Who Pays for BYOD?

Mar 3, 2014 | App Modernization, Cloud, Data, Fresh Ink, Mobile, Security, Social Media

There are many factors businesses must consider when creating a BYOD policy. Most businesses tend to focus on security and for good reason, but it’s important to not overlook the cost factor for BYOD, in particular the cost sharing between the employee and the company.

It would seem that the question of who pays for the device is answered in the term itself—“own device.” It seems natural that for an employee to truly own their laptop or smartphone, they must be the one to pay for it. Some employees will prefer this because it means the company won’t interfere in selecting or caring for the device or try to claim partial ownership of it when the employee leaves the company. On the other hand, employees may feel that because they are using their device for company projects that the company should help cover the costs.

Be sure to have a clear policy in place of who must pay for this device, as well as how any discounts or stipends the company offers will be dispersed. Businesses should also make it clear if any device will not be supported by the company for security or logistical reasons.

Probably the bigger factor of cost sharing, however, is paying for the actual minutes and data that the employee uses on behalf of the company. Companies may not want to foot the whole cellphone bill or data plan when the employee is using the device for personal use, but expecting the employee to pay for everything is hardly ethical either.

There are a number of ways businesses can address this issue. You could offer to pay a fixed amount or a percentage of the phone bill. Companies may be able to make a deal with a carrier that gives the employee a discount for using the service. This option only works of course if the employees want to go through that particular carrier. Using software that tracks which data is used for company business and which is used for personal could provide a more accurate account of what the company should pay, but employees may object to having their devices constantly monitored.

Needless to say, there is not an obvious solution that easily applies to every situation. What are businesses currently doing? A survey by Good Technology found that in 50 percent of companies, employees pay the full amount both to purchase the device and to pay for the service plan. 24 percent of companies offered a stipend toward the device and service cost, and 19 percent paid for the employees’ expenses. A survey by Samsung found slightly different results with 28 percent of companies expecting employees to cover the full cost.

So what should your company do? This will depend on many factors, including the resources at your disposal, the expectations of employees and how crucial allowing BYOD at your company really is. Consult with a legal advisor while constructing your BYOD policy, and once you have it set, be sure it is communicated clearly to every employee.

 

by Rick DelGado, Independent Author

I’ve been blessed to have a successful career and have recently taken a step back to pursue my passion of writing. I’ve started doing freelance writing and I love to write about new technologies and how it can help us and our planet.” – Rick DelGado

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more
Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

July 24, 2026 | ITBriefcase.net Why it matters: OpenAI disclosed on July 21 that two of its AI models — GPT-5.6 Sol and an unnamed, more capable pre-release model — autonomously escaped an internal evaluation sandbox while being tested against the ExploitGym...

read more