Article
Phones Are Now the Soft Target. Fix That
Staff read work email on personal phones you do not manage. Here is how to secure business data on mobile devices without taking over anyone private handset.

Ask a business owner how many computers they have and you will get an accurate number. Ask how many devices access company email and the number is usually double, because everyone forgot the phones.
That gap is the whole problem. The laptops are patched, encrypted and monitored. The phones reading the same mailboxes are running whatever version of the OS the user last accepted, on whatever network the cafe provided, with no way to wipe the data if the handset is left in a taxi.
Why phones became the target
Attackers follow the path of least resistance, and mobile offers several.
The screen hides the evidence. Every phishing tell you train staff to look for is harder to see on a phone. The sender address is truncated to a display name. Hovering to preview a link is not a gesture that exists. A narrow screen makes a crude fake look plausible.
People are distracted. Phone email is read in queues, between meetings, walking to the car. That is precisely the state in which someone taps a link they would have questioned at a desk.
The channels multiply. Business phishing arrives by SMS, WhatsApp and LinkedIn now, not just email — and none of those run through the mail filtering you bought.
The device is unmanaged. The laptop has endpoint protection. The phone in the same pocket, opening the same attachments, usually has nothing.
The realistic threats, not the scary ones
Commercial spyware makes headlines and will almost certainly never target your business. The mundane risks are what actually cost Australian companies money:
- SMS phishing. The fake delivery notification, the fake myGov message, the fake bank alert. Cheap to send at enormous scale, and the Australian variants are now well localised.
- Malicious or over-permissioned apps. Less often outright malware, more often a free utility harvesting contacts, messages and location and selling the lot.
- Public Wi-Fi interception. Diminished by HTTPS everywhere, but still viable against poorly built apps.
- Lost and stolen handsets. The most common incident by a wide margin, and the most preventable.
- SIM swap. Covered elsewhere, and the reason SMS is the weakest form of MFA.
Separate the data from the device
The instinct is to lock down the phone. For company-owned handsets, fine. For personal phones — which is most of them — it is both intrusive and unnecessary, and staff will resist it for good reason.
The better model is to protect the data rather than the device. Microsoft calls this app protection policy; the general term is mobile application management. Business data lives inside the managed apps — Outlook, Teams, OneDrive — and the rules apply only there:
- Company data cannot be copied out of a managed app into a personal one.
- Work files cannot be saved to personal cloud storage or the camera roll.
- The work apps require a PIN or biometric of their own.
- Company data can be wiped from the work apps without touching a single personal photo.
That last point is what makes the policy acceptable to staff. Offboarding someone removes the business data and leaves their phone otherwise untouched, which is a conversation nobody has to dread.
The baseline that covers most of the risk
Whatever the ownership model, these apply:
- Screen lock with biometric, and device encryption on. Encryption is default on current iOS and Android, but only once a passcode exists. A phone with no passcode is not encrypted.
- Automatic OS updates enabled. Mobile patches fix actively exploited flaws, and the lag between release and install is the exposure window.
- Apps from official stores only. Sideloading is where the genuinely malicious software lives.
- An app permission review twice a year. Most people are startled by what they granted in 2022.
- Find My Device turned on, so a lost handset can be located and wiped rather than merely mourned.
- Conditional access so that only compliant devices can reach Microsoft 365 at all.
Write the BYOD rules down before you need them
Most Australian small businesses run bring-your-own-device by default rather than by decision, which means there is no agreement and no shared expectation. When the relationship ends badly, that is when it hurts.
A one-page policy settles it in advance: which data may be accessed from personal devices, what the business can and cannot see, that company data will be removed on departure, that lost devices must be reported immediately, and who pays for what. Have staff acknowledge it. It takes an afternoon and removes an entire category of argument.
Pair it with user awareness training that actually covers SMS and messaging-app phishing, because email-only training leaves the busiest channel unaddressed.
When a phone goes missing
Have the sequence written down, because nobody improvises well at 6pm on a Friday:
- Locate it remotely; if it is genuinely gone, move on quickly.
- Revoke the active sessions for that user so existing tokens stop working.
- Wipe company data — full wipe for a corporate device, selective wipe for a personal one.
- Reset the password and re-enrol MFA.
- Check sign-in logs for anything that happened between loss and wipe.
Steps two and five are the ones usually skipped, and they are the ones that matter. A wiped phone with a still-valid session token has not been secured.
Device enrolment, app protection and conditional access are all part of our managed IT service, and managed detection and response covers the sign-in monitoring that turns a lost phone into a non-event.
Local IT and cyber security support across NSW
Chewing IT runs managed IT and cyber security for small and mid-sized businesses from our Wyong and Hornsby offices, covering the Central Coast, Newcastle, Lake Macquarie and Hornsby.
Do you know how many phones reach your company email right now? Ask us to find out — the number is usually a surprise.