The incident data shows that BYOD risk is less about lost hardware and more about compromised identities.
In the Omdia survey, 55% of MSPs reported at least one BYOD-related security incident in the past 24 months where an unmanaged personal device played a material role. Among those incidents:
- 45% involved credential theft or account compromise.
- 42% involved email or messaging compromise, often phishing.
- 40% involved malware.
- 31% involved data leakage (files, screenshots, messages).
- Only 29% involved lost or stolen devices.
This pattern shows that the primary BYOD risk has shifted to the identity layer rather than the physical device. Attackers are targeting credentials and sessions on personal devices that connect to corporate systems, and then using those identities to move further into the environment.
MSPs with higher annual recurring revenue (above $10 million) reported a 61% BYOD incident rate, compared with 52% for smaller MSPs. This likely reflects better detection rather than lower risk for smaller providers, suggesting that the overall 55% incident figure may understate the true prevalence.
For MSPs, this means that BYOD governance can’t be limited to device-centric controls. It needs to address identity, credentials, and sessions alongside traditional endpoint protections.