forumNew topic

It's risky for employees to open company data on their personal computers, how to set up a protocol

OOnur K***Expert
Job title
R&D Manager
Joined
Aug 2023
Message
142
#1

We have a remote team. They open company email and customer files on their personal laptops. This seems very risky but I can't ban it.

How do you configure a device policy? Can company data be accessed on personal devices?

Are measures like antivirus and VPN enough?

EErcanMember
Job title
Accountant
Joined
Sep 2024
Message
92
Most Helpful#2

Opening company data on personal devices is risky. Policy: Providing company-owned devices is ideal, but if you have to use 'BYOD' (Bring Your Own Device), the rules must be strict.

Protocol: VPN mandatory, antivirus must be installed, company files must be kept encrypted.

Have them sign a written agreement — the employee must accept in writing that they 'understand these risks'.

OOya K***ExpertCommunity member
Joined
Jun 2024
Message
96
#3

were in the same boat we gave out laptops for remote work but they still use personal devices and tbh we relaxed a bit with VPN

GGökhan D***ExpertCommunity member
Joined
Jan 2023
Message
316
#4

BYOD policy: 1. Mandatory VPN 2. Antivirus installed 3. OS updated 4. Encrypt files 5. Wipe all data upon resignation

HHilal B***Veteran
Job title
Graphic Designer
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Dec 2023
Message
17
#5

Use MDM (Mobile Device Management) software. You can remotely wipe company data. Keep passwords in BitWarden.

OOkan T***VeteranCommunity member
Joined
Jan 2023
Message
7
#6

keeping data on personal devices is dangerous... if an employee loses their laptop the data is gone. big risk

DDeniz D***Member
Job title
Agency Founder
Sector
Security services
Organization type
40-person manufacturing company
Joined
Mar 2023
Message
122
#7

Do you recommend any other security tools besides VPN?

FFiliz Ç***Member
Job title
General coordinator
Sector
Leather
Organization type
medium-sized business
Joined
Jul 2025
Message
13
#8

If you use BYOD, a written policy is mandatory. The company cannot be held liable for data loss from an employee's personal device.

PPolat G***Member
Job title
Chief Technology Officer
Sector
Printing
Organization type
8-person team
Joined
Aug 2023
Message
275
#9

Generally correct, but one part is missing. When making a decision, first look at what data you have on hand.

Proven by experience.

KKaan D***Member
Job title
Secretary
Sector
Education
Organization type
workshop
Joined
Jul 2024
Message
2
#10

Sorry, but this doesn't apply in every case. If it's your first time, start small; scaling comes later.

Taking measures without an inventory leaves doors you haven't seen open. Just leaving this note, it might be useful.

EElif B***Member
Job title
Store associate
Sector
Chemistry
Organization type
workshop
Joined
May 2023
Message
55

Doki · SEO consulting · 2024

#11

Thanks for writing this, that's the right way. Hasty decisions become decisions you have to fix six months later.

Hope this helps.

PPolat Y***ExpertCommunity member
Joined
May 2023
Message
54
#12

Following.

AAycan P***MemberCommunity member
Joined
Jan 2024
Message
260
#13

Let me summarize the topic, since several different answers were given. Everyone rushing into employee device policy gets stuck at the same point.

Good luck with that.

KKübra A***Member
Job title
Technical service technician
Sector
Automotive aftermarket
Organization type
120-person company
Joined
Aug 2025
Message
71

Doki · Phishing awareness training · 2026

#14

Thanks, this was very helpful. If you don't write this down from the start, it leads to arguments later.

That's all, sorry if I went on too long.

DDoki ekibiDoki team
Job title
Official account
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Mar 2023
Message
310
#15

The opposite happened to me, that's why I'm writing. An automated scan report is not the same as a penetration test.

If you post the result here, it will help others too.

LLevent U***MemberCommunity member
Joined
Mar 2022
Message
270
#16

Here's how it went for us. If you don't write this down from the start, it leads to arguments later.

If it's your first time, start small; scaling comes later. This is my opinion I'm not claiming it's absolute truth.

İİbrahim Y***Member
Job title
Marketing manager
Sector
Electrical-electronics
Organization type
20-person company
Joined
Nov 2023
Message
95
#17

Good call starting this thread. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

I'm also curious if anyone does it differently.

SSelin Y***Veteran
Job title
Front office accounting
Sector
Real estate
Organization type
120-person company
Joined
Sep 2024
Message
111
#18

There's also a measurement aspect to this. The answer varies greatly by industry; there is no one-size-fits-all rule.

If you post the result here it will help others too.

HHavva K***Member
Job title
Content Editor
Sector
Packaging
Organization type
workshop
Joined
Oct 2022
Message
2
#19

don't miss this: Tring to do this alone is the most expensive way.

the harder it is to rveerse a decision the slower you should make it. that's all sorry if I went on too long.

MMert E***MemberCommunity member
Joined
Sep 2024
Message
28
#20

i've been dealing with this for a long time. tbh having backups accessible on the same network and with the same identity makes them part of the target.

if you have questions wriet them; I'll answer as best I can.

Reply