Skip to main content
CybersecurityChecklistIntermediate2 min readUpdated

Securing the Devices Your Staff Actually Use

Laptops, phones, and personal devices used for work all need a baseline of protection. Here's what that baseline should include.

Written by

Zach Swartz, Business Technology Advisor

Zach Swartz

Business Technology Advisor · Great Falls, Montana

Every device that touches organizational data — including personal phones checking work email — is part of your security posture, whether it's managed or not.

  1. Encryption is turned on. BitLocker (Windows) or FileVault (Mac) should be enabled on every device, so a lost or stolen laptop doesn't mean a lost or stolen dataset.
  2. Screen locks are required, with a reasonably short timeout — a device left unlocked in a coffee shop is a real, common failure mode.
  3. Endpoint protection is current on every machine, not just the ones IT remembers to check.
  4. Personal devices have a minimum standard. If staff use their own phones for work email, a passcode and remote-wipe capability should be a condition of that access, not an afterthought.
  5. Software updates aren't optional. Unpatched operating systems and browsers are one of the most common ways devices get compromised.
  6. Offboarding includes device access. When someone leaves, their access to organizational data — not just their email account — should be removed the same day.

Most of this is achievable with Intune or similar device management, already included in many Microsoft 365 plans — see our Microsoft 365 governance guide for where to start.

Not sure where your organization stands?

The Business Success Assessment covers this topic and more, with results in about 7–10 minutes.