Free Omdia research · For MSP owners

55% of MSPs had a BYOD incident in the last 24 months. Most cleaned it up for free.

Your clients’ staff are working on personal phones and laptops your team doesn’t manage — but still ends up supporting. Independent research conducted by Omdia puts hard numbers on that gap: where the incidents start, what clients are asking for, and the line of revenue most MSPs haven’t written yet.

  • The incident data behind the 55% — and why credential theft now beats lost devices
  • 65% of MSPs have clients asking for BYOD security. What they actually want from you
  • How to close the gap without invasive MDM — and get paid for work you’re already doing
OMDIA Independent research · 319 US-based MSPs surveyed · Q1 2026
Research report · PDF
The real BYOD threat:
Identity, not devices
Omdia × Aura Business · 2026

Get the full report

Straight to your inbox. No sales call attached.

Free · No spam · Unsubscribe anytime

Research by Omdia 319 US-based MSPs surveyed Fielded Q1 2026 Published by Aura Business

What the research found

The gap is bigger than most MSPs think. And clients already know it’s there.

Omdia surveyed 319 US-based MSPs about the personal devices touching their clients’ data. The short version: the work is common, the controls are rare, and the demand is already sitting in your inbox.

55%

had at least one BYOD-related security incident in the last 24 months*

65%

have had clients ask for BYOD security in the last 12 months — 45% from multiple clients*

78%

manage BYOD with no or limited technical controls in place*

79% vs 24%

corporate laptops monitored vs. employee-owned devices monitored*

*Market data based on independent research conducted by Omdia (N=319 US-based MSPs, Q1 2026).

The work is already yours

The revenue isn’t.

Every client you manage has staff on personal phones and laptops. When something goes wrong on one of them, the cleanup lands with your team — the password resets, the “can you check this link” messages, the Friday-afternoon phone call.

And chances are, none of that work makes it onto an invoice — because BYOD was never in the contract.

The report puts numbers on both sides of that trade: what unmanaged personal devices are costing MSPs in incidents and unbilled hours, and what the 65% of clients already asking for BYOD security are prepared to pay for.

Sound familiar?

It’s never the corporate laptop at 4:55 on a Friday.

A client’s employee gets phished on a personal device, and the mess is yours by Monday. You’ll lose half a day to it and bill nothing at the end — and it keeps happening, across every client you’ve got.

That’s not an unlucky week. It’s the pattern Omdia found across the industry: personal devices carry a growing share of the work and almost none of the monitoring. The report shows exactly where those incidents are coming from — so you can turn the Friday fire drill into a service line with a price on it.

Why the old playbook misses

The threat moved from the device to the person using it.

BYOD risk used to mean a phone left in a taxi. Not anymore. When Omdia asked MSPs what their BYOD incidents actually involved, identity-driven attacks came out on top — and physical device loss came out bottom.

45%
Credential theft

of BYOD incidents involved stolen logins — the front door to your clients’ systems*

42%
Email compromise

of incidents involved business email compromise starting on a personal device*

29%
Physical device loss

ranked as a threat — the lowest of any category in the survey*

Attackers aren’t stealing phones. They’re stealing identities.

Inside the report

Four sections. No jargon. Numbers you can take to a client meeting.

1

The danger is already here

The incident data behind the 55% — what actually happened, to whom, and what it cost. Including the 16% of incidents that ended in confirmed data exposure.*

2

A shift in the threat landscape

Why credential theft and email compromise now outrank the lost-phone problem — and what that means for tools built to manage hardware.

3

Your clients are already asking

The demand side: 65% of MSPs have been asked for BYOD security. What clients want, and how MSPs are packaging it as a recurring line.

4

Closing the gap

An identity-centric approach for the devices MDM can’t reach: protecting work access on personal devices without invasive control — and where the MSP fits.

*Market data based on independent research conducted by Omdia (N=319 US-based MSPs, Q1 2026).

Who’s behind the research

Aura Business, built for MSPs.

Aura Business closes the BYOD security gap with identity-centric protection that manages work access on personal devices — without requiring invasive control or complex deployment.

Instead of locking down hardware your clients’ employees own, Aura protects the person using it — so employees actually adopt it, and MSPs get a security layer (and a revenue line) for the devices they could never manage before.

Put a number on the gap.

Get The real BYOD threat: Identity, not devices — free, in your inbox in the next five minutes. Then decide what the missing line on your invoices should say.

Get the free report
Get the free report