TJ’s Story #001
“Just Use Your Own Laptop”
Unmanaged BYOD and VPN access
The company needed someone to work from home, so a personal laptop was approved in five minutes. It had no central management, no confirmed encryption, and no reliable patch record. The employee connected through the VPN, copied client files locally, and later lost the laptop in a café. The VPN had been protected; the device and the data on it had not. When the employee was terminated, the company disabled the VPN account—but could not prove whether client files, cached email, browser downloads, or synchronised folders had been removed from the personal laptop. An RMM agent or remote-wipe tool was not an answer: the laptop contained the employee’s private information, and the employee was not expected to let a third party control it.
Question for the Directors
If a personal device is used to reach company systems, who verifies that it is secure before access is granted—and how will the organisation verify deletion when the person leaves?
Potential Legal & Regulatory Implications
PDPA 2024 may be relevant where personal data is accessed or stored. Under the Companies Act 2016, directors should be able to explain how material operational and information risks were considered. The issue is not that BYOD is automatically unlawful; it is whether the organisation has defined, proportionate safeguards and can demonstrate them.
ISO/IEC 27001 best-practice controls
- Asset and access inventory with an assigned device owner
- MFA and least-privilege VPN or zero-trust access
- Company-controlled storage with no local synchronisation or downloads where possible
- Immediate termination checklist: revoke accounts, tokens, sessions, certificates, and shared links
- Clear BYOD prohibition or tightly limited exception that respects the employee’s private data and does not rely on RMM control
- Offboarding attestation and documented residual-risk decision where the device cannot be inspected
What should a reasonable director have done?
Prefer managed company devices, or keep company data in systems that can be revoked centrally without controlling the employee’s personal laptop. At termination, disable every access path, remove company-side access and shared links, recover any company equipment, request deletion of any agreed local copies without inspecting private data, and record what cannot be verified. If the organisation cannot prove that data is absent, it should not have placed that data on the personal device.