It sounds reasonable. But allowing a personal computer to access your business is a little like giving someone a key to your office without knowing who else has access to their house, whether the doors are locked or whether a window has been left open.
The employee isn’t necessarily the problem. The unknown device is.
A real-world incident involving Disney demonstrates how quickly things can go wrong.
In 2024, a Disney employee downloaded what appeared to be an AI image-generation application onto his personal computer. The application was actually malicious. According to the U.S. Department of Justice, the attacker gained access to the employee’s computer, obtained credentials and ultimately accessed thousands of Disney’s internal Slack channels.
The employee didn’t intentionally put his employer at risk. He simply installed software on a computer that his employer didn’t manage.
And that is exactly where the risk lies.
On a company-owned computer, your IT team can control security updates, company-approved antivirus and endpoint protection, encryption, applications and access policies.
A personal computer is different.
It may have games, browser extensions, free utilities, file-sharing programs or old applications that your IT team doesn’t even know exist. Some may be malicious; others may simply contain vulnerabilities that haven’t been patched.
Your business may have strong security policies in place for company-managed devices, but those protections can be undermined when employees are allowed to connect from unmanaged personal computers. Because these devices may not meet the same security requirements, they can create additional opportunities for attackers to access business systems and networks.
This is a common misconception.
A VPN can secure the connection between the employee and the business. It does not automatically make the employee’s computer secure.
Think of a VPN as a secure tunnel into your office. The tunnel itself may be extremely well protected, but if you allow a compromised device through the tunnel, you may simply be providing that device with a secure route into your network.
If malware is already running on an employee’s personal computer, connecting that computer to the corporate VPN can potentially expose internal systems and resources.
For Quebec businesses, there is another consideration: personal information.
Employees working from personal computers may access or download customer records, employee information, contracts and other confidential data.
Under Quebec privacy requirements, businesses are responsible for protecting the personal information they collect and hold throughout its lifecycle. Allowing company information to reside on unmanaged personal computers can make that responsibility significantly harder to manage.
In our opinion, yes, the wiser choice is a company-owned, professionally managed computer.
The real risk isn’t what’s stored on an employee’s personal device, it’s what that device can access: Microsoft 365, email, Teams, SharePoint, business applications, customer data and company credentials.
It only takes one compromised session. Whether an employee works remotely five days a week or a few days a month, the risk remains.
A laptop may feel like an unnecessary expense for occasional remote work, but the real comparison is the cost of a managed device versus the potential cost of unmanaged access to your business.
If personal devices must be used, businesses should establish a formal BYOD policy and put technical controls in place to limit what those devices can access.
Give employees flexibility without giving up control. Present can help you secure remote access, manage devices and protect company data without making remote work unnecessarily complicated.