Free it operations policy template

Free BYOD and Remote Work Policy Template for Small Business

A remote work and BYOD policy sets the security rules for working away from the office and for using personal phones or tablets for company email and apps. It covers which devices may be used, minimum device standards, home and public Wi-Fi, where company data may be stored, how fast lost devices must be reported and what happens to company data when someone leaves, so remote work does not become the easiest way into your network.

A remote work and bring your own device (BYOD) policy is a signed company policy that sets who may work remotely, which company-issued and personal devices may reach company data, the security standards those devices and home networks must meet, and how company data is protected, reported when lost and removed when an employee leaves.

Template version
v1.0.0
Last reviewed
September 27, 2026
Sections
18
Guided phases
5
Time to complete
About 5 minutes
Price
Free

Why does this policy matter now?

What is inside the Remote Work and BYOD Policy template?

18 sections, ending with the document control table and the legal notice every template carries. Select any section to jump to it in the sample below.

  1. 1. PurposeWhy the company sets rules for remote work and personal devices.
  2. 2. ScopeWho, which devices and which locations the policy covers.
  3. 3. Key TermsPlain-language definitions of the remote work and device terms used.
  4. 4. Remote Work Eligibility and WorkspaceWho may work remotely, the written arrangement, and the home workspace.
  5. 5. Company-Issued DevicesRules for company computers, phones and tablets used remotely.
  6. 6. Personal Devices (BYOD)Which personal devices may be used, how company data on them is protected, and the minimum standards.
  7. 7. Home Networks, Public Wi-Fi and Remote AccessHome router settings, public Wi-Fi and how to connect.
  8. 8. Storing, Sharing and Printing Company DataWhere company data may live, printing at home and rules for regulated data.
  9. 9. Physical Security and Confidential ConversationsProtecting screens, devices and conversations at home, in public and on video calls.
  10. 10. Travel and Working Away From HomeCarrying devices, international travel and working from another state or country.
  11. 11. Lost or Stolen Devices and Security IncidentsWhat to report, how fast, and what the company does next.
  12. 12. Privacy and MonitoringWhat the company can and cannot see on company and personal devices.
  13. 13. Expenses and Working HoursEquipment, personal phone reimbursement and after-hours work for hourly staff.
  14. 14. Leaving the CompanyRemoving access, returning equipment and removing company data from personal devices.
  15. 15. Exceptions and ViolationsHow exceptions are approved, consequences, and keeping the policy current.
  16. 16. Employee AcknowledgmentThe statement each employee signs and dates.
  17. 17. Document Control and Revision HistoryDocument ID, version, effective date, next review, owner and approver, plus a revision history table.
  18. 18. Template Notice and Legal DisclaimerThe starter-template disclaimer and the reminder to have qualified counsel review the policy.
Template changelog
  • v1.0.0, September 27, 2026

    • Initial release: remote work eligibility, company and personal devices, app protection and selective wipe, home and public networks, data storage and printing, travel, lost devices, privacy, expenses and working hours, offboarding and employee acknowledgment.

Read the full sample Remote Work and BYOD Policy

This sample uses the recommended answer to every question and a placeholder company name. Build your own version to put in your organization's name, owners and choices.

Sections in this policy
Sample[Company Name]

Remote Work and Bring Your Own Device Policy

Document ID
PDC-RWB-SAMPLE
Document version
1.0
Template version
v1.0.0
Effective date
September 27, 2026
Next review
September 27, 2027

1. Purpose

This policy sets the rules [Company Name] employees must follow when they work away from a company site and when they use any device, company-issued or personal, to reach company email, apps or data. Remote work and mobile devices make the business more flexible. They also move company information onto home networks, public Wi-Fi and personal phones, where it is easier to lose, steal or expose.

The goal is simple: work from anywhere the company approves, keep company data inside company systems, keep devices updated and locked, and report problems quickly. Following this policy supports the company in meeting its legal, contract and customer obligations and respects the privacy of personal devices.

If you are not sure whether something is allowed, stop and ask the IT Manager before you act.

2. Scope

Who it covers. This policy applies to all employees of [Company Name], and to temporary workers, interns and contractors who use company systems or handle company or customer information, whether they work remotely full time, on a hybrid schedule, while traveling, or only check email on a phone.

What it covers. It covers every device used to reach company email, chat, files or systems, including company-issued computers, phones and tablets, and any personal device the company allows. It covers every location outside a company site, including homes, hotels, vehicles, customer and supplier sites, and public places.

Other policies. This policy works alongside the company's information security, acceptable use, password and incident response policies, and its HR policies. When two rules conflict, follow the stricter rule. Where a law, regulation or customer contract is stricter than this policy, it applies instead.

Your rights. Nothing in this policy limits your right to discuss wages, hours or other working conditions with coworkers, or to report a possible violation of law to a government agency.

3. Key Terms

Remote work
Any company work done away from a company site, including full-time remote work, hybrid schedules, occasional work from home and work while traveling.
Company device
A computer, phone, tablet or other device the company owns or leases and issues to you.
Personal device (BYOD)
A phone, tablet or computer that you own, used for company work as this policy allows. BYOD stands for bring your own device.
Company data
Any information the company, its customers, suppliers or employees have not made public, in any form, including email, chat, files, photos and paper.
Approved storage
The company email, file storage and business systems the company provides and manages, such as its company cloud storage and shared drives.
App protection (MAM)
Protection applied to company apps, such as email and chat, that keeps company data inside those apps without the company managing the rest of the device.
Device management (MDM)
Enrolling a device in a company management system so the company can require security settings and install or remove company apps and data.
Selective wipe
Removing only company data, accounts and apps from a device, leaving personal apps, photos and messages untouched.
VPN or secure access app
Company software that creates a protected connection from your device to company systems, including zero trust network access tools.
Multi-factor authentication
Signing in with something beyond a password, such as an authenticator app prompt, a security key or a fingerprint.
Public Wi-Fi
Any wireless network the company or you do not control, including hotel, airport, coffee shop, conference and guest networks.

4. Remote Work Eligibility and Workspace

Eligibility. Remote and hybrid work is available only for roles the company has approved for it, and only after the employee and their manager agree the arrangement in writing, including the schedule, the primary work location and the equipment the company will provide.

A business arrangement. Remote work is a business arrangement, not an entitlement. The company may change or end an arrangement with reasonable notice, or immediately when business needs, performance, conduct or security require it. Requests to work remotely as a reasonable accommodation for a disability or other protected reason go through the company accommodation process rather than this section.

Your workspace. Work from the primary location in your arrangement, in a space that is safe, reasonably quiet and private enough that others cannot read your screen or hear confidential calls. Remote work is not a substitute for dependent care, and you must be able to focus on work during working hours.

Injuries. Report any injury that happens while you are working remotely to your manager and HR right away, the same as you would at a company site.

Training. You must complete the company remote work security training before you are given remote access or use a personal device for company work, and repeat it every year.

5. Company-Issued Devices

The company provides the computer each remote role needs, and all computer-based company work must be done on a company computer.

When you use a company device, you must:

  • Keep it for your own use only. Family members, friends and roommates must not use it, even briefly or for schoolwork.
  • Lock the screen whenever you step away. Devices are also set to lock automatically after 5 minutes or less.
  • Leave the security tools, encryption, firewall and updates the company installed turned on, and never try to disable or get around them.
  • Install software only from the company-approved list or with IT approval.
  • Allow security updates and restarts when prompted, and never postpone them for more than 3 days.
  • Connect the device to the internet and sign in at least every 14 days so it receives updates. Devices not seen for 30 days may be locked until IT checks them.
  • Do not plug in USB drives, chargers or other accessories from unknown sources, and do not store company data on personal USB drives.
  • Report damage, loss or strange behavior right away.

Personal use. Limited personal use of a company device by you is governed by the company's acceptable use rules. Do not store personal files on a company device. The company is not responsible for personal files left on it.

6. Personal Devices (BYOD)

What is allowed. You may use a personal phone or tablet for company email, chat and calendar, and for other mobile apps the company has approved, but only in the company versions of those apps, signed in with your company account, and only after the company protection described below is in place. Personal devices are optional. The company will provide the devices your role needs.

App protection. Company data on personal phones and tablets is protected inside the company apps rather than across the whole device. The protected apps may require their own PIN or fingerprint, encrypt company data, block copying or saving company data into personal apps and personal storage, and refuse to open on a device that is out of date, jailbroken or rooted. The company can remove company data and accounts from those apps (a selective wipe) but cannot erase or see your personal apps, photos or messages.

Personal computers. Personal laptops and desktops must not be used for company work, including through a web browser. Personal computers are a common source of stolen passwords, and the company cannot check or protect them. Use the company computer you were issued.

Minimum standards. A personal phone or tablet used for company work must meet these standards at all times. Company tools check some of them automatically and may block access until the device meets them again.

RequirementStandard
Operating systemA version the manufacturer still supports with security updates
UpdatesSecurity updates installed within 14 days of release
Screen lockA PIN of at least 6 digits, a password or biometric unlock, locking automatically after 5 minutes or less
EncryptionDevice encryption turned on
IntegrityNot jailbroken or rooted, and not running beta or modified software
AppsInstalled only from the official app store for the device

Sharing the device. Family members may use your personal device, but they must never use the company apps. Do not share the device PIN or app PIN with anyone, and do not leave company apps open for someone else to use.

Changing or selling a device. Before you sell, trade in, give away, repair or replace a personal device used for company work, sign out of the company apps and tell the IT Manager so company access can be removed.

Sign-in approvals. Using a personal phone only to approve company sign-ins with the company authenticator app is not considered BYOD under this policy. Anyone who prefers not to use a personal phone for this may ask for a hardware security key or another company-provided method instead.

7. Home Networks, Public Wi-Fi and Remote Access

Your home network. Your home Wi-Fi router carries company traffic, so it must meet these basics. Ask the IT team for help if you are not sure how.

  • Change the router administrator password from the factory default to a unique, strong password.
  • Use WPA3 encryption, or WPA2 if the router does not support WPA3, with a strong Wi-Fi password. Never use an open network, WEP or WPS.
  • Keep router firmware updated, turn on automatic updates if available, and replace routers the manufacturer no longer supports.
  • Put smart home devices, game consoles and guests on a separate guest network where your router allows it.
  • Do not use a network run by a neighbor, landlord or building unless you connect the company VPN or secure access app first.

Connecting to company systems. Company cloud services, such as email, chat and file storage, may be reached directly over the internet, protected by multi-factor authentication and the company sign-in rules. Internal systems, such as file servers, ERP and business applications hosted at a company site, may be reached only through the company VPN or secure access app.

Public Wi-Fi. Public Wi-Fi, such as hotels, coffee shops, airports and customer or supplier guest networks, may be used for company work only after the company VPN or secure access app is connected. If it will not connect, use the hotspot on your phone instead. Never sign in through a public network that asks for your company password or wants you to install something first.

Signing in. Always sign in to company systems with multi-factor authentication. Never approve a sign-in prompt you did not start, and report unexpected prompts right away.

8. Storing, Sharing and Printing Company Data

Company data must stay in approved storage. Whether you are on a company device or a personal one, you must not:

  • Save company files to personal cloud storage, personal email, personal USB drives or the local storage of a personal device
  • Forward company email or files to a personal email address or messaging app
  • Use personal text messaging, WhatsApp or other personal apps for company business the company has not approved
  • Take photos or screenshots of company data with a personal device, except inside protected company apps or where this policy allows it
  • Keep company data after you no longer need it for your work

Printing and paper records. Print at home only when the work truly needs paper, and never print confidential or regulated records at home. Use a printer connected directly to your computer or your home network, collect printouts right away, keep them where others in your home cannot read them, and shred them with a cross-cut shredder, or bring them to a company site for secure disposal, when you no longer need them.

Personal information. Personal information about employees, customers or anyone else, such as Social Security, driver's license, bank account and health details, must stay in approved company systems and must not be saved to a personal account, a removable drive or a personal device outside the protected company apps. North Carolina and other state breach notification laws can require the company to notify affected people when a lost device or misdirected file exposes personal information, so prompt reporting matters.

9. Physical Security and Confidential Conversations

At home and in public. Treat every place outside a company site as one where others may see or hear your work.

  • Lock your screen every time you step away, even at home.
  • Use a privacy screen filter when working in public places or while traveling, and position your screen away from windows and walkways.
  • Never leave devices unattended in public, and never leave them in a vehicle overnight or in view.
  • Store company devices and any company paper out of sight and out of reach of others in your home when you are not using them.
  • Do not let anyone else use your company accounts, and do not share your passwords, PINs or security keys with anyone, including family members.

Video calls and phone calls. Confidential conversations need the same care as confidential documents.

  • Use headphones and a private space for confidential calls, and never discuss confidential matters in public places, shared rides or where family members can hear.
  • Use a blurred or company background when your surroundings could show personal or confidential information.
  • Before sharing your screen, close unrelated windows, email and chat, and share one window rather than your whole screen when you can.
  • Check who has joined before discussing confidential matters, and do not admit unknown attendees or note-taking bots.
  • Record a call only with the company's approval and after telling everyone on the call. Some states require every participant to agree before a call is recorded.
  • Mute or turn off voice assistants and smart speakers in the room during confidential calls.

10. Travel and Working Away From Home

Traveling with devices. Keep company devices with you. Carry laptops and phones on board rather than in checked luggage, and avoid leaving them in a vehicle. If you must, lock them in the trunk or out of sight before you arrive, not in the parking lot, and never overnight. Use a hotel safe or take them with you, and charge devices from your own charger and a wall outlet rather than public USB charging ports.

International travel. Before you take a company device outside the United States, or use company systems from outside the United States, get approval from the IT Manager at least 10 business days in advance. Some countries restrict encryption or the use of VPNs, and border officials in the United States and elsewhere may inspect devices, so take only the devices and data the trip needs. The company may block sign-ins from other countries unless travel has been approved.

Working from another state or country. Working from a different state for more than two weeks, or from any other country for any length of time, requires written approval in advance, even when the trip is personal. Where you work can change tax, payroll, employment law and data protection obligations for the company.

11. Lost or Stolen Devices and Security Incidents

Report right away, and no later than 4 hours after you notice, if:

  • A company device, or a personal device with company apps or data on it, is lost, stolen or left behind somewhere you cannot get back to
  • You think someone else has seen, copied or used company data on one of your devices
  • You clicked a suspicious link, opened a suspicious file or entered your password on a site you now doubt
  • You got a sign-in prompt you did not start, or a device is acting strangely
  • Company paper records were lost, misplaced or thrown away without shredding

How to report. Contact the IT Manager, by phone if you can. Say what happened, which device or records were involved, what data may have been on them, when and where you last had them, and whether the device was locked. Do not wait days while you search for a missing device. If a device was stolen, file a police report and share the report number.

What the company will do. The company will block access and may remotely lock, locate or erase a company device. For a personal device, the company will remove company data and accounts (a selective wipe) and will erase the whole device only if you ask.

No blame for prompt reports. The company will not charge you for a company device that is lost, stolen or damaged by accident when you report it as this policy requires. You will never be disciplined for reporting a mistake in good faith. Hiding a loss or delaying a report on purpose is a violation of this policy.

12. Privacy and Monitoring

Company devices and accounts. Company devices, accounts and systems belong to the company. As the law allows, the company may monitor, log and review their use, including sign-ins, network traffic, security alerts, email and files, to protect the business, so do not expect privacy in anything on a company device or account. Device location is used only to recover a lost or stolen device or to investigate a security incident, never to track where you are.

Personal devices. The company will set up app protection so that it collects only what it needs to protect company data. It may see your name, the device model and operating system version, the company apps you use, and whether the device meets this policy.

The company will not collect, view or erase:

  • Personal email, text messages, call history or voicemail
  • Personal photos, videos, files or contacts
  • Personal apps, browsing history or social media
  • Your location

Legal holds. If company data on a personal device is needed for a lawsuit, investigation or legal hold, you must help the company preserve and collect that company data. The company will limit any review to company data.

Notice. This policy is your notice of the monitoring it describes. Where state law requires a separate written notice or acknowledgment of electronic monitoring, the company will provide it.

13. Expenses and Working Hours

Equipment. The company provides the equipment each remote role needs, such as a computer and headset. The company does not generally pay for home internet, utilities or furniture unless the law requires it or it is approved in writing.

Personal phone costs. Employees approved to use a personal phone for company work receive a fixed monthly stipend, in an amount set by the company, through payroll. If your actual business cost is higher than the stipend, submit it through the normal expense process and the company will review it.

State reimbursement laws. Some states, including California and Illinois, require employers to reimburse necessary business expenses, which can include a reasonable share of personal phone and home internet costs. Where a law in North Carolina or in the state where you work requires more than this section provides, the company will follow the law.

Working hours for non-exempt employees. Non-exempt employees, meaning those who are paid hourly or are otherwise eligible for overtime, must not read or answer work email, chat, texts or calls outside their scheduled hours unless their manager has approved it in advance. If you do any work outside your scheduled hours, even a few minutes, record it.

The company will pay for all time worked, including time spent on a personal phone, even when the work was not approved. Managers must not ask for, encourage or accept unrecorded work. Take meal and rest breaks as company policy and state law require. Having company apps on your phone does not mean you must be available outside your working hours.

14. Leaving the Company

When you leave the company, or when your role no longer needs remote access or a device:

  • Your access to company systems will end on your last day, or earlier if the company decides.
  • Return all company devices, accessories, security keys, badges and company paper records within 5 business days after your last day. If you work remotely, the company will provide prepaid shipping and packaging.
  • Do not reset, wipe or remove data from company devices yourself. The company needs them returned as they are.
  • Remove your personal files from company devices before your last day.
  • On or before your last day, the company will remove company apps, accounts and data from your personal devices with a selective wipe. Keep the devices connected so this can happen.
  • Delete any company data you have anywhere outside approved storage, and do not keep copies. The company may ask you to confirm this in writing.

Unreturned equipment. The company may take steps to recover unreturned equipment, including remotely locking it, as the law allows. Your duty to protect confidential information continues after you leave.

15. Exceptions and Violations

Exceptions. Any exception to this policy must be requested from the IT Manager, approved in writing, limited in time and recorded. Exceptions cannot override a law, regulation or customer contract.

Violations. Breaking this policy may lead to discipline, up to and including termination of employment or of a contract, consistent with company policy and applicable law. The company may also suspend remote access, end a remote work arrangement or remove a personal device from company access.

Keeping this policy current. The IT Manager is responsible for this policy and will review it by September 27, 2027, or sooner when the company changes its devices or remote access tools, or when laws change. The company will tell you when the rules change.

16. Employee Acknowledgment

I have received and read the [Company Name] Remote Work and Bring Your Own Device Policy, effective September 27, 2026. I understand it, I have had the chance to ask questions, and I agree to follow it. I understand that breaking it may lead to discipline, up to and including termination, and that the company may monitor company devices and accounts as the policy describes. I understand that the company may update this policy, and that this acknowledgment is not a contract of employment.

Personal devices. If I use a personal device for company work, I agree to the company protection described in this policy, and I consent to the company removing company data, accounts and apps from that device when it is lost or stolen, when I stop using it for company work, or when I leave the company.

Employee name (printed)

Employee signature

Date

17. Document Control and Revision History

FieldValue
DocumentRemote Work and Bring Your Own Device Policy
Organization[Company Name]
Document IDPDC-RWB-SAMPLE
Document version1.0
Effective dateSeptember 27, 2026
Next scheduled reviewSeptember 27, 2027
Policy ownerIT Manager
Approved byChief Executive Officer
Source templatePreferred Data Corporation Remote Work and BYOD Policy template v1.0.0

Revision history. Record every change to this policy below. Increase the document version and obtain approval again each time the policy is revised.

VersionDateDescription of changeApproved by
1.0September 27, 2026Initial adoption, generated from template v1.0.0.Chief Executive Officer
BlankBlankBlankBlank
BlankBlankBlankBlank

18. Template Notice and Legal Disclaimer

This document was generated from a starter template provided by Preferred Data Corporation. It is general information only. It is not legal advice and it is not a substitute for advice from a licensed attorney.

Preferred Data Corporation is not a law firm. It makes no representation that this document is complete, current, or suitable for any particular organization, industry, jurisdiction, or regulatory requirement, and it is not responsible or liable for any use of this template or of any policy created from it. You are solely responsible for how you adapt, adopt, and enforce it.

Laws, regulations, insurance requirements, and contracts that apply to your organization may require different or additional terms. Before you adopt, publish, or rely on this policy, and in every case where you have a legal, regulatory, or contractual obligation, have it reviewed by qualified legal counsel.

How does the Remote Work and BYOD Policy generator work?

5 short phases, about 5 minutes in total. Every question is pre-filled with a best-practice answer and the reason we recommend it.

  1. Your organization

    The basics that shape who the policy covers and which obligations it has to respect.

  2. Remote work and access

    Who may work remotely, how they connect, and the rules for printing and travel.

  3. Devices and BYOD

    Which personal devices may be used, how company data on them is protected, and who pays.

  4. Losses, hours and offboarding

    How fast problems are reported, after-hours work for hourly staff, and returning equipment.

  5. Ownership and review

    Who owns the policy, who approves it, and how it stays current.

  6. Review and download

    Preview your policy, unlock the full document and download it as a PDF with a document ID and review date.

Start the generator

Who should adopt this policy?

  • Small and mid-sized businesses with staff who work from home, travel or read company email on personal phones
  • Manufacturers, contractors and distributors with office staff, field crews and supervisors working away from the plant or office
  • Companies rolling out Microsoft 365 with Intune app protection or device management that need signed employee rules first
  • Owners and HR leaders who want one plain-language policy covering remote work, personal devices, reimbursement and offboarding
  • Defense suppliers and regulated businesses that must keep CUI, health, payment or financial data off personal devices

Which frameworks does this template align with?

The template was written against these public frameworks, laws and standards. Alignment is not certification, and your obligations depend on your industry and location.

Framework or lawWhy it matters for this policy
NIST SP 800-46 Rev. 2, Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security(opens in a new tab)The federal guide to securing telework, remote access and BYOD that this policy turns into everyday rules.
NIST SP 800-114 Rev. 1, User's Guide to Telework and Bring Your Own Device (BYOD) Security(opens in a new tab)The employee-facing companion guide behind the home network, public Wi-Fi and personal device rules.
NIST SP 800-124 Rev. 2, Guidelines for Managing the Security of Mobile Devices in the Enterprise(opens in a new tab)Covers mobile device threats and management approaches, including personally owned devices.
Microsoft Learn, App Protection Policies Overview (Microsoft Intune)(opens in a new tab)Explains how app protection secures company data on personal devices without enrollment, including selective wipe of company data only.
U.S. Department of Labor, Fact Sheet #22: Hours Worked Under the Fair Labor Standards Act(opens in a new tab)States that work suffered or permitted must be paid, the basis for the after-hours rule for non-exempt staff.
FTC, Safeguards Rule: What Your Business Needs to Know(opens in a new tab)Sets multi-factor authentication and encryption expectations for businesses that hold customer financial information.

Remote Work and BYOD Policy questions, answered

What should a BYOD policy include?

At minimum: which personal devices may be used and for what, how company data on them is protected (app protection or device enrollment), minimum standards for updates, screen lock and encryption, what the company can and cannot see, and how company data is removed when a device is lost or the employee leaves. It should also cover reimbursement, after-hours use by hourly staff, and a signed acknowledgment that includes consent to removing company data.

Can my employer wipe my personal phone?

With app-level protection, such as Microsoft Intune app protection policies, the company can remove only company data and accounts from its apps, a selective wipe, and cannot erase or see your personal photos, messages or apps. A full device wipe is only possible when the phone is fully enrolled in device management. A good BYOD policy limits the company to selective wipes and erases a whole personal device only at the employee's request.

Do employers have to reimburse employees for using personal cell phones?

It depends on the state. California Labor Code section 2802 and Illinois law (820 ILCS 115/9.5) require employers to reimburse necessary business expenses, and California courts have applied this to a reasonable share of personal phone costs even for employees on unlimited plans. Many employers in other states pay a flat monthly stipend or offer a company phone instead, and the policy should say which approach applies.

Do hourly remote workers have to be paid for answering email after hours?

Yes. Under the federal Fair Labor Standards Act, the U.S. Department of Labor says that work not requested but suffered or permitted is work time that must be paid. That is why a remote work policy should tell non-exempt staff not to check work email or chat outside scheduled hours without approval, and to record any time they do work so it can be paid.

What is the difference between MDM and MAM for BYOD?

Mobile device management (MDM) enrolls the whole device so the company can enforce settings, install apps and, on fully enrolled devices, erase it. Mobile application management (MAM), also called app protection, protects company data only inside company apps such as Outlook and Teams, without enrolling the device. MAM is usually the better fit for personal phones because it protects company data while leaving personal data alone.

Is it safe for employees to use public Wi-Fi for work?

Only with protection. Hotel, airport, coffee shop and guest networks are shared with strangers and can be imitated by look-alike networks, so a remote work policy should require the company VPN or secure access app before any company work, or a phone hotspot instead. Multi-factor authentication and up-to-date devices add further protection.

Does a small business really need a remote work and BYOD policy?

Yes, if anyone reads company email on a phone or works from home. The U.S. Bureau of Labor Statistics found that 20.8 percent of private wage and salary workers teleworked in April 2025, and the 2025 Verizon Data Breach Investigations Report found that 46 percent of infostealer-compromised systems with corporate logins were non-managed, personal devices. A written policy sets the device and data rules before an incident, not after.

What happens to company data when a remote employee leaves?

The company should disable access by the end of the last day, remove company apps and data from personal devices with a selective wipe, and collect company equipment within a set number of days using prepaid shipping. The employee should confirm they have not kept copies of company data. Setting these steps in a signed policy makes offboarding quick and consistent.

Related policy templates

Services that put this policy into practice

Want help rolling out your Remote Work and BYOD Policy?

A policy works when the tools, training and controls behind it do. Preferred Data Corporation helps North Carolina businesses put policies like this one into practice, from High Point since 1987.