Breaking
Ransomware Defense

CIOs struggle with unmanaged device risks

By Ethan Blackwell 5 min read
CIOs struggle with unmanaged device risks - unmanaged device risks

A mid-sized financial services firm’s regional sales manager used a personal phone to log into the company’s customer relationship management system for nearly a year. The device was never enrolled in mobile device management, leaving IT blind to its security status. No formal exception had been granted, but the employee followed the fastest available path rather than the official one.

How Unmanaged Devices Evade IT Visibility

This example illustrates the central challenge of bring-your-own-device programs in modern workplaces. Hybrid work arrangements and cloud-based applications have erased the distinction between managed and unmanaged endpoints. Companies no longer question whether employees bring personal devices to work—they now face the harder question of whether their policies actually reflect real-world behavior.

Traditional BYOD frameworks assumed employees would register devices, accept security requirements, and gain controlled access. Workers might check email on one device, use a different phone for collaboration tools, or access cloud services from a home computer—none of which appear on IT’s radar. Contractors may use their own computers. Executives may carry a second phone that never went through the normal IT process. An employee may also replace a phone and restore work apps from a backup before IT even knows the device has changed. A company could enforce strict BYOD rules while still missing critical details about the devices handling sensitive data.

Why Employee Workarounds Outpace Security Policies

An approved personal device does not equal a secure one. Both can reach the same business systems if access controls focus only on user credentials rather than device health.

Employee behavior stems from practicality, not malice. Personal devices offer convenience—no setup delays, immediate availability, and minimal friction. When a company device is in repair, a home laptop becomes the obvious alternative. Contractors often require temporary access, and cloud applications demand only a username, password, and multi-factor authentication to grant entry. The approved route can take longer. It may involve device enrollment, a support ticket, software setup, security checks, or approval from IT. If the secure route is harder than the workaround, some employees will choose the workaround.

Cloud Access Ignores Device Security Risks

Cloud computing has worsened the problem. Legacy on-premise systems allowed IT to define clear security boundaries. Today’s internet-accessible CRMs, document platforms, and analytics tools rely on identity verification but ignore device security. Multi-factor authentication confirms a user’s identity, but it does nothing to assess whether the device itself is compromised or outdated.

Related: Android Tightens Data Usage Around AI Memory Crunch

Organizations must shift from asking who is accessing systems to asking what device is being used. Security policies must evaluate not just credentials but also device enrollment status, operating system updates, installed security tools, and permitted applications. The goal is transforming BYOD from a policy document into an enforceable access control mechanism.

Enforcing Device-Based Access Controls

For high-sensitivity systems, personal devices should be enrolled in mobile device management or endpoint protection platforms. Conditional access policies can block untrusted devices even when credentials are valid. Companies should enforce standards such as full-disk encryption, supported operating system versions, automated updates, and clear separation between work and personal data. Authentication strength must also improve—strong multi-factor authentication should be mandatory, while passkeys or hardware security keys provide additional protection against phishing attacks. Zero Trust Network Access can further refine permissions based on user context, device status, and application risk.

Regular access audits are essential. IT teams must track not only which users have permissions but also which devices are utilizing them. A policy without technical enforcement remains ineffective. However, implementing these controls takes time. Large organizations must reconcile contractors, legacy systems, regional variations, and acquisitions that operate at different speeds. Employees continue working through home networks, hotels, client offices, and airports during transitions.

For those relying on unmanaged connections, a free VPN can provide encrypted communication while broader controls are deployed. Yet VPNs offer limited protection—they do not verify device security, enable remote data wipes, or manage access to sensitive cloud applications. Much modern web traffic is already secured via HTTPS, reducing the VPN’s value. Still, encryption helps mitigate risks when employees connect from uncontrolled networks, though it cannot replace full device management.

Balancing Convenience with Security Compliance

The core lesson from BYOD is not that employees cannot be trusted but that security must adapt to actual work patterns. If obtaining an approved device takes days while accessing a cloud app on a personal device takes seconds, policy will always lose. Chief information officers can narrow this gap by streamlining device enrollment, automating security checks, applying consistent access rules, and providing clear backup options when primary devices fail. The ultimate objective remains clear: verified users, known devices, appropriate access levels, and protected connections.

BYOD must be treated as an ongoing access management challenge rather than a static policy. The divide between managed and unmanaged devices will not vanish immediately, but each step toward enforcement strengthens control over what companies cannot fully oversee. The hidden costs of ignoring compliance rules grow over time, making proactive adjustments essential for long-term security.

Ethan Blackwell

Leave a Reply

Your email address will not be published. Required fields are marked *