FREE TEMPLATE
Remote Work and BYOD Policy
The minimum a device must meet to hold company data — and, said plainly, what the company can and cannot see on a device it does not own.
[COMPANY NAME]
Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, or after any material change
Purpose
The office network stopped being the security boundary years ago. Company data now sits on laptops at kitchen tables and phones in coat pockets, on hotel wifi, on devices the company does not own.
This policy sets the minimum a device must meet to hold company data, and — just as importantly — what the company will and will not do to a device it does not own.
Scope
Applies to every device used for company work, whether the company bought it or not, and to working anywhere other than a company location.
Minimum standards for any device
Non-negotiable. A device that does not meet these does not get company data on it.
| Requirement | Why |
|---|---|
| Full-disk encryption on | A lost laptop is an incident; an encrypted lost laptop is usually paperwork |
| Screen lock, [NUMBER] minutes, password or biometric | The most common “breach” is someone walking past an unlocked screen |
| Operating system still supported and receiving updates | An unsupported OS cannot be secured, whatever else you install |
| Updates applied within [NUMBER] days | Most break-ins use a patch that was available and not applied |
| Company-approved security software where required | |
| Not shared with family or anyone else while holding company data | A shared family laptop cannot meet this policy |
| Not jailbroken or rooted |
Company devices and personal devices
Company-owned devices are managed by [COMPANY NAME]. They may be monitored, configured, updated and wiped. Reasonable personal use is [PERMITTED / NOT PERMITTED], and personal data on them is not private.
Personal devices used for work are permitted for [WHICH SYSTEMS — e.g. email and calendar only]. The rest of this section is the part staff actually care about, so say it plainly.
What the company can and cannot see on a personal device
BYOD policies fail when staff suspect the company is reading their messages. Be specific instead.
[COMPANY NAME] can:
- See that the device exists, its model, OS version and whether it is encrypted
- Require a passcode before company data is accessible
- Remove company data — company accounts, company email, company files
- Block the device’s access to company systems
[COMPANY NAME] cannot and does not:
- Read personal messages, photos, browsing history or personal email
- Track personal location
- Wipe the whole device, or anything personal on it
If the tooling in use does not match this, change the wording to the truth, not the other way round.
Networks
Home wifi: change the default router password, keep the router firmware updated, use WPA2 or better.
Public wifi — hotels, cafes, airports, conference centers — is untrusted. Prefer a phone hotspot. Where public wifi is used, use [VPN / SECURE ACCESS METHOD].
Never use a public charging port for a work device. Carry a plug.
Physical care
Devices are not left visible in vehicles, are not left unattended in public, and are locked whenever the person steps away — including at home if anyone else is in the house.
A lost or stolen device is reported to [POLICY OWNER] the same day, regardless of hour and regardless of whether it seems likely to turn up. Early reporting lets access be cut; late reporting is how a misplaced laptop becomes a breach.
Where company data may live
Company data is stored in company systems. Not on the desktop, not in a personal cloud drive, not in a personal email account, not in a personal notes app.
This is not bureaucracy: data outside company systems is not backed up, cannot be retrieved when the person leaves, and is invisible when you have to say what a breach exposed.
AI tools, including chat assistants, are treated the same as any other third party — approved ones under the Vendor and Third-Party Management Policy, and customer data is not pasted into unapproved ones.
Printing and paper
Work printed at home is stored securely and shredded, not binned. Paper leaves the same trail as a file and is protected by nothing.
When someone leaves
On the last day, company accounts are removed from personal devices and company data is deleted from them, with the employee present where practical. [POLICY OWNER] records that it was done.
A personal device the company never touched again is the most common way data leaves a small business, and it leaves quietly.
Responsibilities
[POLICY OWNER] maintains the device list, enforces the minimum standards and runs removal at exit.
Managers confirm their team’s devices meet the minimum standards above before granting access.
Everyone keeps company data in company systems and reports a lost device the same day.
Review
Reviewed at least annually by [POLICY OWNER], and whenever the systems accessible from personal devices change.
Acknowledgment
I have read and understood the [COMPANY NAME] Remote Work and BYOD Policy. I agree to follow it on every device I use for company work, including devices I own.
Name: ______________________________
Signature: __________________________
Date: ______________________________
Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your retention obligations. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.
EDITABLE VERSION
Want the Word version you can edit?
The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked, our formatting, and the signature block ready for your team to sign. Tell us where to send it.
Free. About 20 seconds.
Where should we send it?
THE REST OF THE SET
Nine more, and someone to run them.
This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.
A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.
