
Personal devices are the security boundary your business doesn’t control, but should.
Your business is only as secure as your bookkeeper’s phone. Quick gut check: does anyone on your team check work email from their personal phone, or log into a shared drive from their home laptop while the kids are watching TV? If you run a small or medium business in Tasmania, the honest answer is almost certainly yes, and that’s not a criticism. It’s how small businesses operate. But it’s also, increasingly, how they get compromised.
Over the past year, Pritech’s cyber security team, led by Max von Saurma, has investigated multiple incidents involving Tasmanian small businesses where the point of entry wasn’t a weak password or an unpatched server. It was a personal phone or home computer that sat completely outside the business’s security controls. In more than one of these cases, the business had multi-factor authentication switched on. MFA didn’t stop the attack, and that’s worth pausing on, because “we have MFA, so we’re covered” is one of the most common, and most dangerous, assumptions we hear from business owners.
How MFA Gets Bypassed Without Anyone Noticing
The attacks we’re seeing aren’t brute-force password guessing. They’re phishing pages designed to harvest a session token: the piece of data your browser holds onto after you’ve already logged in and passed MFA, so you don’t have to re-authenticate every five minutes. Steal that token and an attacker doesn’t need your password or your MFA code at all. They simply reuse the session. It’s exactly why personal devices matter so much. A phone or home laptop without endpoint protection, without managed updates, without any of the guardrails your office devices have, is a far easier place to harvest a session than a locked-down company laptop.
What These Businesses Had in Common
In the cases we’ve investigated over the past year, a pattern holds: these weren’t careless businesses. Each one had done the sensible, recommended things: MFA switched on, staff trained on phishing basics, a managed IT provider looking after their office systems. The compromise still happened, because none of those measures extended to the personal phone a staff member used to quickly check email on the couch, or the home laptop used to log into a shared drive over the weekend. The office was secured. The boundary around it wasn’t. That’s the uncomfortable, useful point of these case studies. This isn’t a story about a business that ignored security advice. It’s a story about a gap that sits just outside where most standard security advice looks.
This Isn’t About Telling Your Team Off
We want to be upfront about something. This article isn’t about shaming small businesses for letting staff work from their phones. Most owners we talk to are running their business the only practical way they can, and nobody’s budgeting for a second work phone for every casual staff member. The point isn’t that you’re doing it wrong. It’s that this is a risk you probably haven’t been shown, so you can’t yet decide what, if anything, to do about it. And every option here has a real cost, not only a financial one. Locking down personal devices with mobile device management can mean pushback from staff who don’t want company controls on their own phone. Doing nothing means the gap stays open. There’s no option that’s free.
What a Proportionate Response Looks Like
Start with knowing where your risk actually sits: which staff access email, files or client systems from personal devices, and what an attacker would reach if one of those devices were compromised. Conditional access policies can require a device to meet minimum security standards before it’s allowed to log in, without your business owning the phone, which separates convenient from unmanaged without a blanket rule that staff will only work around. Session tokens should be treated like passwords: they need to expire, and unusual sign-in locations or devices should trigger a review rather than sail through silently. And because devices, staff and roles change, this is worth revisiting at least once a year rather than setting and forgetting it. A boundary set up correctly two years ago is often stale today.
The Pritech Approach
At Pritech, we help Tasmanian businesses find this boundary and close it in a way that fits how the business actually operates, not a generic policy off the shelf. Through our partnerships with providers such as Microsoft, Sophos, ThreatLocker and Kaseya, we protect and manage the devices a business controls. Personal devices are the harder conversation, and it’s one we would much rather have before an incident than after.
If you’d rather talk it through directly, get in touch and we’ll help you work out where your own boundary sits.



