Blog · Bring Your Own Chaos
How Unmanaged Work Devices Create Security Risk and IT Problems
If you ask a small business owner how many devices can access company email, files, or client data, you’ll get an approximate guess. Ask how many of those devices are managed, and that’s where things start to fall apart. Nobody ever sat down and decided this was worth thinking about.
This is the first part of a new series looking at the gap between managed and unmanaged devices: the laptops, phones, and tablets touching your business every day with no policy, no visibility, and no plan behind them.
What “Managed” Means
A managed device is one your business has some level of control over, even if an employee is the one using it day to day. Through a tool like Microsoft Intune, a managed device can have things like:
- Encryption enforced automatically, so a lost laptop isn’t a data breach waiting to happen.
- Security updates and patches applied on a schedule, not whenever someone gets around to it.
- Company data wiped remotely if the device is lost, stolen, or the employee leaves.
- A minimum security standard checked before the device is allowed to access company email or files at all.
None of this requires the business to own the device outright. A personal phone can be managed too, usually through a lighter-touch approach that protects company data inside an app without touching anything personal on the rest of the phone.
What “Unmanaged” Looks Like
An unmanaged device is any device with none of the above. It might have a strong password. It might belong to someone careful. But there’s no way for the business to confirm any of that, and no way to act if something goes wrong.
In practice, this is what unmanaged usually looks like in a small business:
- A laptop bought from whichever retailer had a deal on at the time, with whatever version of Windows it happened to come with.
- A personal phone with the Outlook app installed, no passcode requirement, no way to remotely wipe it if it’s lost.
- A home PC an employee uses to check email on evenings and weekends, with no idea what else is installed on it.
- Nobody in the business able to say, with any confidence, how many devices currently have access to company data.
None of these are unusual. Most small (and many medium-sized) businesses operate exactly like this, often for years, without an incident that forces the question.
Why This Happens
Device management isn’t something most small businesses actively decide against. It’s something that never comes up until there’s a reason to think about it, and by then, a handful of unmanaged devices has usually turned into a few dozen.
A few common patterns we regularly see at Outlaw:
- IT purchasing decisions get made by whoever needs a laptop that week, not as part of a wider plan.
- Mobile access to email gets turned on because it’s convenient, without anyone considering what that means for company data sitting on personal phones.
- The business grows from five people to 25, and what was previously manageable informally is now a growing problem.
- Nobody owns the problem, because it was never assigned to anyone in the first place.
What This Costs You
Visibility and centralised management are the points here. A lost laptop with no encryption is a data protection issue, not just an inconvenience. A former employee’s personal phone still holding a synced copy of the company inbox is also a data security risk. A home PC with out-of-date software sitting on the same network as client files is a route in for exactly the kind of attack covered elsewhere on this blog.
With unmanaged devices, IT support can become guesswork. Every device is a slightly different problem, with different software versions, different security settings, and no consistent baseline to troubleshoot against. What should be a five-minute job can turn into an hour of working out what’s even installed.
What’s Coming in This Series
Over the next three parts, we’ll go deeper into specific pieces of this problem:
- Part 2 looks specifically at mobile devices, the most commonly overlooked part of the picture, and what a sensible policy looks like without requiring the business to own everyone’s phone.
- Part 3 covers what a tool like Intune does for a business once it’s properly set up, beyond the basic idea of “managing devices”.
- Part 4 is the practical rollout: how a business goes from zero device management to a properly managed fleet without disrupting how anyone works day to day.
Not Sure Where You Stand?
If you couldn’t confidently answer how many devices currently access your business data, you’re not alone, and thankfully, it’s a fixable gap.
This is exactly the kind of thing we look at in our Free M365 Assessment, including a clear picture of what’s currently managed, what isn’t, and what that’s likely costing you in risk and support time.