If your team uses personal phones to check work email, access cloud files, or text clients, you have a BYOD situation whether you've named it that or not. Bring Your Own Device is the norm for small businesses—it saves money and nobody wants to carry two phones—but it also means your business data is sitting on hardware you don't control, mixed in with personal apps, personal accounts, and whatever risky Wi-Fi that phone connected to last Tuesday.
The threat here isn't abstract. AI-generated phishing texts (smishing) are now indistinguishable from real messages. A single tap on the wrong link, on a phone with no protections in place, can hand an attacker access to your Google Workspace, your QuickBooks, or your client files. Here's how to close the most common gaps.
Start With a Written BYOD Policy (Even a One-Pager)
Before touching any settings, write down what you expect. A policy doesn't have to be a legal document. A shared Google Doc works. Cover:
- Which apps are approved for work data (email, Slack, cloud storage)
- What happens when someone leaves—how work accounts get removed from their device
- A requirement that the phone has a screen lock and stays updated
- Agreement that you can remotely wipe work accounts (not the whole phone) if the device is lost
Having this in writing protects you legally and sets clear expectations before a problem happens.
Enforce Screen Locks and OS Updates
This sounds basic because it is—and it's still the gap that causes real breaches. Ask everyone on your team to confirm:
- Screen lock is enabled with a PIN of at least 6 digits, or biometrics backed by a strong PIN fallback
- Auto-lock is set to 30 seconds or less when the phone is idle
- Automatic OS updates are turned on — both iOS and Android push security patches regularly, and an unpatched phone is a known-vulnerability phone
If you're using Google Workspace or Microsoft 365, both platforms let you enforce basic device policies from the admin console—including requiring a screen lock before a work account will sync. Turn that on. It costs nothing extra and takes about ten minutes to configure.
Separate Work Apps from Personal Apps
The biggest risk with BYOD is data bleed: work files saved to a personal iCloud, client emails forwarded to a personal Gmail, that sort of thing. A few ways to reduce it:
- Use managed apps where possible. Google Workspace and Microsoft 365 both have mobile app management features that can restrict copy-paste between work and personal apps.
- Disable personal cloud backup for work apps. On iPhone, check Settings → [Your Name] → iCloud and make sure work apps like Outlook or Slack aren't backing up to a personal iCloud account.
- Train your team to use the official app, not a browser, for work platforms. Official apps respect the security policies you've set; a browser session often doesn't.
Lock Down What Happens If a Phone Is Lost
Lost phones are a near-certainty over the life of a small business. Have a plan before it happens.
For Apple devices: Make sure Find My is enabled. From your end, if someone on your team uses Google Workspace, you can remotely sign their work account out from the Admin Console under Devices—without wiping their personal photos or apps.
For Android devices: Find My Device should be enabled in Settings → Security. Same story with Google Workspace admin: you can remove the work account remotely.
Set the expectation now: if a phone is lost or stolen, the person contacts you within the hour so you can revoke access. Every hour of delay is an hour an attacker may have to pivot from that phone into your business accounts.
Use Multi-Factor Authentication on Every Work Account
If I could enforce only one thing across every small business in DFW, it would be this. MFA means that even if an attacker steals a password from a phishing text, they still can't get into the account without the second factor.
- Use an authenticator app (Google Authenticator, Authy, or Microsoft Authenticator) rather than SMS codes—SMS can be intercepted or SIM-swapped
- Enable MFA on email first, then cloud storage, then any financial or billing platforms
- If someone on your team resists, show them what account takeover looks like and what it costs—usually that's enough
Watch Out for AI-Powered Smishing
This is the threat that's gotten dramatically worse in the last two years. Attackers are now using AI to write phishing texts that are grammatically perfect, contextually relevant, and sometimes personalized with real details scraped from LinkedIn or public records. They'll impersonate a vendor, a bank, or even you as the business owner.
Train your team to:
- Never tap a link in a text from an unknown number, even if the message looks urgent
- Call the sender directly using a known number (not one in the text) if a message seems off
- Be especially suspicious of texts requesting login credentials, payment changes, or clicking to "verify" an account
This isn't paranoia—it's the current threat environment for businesses of every size.
A Realistic Minimum for a Small Team
If you're a 2-5 person operation and this all feels like a lot, here's the minimum I'd want in place before anything else:
- Screen lock + auto-updates on every phone that touches work data
- MFA on email and cloud storage
- Remote account wipe capability through your Google or Microsoft admin console
- A written understanding of what happens when someone leaves or loses their phone
That's it. Four things. They won't make you bulletproof, but they'll stop the most common attacks cold.
If you're not sure whether your team's devices meet even this baseline, I'm happy to do a quick review and help you set it up. Let's talk.

