Your clients’ staff are working on personal phones and laptops your team doesn’t manage — but still ends up supporting. Independent research conducted by Omdia puts hard numbers on that gap: where the incidents start, what clients are asking for, and the line of revenue most MSPs haven’t written yet.
Straight to your inbox. No sales call attached.
What the research found
Omdia surveyed 319 US-based MSPs about the personal devices touching their clients’ data. The short version: the work is common, the controls are rare, and the demand is already sitting in your inbox.
had at least one BYOD-related security incident in the last 24 months*
have had clients ask for BYOD security in the last 12 months — 45% from multiple clients*
manage BYOD with no or limited technical controls in place*
corporate laptops monitored vs. employee-owned devices monitored*
*Market data based on independent research conducted by Omdia (N=319 US-based MSPs, Q1 2026).
The work is already yours
Every client you manage has staff on personal phones and laptops. When something goes wrong on one of them, the cleanup lands with your team — the password resets, the “can you check this link” messages, the Friday-afternoon phone call.
And chances are, none of that work makes it onto an invoice — because BYOD was never in the contract.
The report puts numbers on both sides of that trade: what unmanaged personal devices are costing MSPs in incidents and unbilled hours, and what the 65% of clients already asking for BYOD security are prepared to pay for.
Sound familiar?
A client’s employee gets phished on a personal device, and the mess is yours by Monday. You’ll lose half a day to it and bill nothing at the end — and it keeps happening, across every client you’ve got.
That’s not an unlucky week. It’s the pattern Omdia found across the industry: personal devices carry a growing share of the work and almost none of the monitoring. The report shows exactly where those incidents are coming from — so you can turn the Friday fire drill into a service line with a price on it.
Why the old playbook misses
BYOD risk used to mean a phone left in a taxi. Not anymore. When Omdia asked MSPs what their BYOD incidents actually involved, identity-driven attacks came out on top — and physical device loss came out bottom.
of BYOD incidents involved stolen logins — the front door to your clients’ systems*
of incidents involved business email compromise starting on a personal device*
ranked as a threat — the lowest of any category in the survey*
Attackers aren’t stealing phones. They’re stealing identities.
Inside the report
The incident data behind the 55% — what actually happened, to whom, and what it cost. Including the 16% of incidents that ended in confirmed data exposure.*
Why credential theft and email compromise now outrank the lost-phone problem — and what that means for tools built to manage hardware.
The demand side: 65% of MSPs have been asked for BYOD security. What clients want, and how MSPs are packaging it as a recurring line.
An identity-centric approach for the devices MDM can’t reach: protecting work access on personal devices without invasive control — and where the MSP fits.
*Market data based on independent research conducted by Omdia (N=319 US-based MSPs, Q1 2026).
Who’s behind the research
Aura Business closes the BYOD security gap with identity-centric protection that manages work access on personal devices — without requiring invasive control or complex deployment.
Instead of locking down hardware your clients’ employees own, Aura protects the person using it — so employees actually adopt it, and MSPs get a security layer (and a revenue line) for the devices they could never manage before.
Get The real BYOD threat: Identity, not devices — free, in your inbox in the next five minutes. Then decide what the missing line on your invoices should say.
Get the free report