
The MSP Security Gap
The personal phone had company email.
The scenario:
A sales rep at a regional distribution company set up work email on a personal phone the week they started, without ever going through a device enrollment process, because nobody at the company had asked them to.
Eighteen months later, that phone was lost at an airport. It had never been enrolled in a mobile device management tool, so there was no way to remotely wipe it.
How it unfolds:
Whoever found the phone eventually got past the lock screen, given enough time and a weak passcode.
Company email, calendar invites full of internal meeting details, and a password manager with autofill enabled were all sitting there unprotected. The company had no visibility into any of it, because the phone existed entirely outside their systems.
There was no way to confirm what had been accessed, and no record that this phone had access in the first place.
The warning signs:
Staff accessing company email or files from personal devices that were never formally enrolled or approved
No inventory of which personal devices have access to company data, or an inventory that is known to be out of date
A lost or stolen device report with no clear next step, because nobody owns the process for what happens when it does
Stop it:
Require any device accessing company email or data, personal or company-owned, to enroll in mobile device management before access is granted
Enable remote wipe capability as a condition of that access, communicated clearly to staff as protecting them as much as the company
Run a quarterly check of every device with active access against the list of enrolled devices, and revoke access for anything that doesn't match
-
P.S. BYOD policies usually exist on paper long before they exist in practice, and nobody notices the difference until a device is lost. A phone with company email on it is part of the attack surface whether or not anyone treated it that way. Security that covers endpoint and identity together, regardless of who owns the device, catches this before most MSPs find out the hard way.