don’t have to ban BYOD completely. Instead, set a clear, realistic line: if a device is used for work, it must meet the same minimum standard as a company device.

At a minimum, your BYOD policy should state:

  • Scope — BYOD covers user‑owned laptops, desktops, tablets and phones used to access work email, files or systems.
  • Eligibility — only devices running supported versions of Windows, macOS, iOS or Android with security updates enabled may be used.
  • Security baseline — screen lock and encryption enabled, no jailbreaking/rooting, unique logins, and anti‑malware on PCs and laptops.
  • Managed access — work services must be accessed through managed devices or managed apps (for example, Intune‑enrolled PCs and Outlook with app protection rules), so access can be revoked and data wiped without touching personal content.
  • Right to remove access — if a device is lost or a user leaves, the organisation may wipe work data or block the device from connecting.
  • Opt‑out — staff who don’t want BYOD should be offered a company‑owned device or another way to work.

This keeps control over corporate data while being honest and transparent with staff about what you will and will not do to their own devices.

How to fix BYOD before your next assessment

If you don’t have any of this in place yet, here is a practical order of attack:

  1. Inventory BYOD devices Use identity logs (for example, Entra ID sign‑ins) and a short staff survey to identify every personal laptop, desktop, tablet and phone used for work.
  2. Decide where BYOD is acceptable For higher‑risk roles (directors, finance, admins), you may choose company‑owned, fully managed devices only. For others, BYOD with controls might be acceptable.
  3. Roll out management and controls
  • Enrol PCs and laptops into device management (Intune or equivalent) with encryption and patching enforced.
  • Apply app‑level protection on mobiles and tablets for email and file access.

Other ways:

  1. Publish and explain the BYOD policy to your users Use plain English; explain why this protects both the organisation and users’ own data, and give people time and support to comply.
  2. Update your asset register and Cyber Essentials scope Add BYOD devices to your asset list, including OS edition and version and management status, and ensure your next Cyber Essentials submission explicitly includes them.

With that in place, you’ll be in a much stronger position for both Cyber Essentials and CE Plus, and far less likely to see your assessment derailed by “mystery” home PCs and mobiles.

References:


메타데이터
post_id
a585d87bbcf4
slug
your-staffs-phones-are-in-scope-byod-and-mobile-devices-under-cyber-essentials-and-ce-plus-a585d87bbcf4
url
https://medium.com/@LaurentiuBarbu/your-staffs-phones-are-in-scope-byod-and-mobile-devices-under-cyber-essentials-and-ce-plus-a585d87bbcf4
canonical_url
https://medium.com/@LaurentiuBarbu/your-staffs-phones-are-in-scope-byod-and-mobile-devices-under-cyber-essentials-and-ce-plus-a585d87bbcf4
author_url
https://medium.com/@LaurentiuBarbu
status
ok
fetched_at
2026-06-16 19:09:56