Skip to main content
MSP resources
Article
Article

The BYOD Gap is an Identity Problem, and MSPs Know It

If you’ve been in the MSP space for the last five years, you’ve watched cybersecurity evolve from a line item to a core practice. Supply chain attacks in the early 2020s forced a collective reckoning: the tools MSPs use to protect end customers can themselves become attack vectors. That pushed providers toward more sophisticated  offerings like managed detection and response.

But the evolution didn’t stop at MDR. MSPs are increasingly operating as cyber resilience providers, not just security vendors. The shift from perimeter-based protection to zero trust models after COVID changed the calculus. The goal now is layered defense: endpoint controls, threat detection, and identity-level protections working together. Customers aren’t asking for acronyms. They’re asking for an outcome, which is the most comprehensive protection with the least friction.

And yet there’s one device category that’s been largely left out of that layered approach: employee-owned devices. Personal phones, laptops, and tablets that employees use every day to check email, open files, and access corporate systems. In most cases, these devices sit outside the managed perimeter entirely.

MSPs have avoided managing devices they don’t own for understandable reasons. Operational complexity, liability, the reality that employees don’t want their employer’s MSP controlling their personal phone. Those were rational concerns when the available tools required per-device configuration and gave MSPs ownership of a personal device. But the threat landscape has moved on.

The risk we used to worry about most on mobile was a lost or stolen device. The answer was simple: wipe it. Today, the actual threat is someone’s credentials getting compromised on a personal device that has access to corporate email, files, and systems. The device doesn’t need to leave the employee’s hand for that to happen.That means approaches anchored primarily to device management address an important layer, but not the most commonly reported threat vector. Protection also needs to follow the credential.

That’s the gap. And when Omdia went looking for data to test whether it’s a real problem or just a perceived one, the answer came back clearly.

What the data shows

In Q1 2026, Omdia surveyed 319 US-based MSPs, all deriving more than half of their revenue from managed services, on how they’re handling BYOD security. The highlights:

  • Demand is real: 65% of MSPs said at least one end customer has asked for help with BYOD security in the past 12 months. 45% said multiple customers have raised it.
  • Incidents are common: 55% reported at least one BYOD-related security incident in the past 24 months. Among MSPs above $10M in ARR, that climbed to 61%, likely reflecting a detection gap rather than a difference in actual exposure.
  • The incident profile is identity-driven: Credential theft leads at 45%, followed by email compromise (42%), malware (40%), and data leakage (31%). Lost or stolen device comes in last at 29%.
  • Coverage lags far behind: 79% of MSPs monitor corporate-owned laptops and desktops. Only 24% cover employee-owned devices.
  • MSPs are ready to move: 92% can envision a delivery model for BYOD security. The preferred approach is an optional add-on (36%), followed by inclusion in a security bundle (28%). Only 8% said they wouldn’t offer it under any model.

The pattern across this data is a market where demand, incidents, and delivery preferences have converged. MSPs that adapt their security stacks to follow the credential rather than the hardware will be better positioned to close the unmanaged BYOD gap without adding friction for end users. In a market that increasingly valuesoutcomes over tooling, solving the BYOD identity problem is a natural extension of the cyber resilience model MSPs are already building.

Jessica's Bio

Jessica C. Davis is a principal analyst in the managed services practice at Canalys, part of Omdia. She delivers research and insights on the evolving MSP and MSSP ecosystems, focusing on how service providers adopt emerging technologies including cybersecurity, AI, and automation to drive growth. Her work also encompasses M&A and investment activity among MSPs. Jessica supports vendors, distributors, and MSPs with market intelligence that informs channel strategy and partner engagement.

Prior to joining Canalys, Jessica spent nearly 30 years as a technology journalist and editorial leader. She served as editorial director at CyberRisk Alliance, leading B2B media brands covering managed services and cybersecurity. Earlier, she was a senior editor at InformationWeek, reporting on enterprise IT and AI before the rise of generative AI. She has led major industry research initiatives including the MSP 501, MSSP Benchmark Pricing Survey, and MSSP 250.

See the Aura Business difference in action. Book a demo today
Share:
LinkedIn logo, link to navigate to Aura's LinkedIn pageFacebook logo, link to navigate to Aura's Facebook page