Bring Your Own Device policies sit in an awkward middle space for most Australian small and mid-sized businesses. Banning personal devices entirely is impractical, as staff will use their phones for work email regardless, and asking them to carry two devices is rarely realistic. Allowing everything without controls is risky enough that any audit will surface it as a major finding. The sensible middle ground takes some up-front work, but is not complicated.
Start with the actual risks, not the device list
Most BYOD policies fail because they are written backwards: they list approved devices and operating system versions, then ask staff to comply. Within months the list is stale, the IT team is exhausted from chasing exceptions, and no one is actually safer. A better starting point is to write down what you are trying to prevent.
For a typical Sydney SMB, the real risks are personal devices retaining business data after someone leaves, personal devices being used to authenticate without MFA, personal devices joining the office network and being treated as trusted, and personal devices receiving sensitive information by email or chat that then sits unencrypted on the device. A policy that addresses those four risks is more useful than one that tries to enforce specific operating system versions.
The minimum viable BYOD policy
For a business in the 10 to 100 person range, a workable BYOD policy comes down to a handful of practical controls.
Identity is the perimeter, not the device. Require MFA on every work account from every device, personal or not. This single control eliminates the most common BYOD risk: a personal phone with cached credentials being used to access company data from anywhere.
Use conditional access rather than device bans. Microsoft 365 and Google Workspace both support policies that allow personal devices to access mail and calendar, but block access to file storage unless the device is enrolled in a management profile. This is far more enforceable than a blanket no-personal-devices rule.
Enrol the apps, not the devices. App-level management (sometimes called MAM rather than MDM) lets you control the work mail, work files and work chat on a staff member’s phone without touching their personal photos or messages. Staff are far more willing to accept this than full device management.
Have a remote wipe path. When someone leaves, you should be able to remove company data from their personal device with one action. App-level management makes this clean: their personal data stays, the work data goes.
Segregate the office network. Personal phones should never be joining the same Wi-Fi network as your servers or office printers. A separate guest or BYOD SSID is a five-minute configuration change that fixes a surprising amount of lateral risk.
The voice and SMS edge case
BYOD policies almost always handle email, files and chat well and miss the voice channel entirely. Staff take work calls on their personal mobiles, route texts to customers through their personal numbers, and end up with the business’s customer relationships sitting in the personal contact list. Some businesses are now using AI voice agents and dedicated business numbers as a way to keep the customer-facing voice channel inside the business rather than on a personal SIM, which makes the wider BYOD question much simpler.
Acceptable use, written like a human
A BYOD acceptable use statement that staff will actually read is a single page, not ten. Cover the basics: what the business can see, what it cannot, what happens when you leave, what happens if the device is lost or stolen. Avoid legalese where you can. The signature on a clear one-pager is worth more than initials on a document no one finishes.
Review every twelve months
The fastest-changing piece of any BYOD policy is the platform side, not the staff side. Microsoft and Google quietly add new conditional access options every quarter, and an annual review of what is available will usually let you simplify your policy rather than complicate it. Pencil it into the IT calendar the same way you would patching or backups.
The bottom line
Modern BYOD does not need to be a fight between IT and staff. With identity, conditional access and app-level management, you can get most of the safety of corporate devices without the cost or the friction. The policy that sticks is the one staff understand and the one IT can actually enforce, which usually means short, modern, and reviewed once a year.