Remote Work and BYOD Policy Template

FREE TEMPLATE

Remote Work and BYOD Policy

The minimum a device must meet to hold company data — and, said plainly, what the company can and cannot see on a device it does not own.

[COMPANY NAME]

Effective date: [DATE] · Owner: [NAME, TITLE] · Review: annually, or after any material change

Purpose

The office network stopped being the security boundary years ago. Company data now sits on laptops at kitchen tables and phones in coat pockets, on hotel wifi, on devices the company does not own.

This policy sets the minimum a device must meet to hold company data, and — just as importantly — what the company will and will not do to a device it does not own.

Scope

Applies to every device used for company work, whether the company bought it or not, and to working anywhere other than a company location.

Minimum standards for any device

Non-negotiable. A device that does not meet these does not get company data on it.

RequirementWhy
Full-disk encryption onA lost laptop is an incident; an encrypted lost laptop is usually paperwork
Screen lock, [NUMBER] minutes, password or biometricThe most common “breach” is someone walking past an unlocked screen
Operating system still supported and receiving updatesAn unsupported OS cannot be secured, whatever else you install
Updates applied within [NUMBER] daysMost break-ins use a patch that was available and not applied
Company-approved security software where required
Not shared with family or anyone else while holding company dataA shared family laptop cannot meet this policy
Not jailbroken or rooted

Company devices and personal devices

Company-owned devices are managed by [COMPANY NAME]. They may be monitored, configured, updated and wiped. Reasonable personal use is [PERMITTED / NOT PERMITTED], and personal data on them is not private.

Personal devices used for work are permitted for [WHICH SYSTEMS — e.g. email and calendar only]. The rest of this section is the part staff actually care about, so say it plainly.

What the company can and cannot see on a personal device

BYOD policies fail when staff suspect the company is reading their messages. Be specific instead.

[COMPANY NAME] can:

  • See that the device exists, its model, OS version and whether it is encrypted
  • Require a passcode before company data is accessible
  • Remove company data — company accounts, company email, company files
  • Block the device’s access to company systems

[COMPANY NAME] cannot and does not:

  • Read personal messages, photos, browsing history or personal email
  • Track personal location
  • Wipe the whole device, or anything personal on it

If the tooling in use does not match this, change the wording to the truth, not the other way round.

Networks

Home wifi: change the default router password, keep the router firmware updated, use WPA2 or better.

Public wifi — hotels, cafes, airports, conference centers — is untrusted. Prefer a phone hotspot. Where public wifi is used, use [VPN / SECURE ACCESS METHOD].

Never use a public charging port for a work device. Carry a plug.

Physical care

Devices are not left visible in vehicles, are not left unattended in public, and are locked whenever the person steps away — including at home if anyone else is in the house.

A lost or stolen device is reported to [POLICY OWNER] the same day, regardless of hour and regardless of whether it seems likely to turn up. Early reporting lets access be cut; late reporting is how a misplaced laptop becomes a breach.

Where company data may live

Company data is stored in company systems. Not on the desktop, not in a personal cloud drive, not in a personal email account, not in a personal notes app.

This is not bureaucracy: data outside company systems is not backed up, cannot be retrieved when the person leaves, and is invisible when you have to say what a breach exposed.

AI tools, including chat assistants, are treated the same as any other third party — approved ones under the Vendor and Third-Party Management Policy, and customer data is not pasted into unapproved ones.

Printing and paper

Work printed at home is stored securely and shredded, not binned. Paper leaves the same trail as a file and is protected by nothing.

When someone leaves

On the last day, company accounts are removed from personal devices and company data is deleted from them, with the employee present where practical. [POLICY OWNER] records that it was done.

A personal device the company never touched again is the most common way data leaves a small business, and it leaves quietly.

Responsibilities

[POLICY OWNER] maintains the device list, enforces the minimum standards and runs removal at exit.

Managers confirm their team’s devices meet the minimum standards above before granting access.

Everyone keeps company data in company systems and reports a lost device the same day.

Review

Reviewed at least annually by [POLICY OWNER], and whenever the systems accessible from personal devices change.

Acknowledgment

I have read and understood the [COMPANY NAME] Remote Work and BYOD Policy. I agree to follow it on every device I use for company work, including devices I own.

Name: ______________________________

Signature: __________________________

Date: ______________________________

Template provided free by Cybertitans LLC, Woodbury, Minnesota. It is a starting point, not legal advice, and it has not been reviewed against your contracts, your industry’s regulations or your retention obligations. Have counsel review it before you adopt it. Downloading or using this template does not create a client relationship with Cybertitans, and Cybertitans makes no representation that adopting it satisfies any insurer, regulator, auditor or customer requirement.

EDITABLE VERSION

Want the Word version you can edit?

The policy above is free to read, copy and adapt — that is the point of publishing it. The Word file is the same text with every fill-in field marked, our formatting, and the signature block ready for your team to sign. Tell us where to send it.

Free. About 20 seconds.

THE REST OF THE SET

Nine more, and someone to run them.

This is one of ten free templates written for businesses with no IT department. The others are on the resource library, and the editable Word versions are a name and an email away.

A policy nobody operates is a document. If you would rather someone owned this — and the offboarding, the backups and the MFA behind it — that is what TiTAN is.

Book 20 Minutes