Think about how your team actually works. Someone checks their emails on the train. A sales person uses their personal iPhone to access your CRM. An admin pops into the office WhatsApp group to share a client document. A staff member clicks a link in a text message and lands on a very convincing phishing page.

Mobile devices are central to how small businesses operate, but they’re often the weakest point in the security picture. Most small business owners have put real effort into securing their laptops and office computers — decent antivirus, sensible password policies, maybe some MFA — but the same care doesn’t always extend to phones and tablets.

It should. Here’s what actually matters.

Screen Locks and Encryption

Start with the basics, because they’re surprisingly often missing. Every phone or tablet with access to business data — even personal devices used for work email — should have a screen lock enabled. PIN, password, Face ID, fingerprint: any of these. The NCSC recommends a minimum 6-digit PIN if you’re not using biometrics.

The good news is that modern iOS and Android devices encrypt their storage automatically when a screen lock is set. On an iPhone, enabling a passcode automatically enables full-device encryption. On Android, it’s been automatic since Android 10 on most devices. So setting a screen lock gets you encryption for free.

If a device is lost or stolen without a screen lock, someone picking it up has access to everything — emails, documents, contacts, possibly saved passwords in the browser. With a proper screen lock and encryption, a lost device is an inconvenience rather than a data breach.

The BYOD Question

Bring-your-own-device (BYOD) policies — where staff use personal phones for work — are the norm in most small businesses. Buying separate work phones for everyone isn’t practical when you’re running a team of five or ten people. Fair enough.

The challenge with BYOD is that you don’t control the device. The employee might not have a screen lock. Their personal storage may not be encrypted. They might have apps installed that have permissions you wouldn’t grant to a work device. And if they leave the company, how do you ensure your business data leaves with them?

A sensible BYOD policy for a small business should set minimum standards: screen lock required to access business systems, no jailbreaking or rooting, approval before installing unknown apps for work purposes. Put it in writing, even briefly — a one-page policy that new starters sign is better than nothing, and it sets clear expectations.

For work email specifically, consider whether you can restrict access to devices that meet minimum security standards. Microsoft 365 and Google Workspace both have basic device compliance policies that can block access from devices without a screen lock or with outdated operating systems.

Software Updates: The Overlooked Priority

Here’s the thing about mobile security that catches a lot of people out: the biggest risk isn’t usually a sophisticated targeted attack — it’s known vulnerabilities in apps or the operating system that haven’t been patched.

Keeping phones and tablets updated is one of the highest-value security actions you can take. iOS updates patch security vulnerabilities, often serious ones that are being actively exploited. Android updates do the same. Outdated devices, especially Android devices that manufacturers have stopped supporting, carry real risk.

The NCSC’s guidance is clear: devices should have automatic updates enabled and should be running a supported operating system. If a staff member is using a three-year-old Android phone that no longer receives security updates, that’s a risk you should take seriously — either by replacing the device or, at minimum, not using it to access sensitive business systems.

Basic MDM Without the Complexity

Mobile Device Management (MDM) sounds like enterprise IT territory, but the basic tools are accessible to small businesses and genuinely useful. You don’t need a full suite — you need to be able to enforce basic policies and remotely wipe a device if it’s lost or stolen.

For businesses already on Microsoft 365 Business Premium, Microsoft Intune basic MDM is included. It’s not simple to set up from scratch, but it provides remote wipe, basic compliance policies (screen lock required, minimum OS version), and the ability to selectively wipe company data from a personal device when someone leaves, without wiping their personal photos and messages.

For Apple-only environments, Apple Business Manager (free) combined with a basic MDM profile (using Apple’s own Configurator for very small teams, or a lightweight MDM like Mosyle Business at around £1–2 per device per month) provides remote lock and wipe, enforced screen lock, and app distribution.

For businesses that aren’t ready to implement MDM, the minimum you should have is this: ensure every device with access to business email can be remotely wiped if lost. On personal iPhones, this means staff have “Find My iPhone” enabled and you have a clear process for what happens if they report a lost device. On Android, Find My Device serves the same function. Make sure your staff know to report lost devices immediately rather than hoping they’ll turn up.

What to Do When a Device Is Lost

Have a plan before it happens, because the first hour after a device goes missing matters. The process should be: staff reports it immediately, you or a manager remotely locks the device (and wipes it if the data on it is sensitive or there’s reason to believe it was stolen rather than misplaced), passwords for any accounts accessed on that device are changed.

If the device was accessing business email or cloud storage, it’s worth checking your audit logs for any unusual access in the period before it was reported. Microsoft 365 and Google Workspace both provide sign-in activity logs that show recent access times and locations.

Under UK GDPR, if a lost device contained personal data about customers or staff and you can’t confirm it was encrypted, you may have a reportable breach obligation to the ICO. This is another reason why encryption (which is automatic with a screen lock on modern devices) matters — it’s not just security, it’s your GDPR risk management for the most common loss scenario.

None of this is complicated. Screen locks, updates, a basic BYOD policy, and a plan for lost devices covers the vast majority of mobile security risk for small businesses. The cost is minimal; the downside of ignoring it is real.