Blog

Personal Devices & Unmanaged Device Security Still Loom Large

Operational Excellence
Risk Management
Personal Devices & Unmanaged Device Security Still Loom Large

For a while, everyone talked about BYOD. Then the language changed and the conversation moved to shadow IT. Now the spotlight is on AI, agentic tooling, and application sprawl.

The enterprise attack surface is changing quickly and attention is limited. Attackers know this, of course, and when you're looking left, they're liable to go right.

While remote and hybrid work models have matured, unmanaged device security remains one of the largest blind spots for enterprise security teams.

Fundamentally, not much has changed when it comes to the conditions that made unmanaged devices dangerous in the first place. A personal laptop used by a contractor or even a regular employee. A privately owned MacBook connecting through a browser-based SaaS workflow. A support engineer's home workstation holding cached credentials. An executive's tablet touching sensitive collaboration tools.

All these devices still create the same exposure pattern: enterprise access without enterprise-grade control. That remains as much a problem as ever.

Most organizations measure the devices they manage. Attackers measure the devices that can reach the business. Those are rarely the same thing.

If you want to understand your real attack surface, stop looking only at your management consoles and start looking at everything that can authenticate, connect, and borrow enterprise trust.

The Industry Moved On. Exposure Didn't

Mobile Device Management (MDM) platforms helped solve part of the original BYOD problem. It improved enrollment, policy distribution, remote wipe, certificate handling, and basic device governance for assets organizations could meaningfully manage. That was real progress.

But MDMs never solved the harder problem: what to do about devices you don't fully own, don't fully trust, and can't fully instrument.

That problem shows up every day in rogue device access, third-party support, temporary onboarding, partner collaboration, privileged remote administration, and hybrid work. In those scenarios, the enterprise often settles for partial control.

A VPN profile is issued. Browser access is allowed. Single sign-on is enabled. Maybe conditional access checks for a narrow set of attributes. Maybe it doesn't.

The result is more negotiated trust than full governance. An ideal environment for exposure to sneak in and slowly fester. 

Unmanaged Device Security Is A Matter of  Borrowed Trust

The old BYOD conversation was mostly about ownership. Who owns the laptop? Who pays for the phone? Who has the right to install an agent?

That is no longer the most useful frame. Instead operators should be thinking in terms of the enterprise trust that a personal device borrows when it connects?

That borrowed trust can include:

  • Valid user credentials
  • Long-lived SaaS sessions
  • Browser-stored tokens
  • Remote desktop clients and support tools
  • Access to internal documentation and collaboration platforms
  • OAuth grants into approved business applications
  • Local copies of regulated or sensitive data

From an adversary's point of view, that's plenty. An attacker doesn't need the device to be corporate-owned. The attacker only needs the device to be accepted by the surrounding environment long enough to turn access into movement.

Get smarter. Get stronger.Tired of Solution Confusion? Get the Guide

That is why this topic deserves renewed attention now. In an AI-heavy enterprise, personal-device risk is no longer only about unmanaged hardware. It is about unmanaged endpoints carrying identity, policy exceptions, AI access, and data pathways into systems that were designed around trust assumptions rather than continuous verification.

Why the Risk Persists Even In Mature Environments

The truth is that the shift from talking about shadow IT to talking about BYOD somewhat misses the mark. The reason unmanaged device security remains a real stumbling block for enterprises is not because security teams are truly unaware of them. It's because operational controls are uneven and the exceptions are persistent.

Most organizations already know the basic playbook. Require MFA. Use MDM where possible. Segment access. Apply conditional policies. Review third-party access. None of that is wrong.

But that's not enough on its own since the real gap usually appears in the last mile:

  • A contractor cannot install your full endpoint stack
  • A personal machine accesses approved SaaS tools through a browser, outside traditional device controls
  • A support exception created for speed becomes a durable access path
  • A local security setting drifts after a software update or user action
  • A remote management utility is installed for legitimate reasons but is never reevaluated
  • Cached credentials, saved sessions, or inherited permissions outlive the business need that justified them

That combination of partial visibility and partial enforcement is what keeps exposure alive. A quarterly compliance report doesn't mean you were compliant yesterday. It only proves you were compliant long enough to generate a report.

MDMs Solved the Enrollment Problem. Not  the Trust Problem

There is a tendency to treat MDMs as the chapter that closed the BYOD problem.

Would that it were so.

MDMs are valuable, but they work best where organizations have enough ownership, leverage, or user consent to enforce enrollment and maintain policy integrity over time. That makes a world of difference in many corporate mobile use cases and for portions of the managed fleet.

But it loses it's luster in messy real-world day-to-day scenarios like:

  • Employees or contractors using personal devices outside of MDM governance
  • Third parties with temporary operational access
  • Remote troubleshooting from nonstandard endpoints
  • Browser-based access patterns that bypass heavyweight endpoint controls
  • Unmanaged or under-managed tools tied to enterprise data

Even within the managed estate, posture can drift. Security settings decay. Exceptions accumulate. Operators make one-off changes to keep work moving. Software conflicts create quiet deviations from baseline. A device can remain enrolled and still stop being trustworthy.

That is why device ownership is a weak proxy for device assurance.

Personal Devices + AI = Trouble

This is where the conversation becomes more relevant, not less.

As AI adoption expands, personal devices are no longer just endpoints connecting to email and files. They increasingly become operating surfaces for browser-based copilots, desktop AI assistants, agentic workflows, code tools, meeting summarizers, plugins, and connectors into enterprise systems.

The most dangerous AI endpoint isn't the model. It's the unmanaged browser session that's already authenticated to everything the model can reach.

Indeed, IBM found that 97% of organizations reporting an AI-related breach lacked proper AI access controls, while 63% lacked mature AI governance coverage or were still developing it.

Those stats point to a greater truth: unmanaged personal devices often become the least governed place where those AI interactions actually happen.

A sanctioned AI initiative may be tightly reviewed in principle, while the day-to-day reality looks very different:

  • Employees use personal browsers with saved enterprise sessions
  • Contractors connect approved AI tools from unmanaged endpoints
  • Browser extensions and desktop assistants retain access longer than intended
  • Local prompt history, downloaded outputs, and copied data escape centralized control
  • OAuth scopes granted for convenience exceed what the user or workflow truly needs

This is not mainly a model problem, it's an environment control problem. And personal devices are one of the most common environments where that control problem becomes visible.

The Real Issue Is Not Unmanaged Devices, But Unmanaged Exceptions

There is a useful lesson from how remote access risk behaves.

RDP, SSH, Quick Assist, TeamViewer, AnyDesk, ScreenConnect, and similar tools are not themselves the problem. The problem is when organizations lose track of which uses are sanctioned, temporary, justified, and still safe.

The same logic applies to personal devices.

The real risk is not simply that a non-corporate endpoint exists, but that a non-corporate endpoint accumulates exceptions faster than governance can keep up. Exceptions have a habit of outliving the business reasons that created them. Attackers simply inherit them.

That creates a form of endpoint exception drift:

  • Temporary access becomes standing access
  • Minimum posture checks are waived and never restored
  • Session trust outlives the original purpose
  • Sensitive workflows expand onto devices never designed to support them
  • Local changes create configuration drift that nobody validates in time

Once that happens, the organization is no longer managing device trust. It is inheriting device trust and hoping the assumptions hold.

Hope is not a viable security strategy.

What Mature Organizations Do Differently

The answer is not to ban all personal devices. That's operationally unrealistic and strategically beside the point. The better approach is to replace ownership-based confidence with continuous posture-based trust.

So ask yourself: where is enterprise trust being borrowed by endpoints we do not continuously control?

That framing covers personal devices, contractor machines, temporary support systems, lightly managed admin workstations, and unmanaged endpoints participating in AI-enabled workflows.

It also explains why this issue has persisted across so many branding cycles. BYOD was the first label. Shadow IT was the next one. AI is the current one. But underneath those changing labels is the same structural problem: the enterprise keeps extending trust faster than it extends control.

That is the exposure and to get ahead of it, you need to be able to do these five things well.

1.  Discover beyond the enrolled fleet

Your EDR, MDM, and identity consoles do not always describe the full environment. 

You need network-aware discovery, access-path visibility, and a way to surface endpoints that interact with enterprise resources even if they sit outside traditional enrollment models.

If a device can reach your data, identities, or remote administration pathways, it belongs in your exposure model.

2.  Treat access decisions as posture decisions

Do not reduce device trust to a binary enrolled/not-enrolled field.

Before high-value access is granted, validate the controls that actually matter for the workflow: disk encryption, local firewall state, remote access tooling, patch posture, browser hygiene, privilege configuration, and whether risky exceptions are present.

This is especially important for third-party access, contractor onboarding, and privileged support workflows.

3.  Control the support-tool layer

Remote administration utilities deserve more scrutiny than they often receive. Sophos' finding that RDP was present in 84% of its MDR and IR cases is a useful reminder that legitimate tools remain highly valuable to adversaries when governance is weak.

Inventory them. Differentiate sanctioned from forgotten. Remove what is unnecessary. Revalidate what remains.

4.  Extend AI governance down to the endpoint reality

AI governance that lives only in policy documents will not keep pace with actual adoption.

You need to know which tools are present, which browser extensions and local assistants are active, what connectors they invoke, which scopes they hold, and whether they conform to your intended policy over time.

That is where continuous visibility and continuous enforcement become materially more useful than periodic review.

5.  Make safe remediation operationally credible

This is the part many programs still miss. Organizations often know what to change. What slows them down is fear. They worry that revoking access, disabling a setting, or removing a utility will break a workflow somebody depends on.

That is why the path forward cannot be detection-only. It has to include safe remediation, dependency awareness, validation after change, and rollback when business conditions require it.

Without that, known exposures remain open because nobody feels confident enough to close them.

From Ownership to Enforceable Posture

Security teams do not need another lecture on unmanaged device security. Most already understand the category.

What they need is a way to operationalize control without creating helpdesk chaos, slowing the business, or forcing every decision into a manual exception queue.

That means:

  • Continuous discovery of endpoints touching enterprise systems
  • Business-aware posture validation before sensitive access is granted
  • Control over remote administration pathways and risky local utilities
  • Governance for AI tools and connectors at the actual endpoint layer
  • Push-button remediation where possible
  • Safe remediation with rollback where required
  • Continuous enforcement so posture does not decay after the first cleanup

This is where the conversation around personal devices becomes strategically useful again. Not as nostalgia for the BYOD era, and not as a generic warning about shadow IT, but as part of a broader shift from passive visibility to enforceable posture.

The organizations that reduce risk fastest over the next few years will not be the ones that merely catalog unmanaged endpoints. They will be the ones that can validate, harden, and govern the trust those endpoints borrow from the business.

The future of endpoint security isn't defined by who owns the device. It's defined by who controls the conditions under which that device is trusted. That is what continuous risk reduction looks like in practice.


Ready to transform your fragmented security stack into a unified,  outcome-driven defense system?

Unify Visibility and Enforce PostureImplement continuous exposure management  to eliminate persistent risk Download Now


FAQ

Why are personal devices still a cybersecurity risk if organizations use MDM?
Mobile Device Management (MDM) helps organizations enroll and configure devices they own or control, but it cannot fully govern every endpoint that accesses enterprise resources. Contractors, temporary staff, browser-only users, remote support devices, and unmanaged endpoints often fall outside traditional management while still authenticating to business applications. The real challenge is continuously validating trust, not simply confirming enrollment.
How has AI changed the security risk posed by personal devices?
AI has significantly expanded what a trusted browser session can access. Personal devices now interact with copilots, AI assistants, browser extensions, coding tools, and SaaS connectors that can access enterprise data. If those devices are not continuously governed, they can become pathways for data exposure, excessive permissions, and unauthorized AI interactions.
What does "borrowed trust" mean in cybersecurity?
Borrowed trust refers to the privileges a personal or lightly managed device inherits when it connects to enterprise systems. Rather than owning the device, organizations effectively lend it access through user credentials, browser sessions, OAuth tokens, remote administration tools, and application permissions. Attackers often target this borrowed trust instead of the device itself.
Why aren't periodic security audits enough for personal-device risk?
Personal-device risk changes continuously as software updates, browser extensions, user behavior, permissions, and AI tools evolve. A device that met policy during an audit may drift out of compliance days later. Continuous visibility and enforcement are more effective than point-in-time assessments for reducing long-term exposure.
What should organizations monitor beyond device ownership?
Organizations should monitor the trust conditions surrounding every endpoint, including identity posture, browser sessions, local security settings, AI tools, remote administration utilities, OAuth permissions, configuration drift, and access to sensitive business resources. These factors provide a more accurate picture of enterprise exposure than ownership alone.
How can organizations reduce personal-device risk without disrupting users?
The most effective approach combines continuous discovery, posture validation, risk-based access decisions, governance of support and AI tools, and automated remediation with validation and rollback capabilities. This allows security teams to reduce exposure while minimizing operational disruption.
Are unmanaged personal devices always unsafe?
Not necessarily. Risk depends on the conditions under which a device is trusted. Some personal devices can safely access enterprise resources when appropriate security controls, identity verification, posture validation, and continuous monitoring are in place. The objective is to govern trust continuously rather than relying on device ownership as a security boundary.
What is the biggest mistake organizations make with BYOD and personal devices?
Many organizations assume that because BYOD is no longer a major discussion topic, the underlying risk has diminished. In reality, unmanaged devices continue to access enterprise identities, SaaS applications, AI platforms, and remote administration tools. The challenge has shifted from managing devices to continuously governing the trust those devices receive.

About Author

Ilan Mintz

Ilan Mintz

Full-stack Marketer

A full-stack marketer with over 10 years of experience helping startups build brands for global success, Ilan's a firm believer in the transformative power of a well-crafted story. Ilan excels at generating human connection to and through technology and relishes opportunities for creative thinking and problem-solving. Ilan’s favorite things include his family, obscure facts, philosophy, gardening, and believing that this year will finally be different for the Minnesota Vikings.

Fix Misconfigurations Without Fear

Automate configuration security while keeping full control.

Book a Demo