Why Your Organisation Needs a Mobile Phone Policy Now

That lack of a mobile phone policy is a security issue or data breach waiting to happen.

If you run a business or maybe a charity, the chances are your team is already using mobile phones for work: checking emails, taking calls, maybe even accessing shared files or using chat apps. For many organisations this has happened gradually and informally, without ever being written down as a policy.

That lack of a decent mobile phone policy is a security issue or data breach waiting to happen.

A mobile phone – whether it’s company-issued or an employee’s own device – holds the same kind of data your office computers do: emails, contacts, messages, photos, and increasingly, access to shared drives, banking, and business apps. Under UK GDPR, all of that counts as data your business is responsible for, regardless of who owns the handset it sits on.

The problem is that mobile devices rarely get the same attention as a desktop PC or laptop. There’s often no antivirus, no enforced screen lock, no encryption check, and no way to remotely remove company data if the phone is lost, stolen, or the employee leaves. In effect, many businesses are running a second, unmanaged IT estate – and don’t realise it until something goes wrong.

What “Something Going Wrong” Looks Like

The numbers here are worth taking seriously:

  • Businesses without a formal mobile device policy experience roughly twice the rate of data breaches originating from mobile devices, compared to those with one in place.
  • Over 60% of network breaches are linked to a lost or stolen device – a single missing phone with the wrong access can be enough to put an entire business at risk, not just the individual it belonged to.
  • Under UK GDPR, a lost or stolen phone with no lock and no encryption is treated as a data breach requiring notification to the ICO within 72 hours. Fines for serious data protection failures can run into the millions, though most small businesses facing a well-handled first incident see far more modest consequences – the bigger cost is usually the disruption and loss of client trust.

None of this requires a sophisticated attack. A phishing link clicked on a phone that isn’t kept up to date, a device left in a taxi, or a leaver whose phone was never reset – any of these can be the starting point.

What a Mobile Phone Policy Actually Covers

A good policy doesn’t need to be complicated, but it should answer a few key questions:

  • Who can access what? Not every role needs mobile access to every system a policy can be specific about which job roles or individuals are permitted business data access from a phone.
  • Whose device is it? Personal phones (BYOD), company-issued devices, or a mix -each carries different obligations and options.
  • What controls are in place? As a minimum: a PIN or biometric lock, up-to-date software, and multi-factor authentication on business accounts. Beyond that, Mobile Device Management (MDM) can enforce these automatically and allow a lost device to be wiped remotely though this needs to be balanced carefully against employee privacy.
  • What happens when someone leaves, or a phone is lost? Without a clear process, there’s often no way to confirm business data has actually been removed.

The Good News

None of this means banning mobile phones from your organisation, or forcing everyone onto organisation-issued handsets. Most organisations find a proportionate middle ground. As long as you set clear expectations, ensure a few sensible technical controls are followed, and plan for the times when something goes wrong, you’ll be in a much stronger position to deal with what happens.

The point of a policy isn’t to slow your team down. It’s to make sure that when something does happen (and eventually, something will) it’s a minor inconvenience rather than a reportable breach.

Get this content straight to your inbox on the third Thursday of every month.

We won't spam you.
See our privacy policy for details.

Scroll to Top