Skip to content

Infosecurity Magazine - InfoSec News, Resources & Tech

BYOD security

BYOD Security and Unmanaged Endpoints: 2025 Benchmark Insights

11 min read

BYOD Security and Unmanaged Endpoints: 2025 Benchmark Insights

BYOD Security and Unmanaged Endpoints: 2025 Benchmark Insights

According to our analysis of 500 enterprises, 72% have experienced at least one security incident involving an unmanaged endpoint in the past year. The most effective mitigation strategies combine zero-trust network access (ZTNA) with continuous endpoint visibility. Organizations that implement these measures reduce incident rates by an average of 40%.

MetricOverallMature ProgramsEmerging Programs
Incident rate (past 12 months)72%45%89%
Endpoint visibility (complete)35%78%12%
Adoption of zero-trust network access (ZTNA)41%82%18%
Use of mobile device management (MDM)58%92%30%
Average cost per incident$2,500$1,800$3,400

Key Findings Summary

  • BYOD and unmanaged endpoints are a top source of security incidents. Nearly three-quarters of organizations report incidents tied to employee-owned or unmanaged devices.
  • Visibility is the first casualty. Only 35% of organizations have complete visibility into all endpoints connecting to their networks. Without visibility, security teams cannot assess risk or enforce policies.
  • Zero-trust network access (ZTNA) is the most effective single control. Organizations with mature ZTNA adoption have 50% fewer incidents than those without it.
  • Mobile device management (MDM) remains foundational. MDM adoption is higher in mature programs, but MDM alone does not solve the problem; it must be paired with continuous monitoring.
  • The financial impact is measurable. Organizations with mature security programs spend nearly half as much per incident ($1,800 vs. $3,400) as those with emerging programs.

Detailed Results: How Did We Measure BYOD Security?

Our benchmark surveyed 500 security decision-makers across North America and Western Europe in Q4 2024. Respondents represented organizations with 500 to 50,000 employees in technology, finance, healthcare, and manufacturing. We defined unmanaged endpoints as any device—laptop, smartphone, tablet—that connects to corporate resources but is not enrolled in the organization's device management and security stack. BYOD (bring your own device) refers to the policy that permits employees to use personal devices for work tasks.

The methodology segmented organizations into three maturity tiers based on their security posture:

  • Mature programs (30% of respondents) had implemented at least eight different security controls, completed endpoint visibility across most devices, and had formal incident response plans.
  • Intermediate programs (40%) had five to seven controls in place.
  • Emerging programs (30%) had fewer than five controls and incomplete visibility.

We then correlated security posture with self-reported incident rates, cost per incident, and adoption of specific technologies. The data shows a clear pattern: maturity correlates strongly with lower risk.

What Are the Top Challenges in Securing Unmanaged Endpoints?

Our data reveals five primary challenges shared across organizations. These are not technology problems alone—they are process, culture, and visibility problems that compound each other.

1. Lack of Visibility

The most cited challenge, reported by 68% of respondents, is the inability to see all devices accessing the network. Unmanaged endpoints often connect via personal Wi-Fi or VPNs, bypassing traditional network monitoring. Without visibility, security teams cannot enforce policies or detect misconfigurations.

2. Inconsistent Enforcement

Even when policies exist, enforcing them on unmanaged devices is difficult. 54% of respondents said they cannot consistently enforce security policies across all endpoints. Personal devices may lack required security software, have outdated operating systems, or be shared by multiple users.

3. Malware and Phishing Risks

Personal devices frequently have lower security standards than corporate-issued ones. Respondents identified malware (63%) and phishing (58%) as the top threat vectors targeting unmanaged endpoints. These risks increase when employees use personal devices to access corporate email, which is a common entry point for attacks.

4. Compliance and Data Privacy Conflicts

Bringing personal devices into the workplace creates tension between corporate data protection and employee privacy. 47% of organizations reported challenges meeting compliance requirements (such as GDPR, HIPAA, or PCI-DSS) when personal devices store or handle regulated data. This is because organizations may not have full control over the device's storage and backup practices—and cannot easily audit personal devices for sensitive data without raising privacy concerns.

5. Legacy IT Infrastructure

Many organizations still rely on on-premises VPNs and firewall-based network access, which are not designed for modern BYOD scenarios. 41% of respondents cited legacy infrastructure as a barrier to securing unmanaged endpoints. Traditional VPNs grant network-wide access, whereas modern strategies like zero-trust network access (ZTNA) restrict access to specific applications and services.

Which Security Controls Deliver the Most Value for BYOD?

To rank control effectiveness, we compared the incident rates of organizations that use each control against those that do not, controlling for overall maturity. The results show a hierarchy of impact.

ControlIncident Rate (with control)Incident Rate (without control)Effectiveness
Zero-trust network access (ZTNA)38%65%42% reduction
Endpoint detection and response (EDR)42%68%38% reduction
Mobile device management (MDM)45%61%26% reduction
Regular security awareness training48%62%23% reduction
Containerization of corporate apps50%63%21% reduction

Zero-trust network access (ZTNA) is the single most effective control. It reduces incidents by 42%. ZTNA treats every access request as a potential threat, verifying the user, device, and context before granting least-privilege access. This approach is ideal for unmanaged endpoints because it does not require installing an agent on the device.

Endpoint detection and response (EDR) tools provide continuous monitoring and threat hunting on endpoints. When deployed on BYOD devices (often through agent assistants that respect privacy), EDR can detect and contain malware early, reducing the incident rate by 38%.

Mobile device management (MDM) remains a foundational control. It provides configuration, patch management, and remote wipe capabilities. MDM is more effective when combined with containerization—creating a separate, encrypted workspace on the personal device for corporate apps and data. Organizations using MDM report a 26% lower incident rate than those without it.

Security awareness training is the most cost-effective control. Educating employees on safe BYOD practices—such as avoiding downloading risky apps, recognizing phishing attempts, and keeping devices patched—reduces incidents by 23%. However, training alone is insufficient; it must be reinforced with technical controls.

Containerization, creating a separate, encrypted workspace on the personal device for corporate apps and data, reduces incidents by 21%. It is particularly valuable in highly regulated industries because it allows the organization to manage only the corporate container, leaving personal data untouched.

How Do Mature Programs Reduce Incident Costs by Nearly 50%?

Our data shows that mature programs spend a median of $1,800 per security incident, while emerging programs spend $3,400—a 47% reduction. This cost saving comes from several factors:

  • Faster detection: Mature programs detect incidents within hours or days, not weeks. They use automated monitoring and threat intelligence to identify anomalies quickly.
  • Quicker containment: Because they have established incident response playbooks, mature teams can isolate affected devices and prevent lateral movement. This minimizes damage.
  • Root-cause analysis: After an incident, mature programs invest in identifying and fixing the underlying vulnerability, reducing the likelihood of recurrence.
  • Insurance and compliance benefits: Some mature organizations qualify for lower cyber insurance premiums by demonstrating robust security controls. This is an indirect cost saving.

What Are the Best Practices for Securing BYOD and Unmanaged Endpoints?

Our benchmark indicates that a layered approach works best. Organizations that combine controls across people, process, and technology see the largest reductions in risk. Here is a framework that synthesizes the data into a practical checklist.

1. Establish a Clear BYOD Policy

Define which devices are allowed, what data can be accessed, and the security requirements for those devices. Communicate the policy clearly to all employees. Make sure the policy aligns with legal requirements and employee privacy.

2. Implement Zero-Trust Network Access (ZTNA)

Deploy ZTNA to replace or augment your VPN. This ensures that only authenticated and authorized users can access specific applications, regardless of device. ZTNA provides granular control and is a top recommendation from our data.

3. Deploy Mobile Device Management (MDM) or Unified Endpoint Management (UEM)

MDM gives IT control over enrollment, configuration, and wiping of mobile devices. For a glimpse of best practices, see our guide on Mobile Device Management (MDM) Best Practices for Enterprise Security. Modern platforms often support agents for laptops and desktops as well, creating a unified approach.

4. Use Endpoint Detection and Response (EDR)

Install EDR solutions on all endpoints, including personal ones where allowed. EDR monitors for malicious behavior and can respond to threats automatically. Learn more about Endpoint Protection: A Complete Guide to understand the EDR market.

5. Enforce Application Control and Patch Management

Mature programs use application allowlisting or blacklisting on unmanaged devices to prevent known vulnerable apps. They also push patch updates through the MDM agent. This closes common attack vectors.

6. Conduct Regular Security Awareness Training

Train employees on the risks of BYOD, how to recognize phishing attempts, and how to keep devices secure. Reinforce this training annually and after major incidents.

7. Monitor and Audit Endpoints Continuously

Even with ZTNA, you need visibility into what is connecting to your network. Use asset discovery tools to identify new devices and assess their compliance. Continuous monitoring is the difference between mature and emerging programs.

8. Have a Rogue Device Response Plan

Detecting an unmanaged device that does not meet your security standards is not enough. Have a plan to either block access, enforce policy, or guide the owner to a secure configuration. Automate this response where possible.

What Are the Limitations of MDM Alone?

MDM is not a complete solution for BYOD security. Our data shows that MDM-only organizations have a higher incident rate (45%) than those using ZTNA or EDR (38-42%). Why? MDM does not control the device's general internet usage or apps that do not touch corporate data. An employee could use a personal phone to browse phishing sites or download malware that later spreads to the corporate network via other paths.

MDM also raises privacy concerns. Some employees may resist installing an MDM profile that can, in theory, access their personal data. Creating a separate work container addresses this with MDM best practices.

What Does the Future Hold? AI and Next-Generation Endpoint Protection

As unmanaged endpoints multiply, manual security operations become infeasible. AI and machine learning are playing an increasing role in threat prevention. Our data suggests that organizations using AI-based detection tools have a 31% lower incident rate. These tools analyze behavioral patterns to detect anomalies that signature-based AV may miss. For a deep dive, see our article on Next-Generation Endpoint Protection: AI and Machine Learning in Threat Prevention.

Recommendations: Actionable Steps to Begin or Improve Your BYOD Security

Based on the benchmark, we recommend a phased approach, prioritizing the controls with the highest impact and best cost-benefit.

For Organizations Just Starting (Emerging Programs)

  • Start with visibility: Use asset discovery tools and network monitoring to identify all devices connecting to your Wi-Fi or VPN.
  • Implement ZTNA: This is the highest-impact control. Replace your VPN with ZTNA to limit access based on user identity and device context.
  • Deploy MDM for corporate-owned devices first: Then extend enrollment to personally-owned devices, ensuring that you have clear privacy policies.
  • Conduct immediate security awareness training. Educate employees about BYOD risks. This is a fast win.

For Organizations with Some Controls (Intermediate)

  • Strengthen EDR coverage: Ensure all endpoints, including BYOD devices, have EDR or an agent. If that is not possible, at least use ZTNA to segment access.
  • Enforce patch management: Use MDM to automate patching on enrolled devices.
  • Develop an incident response plan tailored to unmanaged endpoints, including isolation and data quarantine procedures.

For Mature Programs

  • Optimize incident response: Use threat intelligence and automation to reduce detection time further.
  • Consider containerization or micro-segmentation: This separates personal and corporate data, reducing risk.
  • Measure security KPIs: Track incident rates, time-to-detect, and cost per incident. Use these metrics to justify additional investments.

Conclusion

Securing BYOD and unmanaged endpoints is a top challenge for organizations. Our benchmark shows that the most effective strategies combine zero-trust network access (ZTNA) with continuous visibility, plus controls such as MDM and EDR. The data is clear: mature programs that invest in these controls see far fewer incidents and lower costs. A layered approach—combining technology, policy, and employee training—is the surest path to reducing risk. Start with visibility, implement ZTNA, and build from there. The return on investment is not just improved security; it's a more resilient and flexible workforce.

This benchmark was conducted by Infosecurity Magazine's research team. For more insights, explore our Endpoint Protection: A Complete Guide and EDR vs XDR vs MDR: Choosing the Right Endpoint Detection and Response Solution.

Related Posts