A personal laptop used to send one client file can become central to a cyber claim. For remote-first SMEs, the key issue is proving who used it. You must also show what business data it held and which safeguards applied.
Do BYOD devices break cyber cover?
BYOD means “bring your own device”. A worker uses their own laptop, phone or tablet for business. This can be insured, but it may complicate a claim.
A claim can be harder if a device was unpatched, shared or poorly protected. Think of it like a spare key to your office. The insurer will want to know who held it and how it was kept safe.
What should be declared?
Answer proposal and renewal questions accurately. Tell your broker if staff, founders or contractors use unmanaged devices. This includes access to email, cloud files, finance systems or customer data.
Ask whether this affects policy conditions, ransomware cover, excesses or sub-limits. The Information Commissioner's Office expects suitable security for personal data. This duty comes from UK GDPR and the Data Protection Act 2018.
Its guidance on security of processing focuses on risk rather than device ownership.
Claims become harder when a business cannot name the device that accessed an affected account. This is common with family computers and contractor devices with broad access.
Keep a light inventory of the user, device, systems and safeguards. Remove contractor access when their work ends.
A personal device does not usually cause cyber cover to fail automatically. The practical test is whether you declared the device and access correctly. You must meet relevant conditions and show evidence after an incident.
What insurers expect from home devices
Insurers differ, but they often expect appropriate controls for home devices. This applies to devices reaching work email, cloud storage, remote access or personal data.
Controls worth recording
The National Cyber Security Centre's Cyber Essentials baseline covers supported software, safe settings, access control, malware protection and updates.
Record MFA for email, admin accounts, finance platforms and remote access. MFA means a second proof of identity, such as a phone prompt.
Require separate accounts, supported operating systems, automatic updates and full-disk encryption. Full-disk encryption scrambles data if a laptop is lost or stolen.
Mobile device management can enforce screen locks, approved apps and remote wiping. A small firm may manage with written rules and platform settings.
Backups and incident response
Test backups and keep one copy away from the main network. Ransomware can encrypt backups that stay connected to the network.
Your incident process should name who disconnects devices and resets accounts. It should also name who contacts the insurer and saves evidence.
Keep emails, logs and screenshots after an incident. Many policies require notice as soon as reasonably possible. Some set periods of 24 to 72 hours for defined events.
A BYOD policy should turn technical controls into daily habits. It should require strong, unique passwords stored in a password manager. It should also require MFA for all work accounts.
The policy should require supported systems and quick patching. It should require approved cloud storage, not personal email or consumer backups.
Staff need short training on phishing and lost-device reports. They also need to understand the risk of shared computers. Ask them to confirm that they understand the rules.
Devices with sensitive data need stronger safeguards. Finance systems and admin roles need them too. Use endpoint protection or EDR, full-disk encryption and mobile device management.
These measures support Cyber Essentials and UK GDPR security duties. They also give a more credible BYOD cyber insurance position.
Clear records matter most after an incident.
Higher-risk home and contractor setups
Device ownership matters less than access, sharing and evidence. Company-managed equipment usually creates clearer records than unmanaged personal devices.
BYOD, CYOD or company devices?
| Device model | Upfront cost | Evidence after an incident | Best use case |
|---|
| BYOD personal device | Lowest hardware spend | Depends on inventory and controls | Low-risk access with MFA and encryption |
| CYOD approved device | Medium | More consistent settings | Staff needing regular cloud access |
| Company-managed device | Highest | Usually strongest logs and control | Finance, admin and sensitive data roles |
CYOD means “choose your own device”. The business offers an approved range and manages it. Company devices are often safer for administrators and finance staff.
They also suit people handling large amounts of personal data. BYOD can suit low-risk access with enforced MFA, encryption and limited permissions.
Assess the home setup
Use WPA2 or WPA3 Wi-Fi and change router passwords. Keep router software current. Personal mobiles need screen locks, encryption and approved work apps.
Avoid downloading customer lists or sensitive files into personal backups. Your device record should list the person, device, systems, safeguards and review date.
Assess common home-working cases separately. Do not treat every personal device as the same risk.
A personal laptop used only in a browser is often lower risk. It needs MFA, encryption and no local downloads. A shared family computer creates more risk.
A personal mobile may suit approved work apps with a screen lock. It should also allow remote wiping. Give contractor devices time-limited access with least-privilege permissions.
These Wi-Fi measures should include WPA2 or WPA3, a changed router password and current firmware. This approach shows unmanaged-device risk clearly.
It also helps explain cover for each type of home access.
Avoid BYOD mistakes that weaken claims
The most common error is an optimistic proposal form. If you declare universal MFA, protection or encryption, you must show it existed during the incident.
Try to list every device accessing email and finance systems within one working day. Keep MFA screenshots, MDM reports and patch-status records. Keep backup-test notes, access reviews and staff acknowledgements too.
Keep policy documents, endorsements and broker emails. Ask whether unmanaged devices need declaring. Ask which controls are conditions and whether contractors are included.
Also ask what interruption sub-limits apply and when notice is due. These questions can matter more than the device's brand or age.
Match interruption cover to reality
Business interruption cover can pay lost income and extra costs after an insured cyber event. Waiting periods and indemnity periods still apply.
Base limits on likely lost gross profit, payroll and temporary IT help. Include customer communications and recovery costs. For many SMEs, an indemnity period of 3 to 12 months may be better than a high limit that ends quickly.
This guidance matters less when nobody uses personal or home devices for work. It is also less relevant if all staff use centrally managed equipment and contractors cannot reach business systems or data. This does not interpret a specific policy or arrange insurance. It does not replace legal advice after a suspected breach or declined claim.
Keep a simple device inventory in a spreadsheet or management platform. Record the owner, make and model, and operating-system version. Record the serial number where suitable.
Also record whether it is personal or company-owned. List systems accessed, MFA status and encryption status. Add endpoint protection, MDM status, last patch date and review date.
Link each record to the employee or contractor acknowledgement. Link it to access-removal dates when their role ends. For ransomware backup tests, record the test date and restored data.
Record the result and any fix needed. This creates useful evidence after a cyber incident. You can show which device had access and which controls were active.
You can also show how you contained and reported the event.
Frequently asked questions
Does BYOD void cyber insurance?
No. BYOD does not normally void cover automatically. Incorrect declarations or unmet relevant conditions can affect a claim.
Should I declare home devices to my insurer?
Declare them when proposal forms or broker questions cover unmanaged devices. This also applies to remote access or security controls. Seek written confirmation where needed.
What does a BYOD policy need?
It should cover allowed devices, MFA, encryption and patching. Include screen locks, approved storage and lost-device reporting. It should also cover access removal.
Does cyber essentials guarantee a claim?
No. Cyber Essentials is a useful security baseline. Policy wording, declarations, endorsements and incident facts still apply.
How much interruption cover do we need?
Choose an amount based on likely lost gross profit and recovery costs. Base it on a realistic outage period, often between 3 and 12 months.
Make evidence routine
Treat each work device as a controlled entrance to your business. Know who can enter, protect that access and show what was in place.
Start with an inventory and enforce MFA. Remove work access from shared computers and former contractors. Review policy conditions, exclusions and sub-limits before renewal.
Check notification requirements with your broker. Your policy wording and broker guidance remain the final test of cover.