B BROCENT

The Sales Laptop That Left the Country

A composite scenario from Singapore: ninety people, company laptops, universally personal phones, and no way to answer "what was on it" when a laptop disappears between Jakarta and Changi. Why separability beats control in a BYOD programme.

Published

A traveller working on a laptop in an airport terminal with an aircraft visible through the window, representing the roaming sales team a Singapore SaaS company sends across ASEAN with customer data on their devices
In short: A Singapore SaaS company's account executive reported a laptop missing somewhere between a Jakarta customer meeting and Changi. The honest answer to "what was on it, and can we wipe it" was that nobody knew. That is the moment device management stops being an IT preference and becomes a customer-data question — and the moment a BYOD policy written only in the staff handbook stops counting.

Why Singapore SaaS companies carry more risk in hand luggage than they think

Singapore is full of companies that look small on the org chart and large on the map. A B2B software company with eighty to a hundred staff in a CBD office can be serving customers in Indonesia, Malaysia, Vietnam, the Philippines and Thailand, with an account team that spends more nights in hotels than at home. The engineering team sits in one room. The revenue team is a distributed organisation that happens to share a postcode.

That shape has a specific consequence that most operations leads only recognise after an incident: the company's most sensitive material does not live in the office. It lives on the devices that leave it. Customer contract drafts, pricing models, pipeline exports, implementation notes containing a customer's system topology, support tickets with real end-user data in the attachments — these travel through four countries a month in a backpack, on a laptop that was configured by whoever set it up on the new hire's first day.

There is a second pressure that is particular to this market. Singapore SaaS companies sell to enterprise buyers, and enterprise buyers ask questions in procurement. A security questionnaire from a bank, a hospital group or a listed manufacturer will ask how the vendor manages endpoints, whether devices are encrypted, whether access can be revoked, and what happens when a device is lost. These are not trick questions. They are the ordinary contents of a vendor assessment. A company that cannot answer them concretely is not disqualified — it is simply slower, because every deal now includes a security remediation conversation that competitors are not having.

And there is the personal-data dimension. A company operating in Singapore handles personal data under the Personal Data Protection Act, and a company selling into the region handles it under whatever regimes its customers are subject to. This article does not attempt to interpret those obligations — that is properly a question for the company's own legal and compliance advisers. What it does say is operational: the ability to know which devices hold company data, and the ability to remove that data from a device you no longer control, is the practical substrate underneath any answer a company gives about data handling. Without it, every answer is an assurance rather than a fact.

The scenario: ninety people, two device policies, and no inventory

Here is a composite picture — not a named client, but a shape that recurs across this market often enough to be worth describing plainly.

A Singapore B2B SaaS company, roughly ninety people. Engineering, product and finance work from the CBD office. Sales, solutions consulting and customer success are on the road. Company-issued MacBooks for engineers, because that was the founding team's preference and it stuck. Company-issued Windows laptops for most of the commercial team, bought in batches whenever headcount grew. And phones — every phone in the company is personal. Nobody has ever issued a corporate handset, because it never seemed necessary. Staff put their work mail on their own iPhone or Android device on day one, because that is how people work.

The written BYOD policy exists. It is a paragraph and a half in the staff handbook, and it says employees are responsible for keeping company information secure on personal devices and must report loss immediately. Every new joiner ticks a box confirming they have read the handbook. Nothing in the environment enforces any part of it.

There is no enrolment. No device is registered with anything. There is a spreadsheet of laptop serial numbers that IT — which is one person, a systems administrator who also owns the internal tooling — updates when they remember. It was last accurate about fourteen months ago. Nobody knows how many phones have company mail on them, because the number is simply "however many people work here, plus a few who used to."

There is no encryption baseline. Most of the Macs have FileVault on because macOS asks at setup and most people say yes. The Windows fleet is mixed, because BitLocker was never enforced at build time and some of the machines were set up by the users themselves.

And there is no wipe capability of any kind. If a device is lost, the only lever the company actually has is to reset that person's password and hope. That lever does not remove anything already on the disk. It does not remove the mail already downloaded to a phone. It does not remove the sixty-page folder of customer implementation documents that someone synced locally so they could work on the plane.

Then the account executive's message arrives from Jakarta.

What actually goes wrong, and why it goes wrong in that order

The failure is rarely dramatic. It is a sequence of small unknowns compounding into an inability to say anything definite. Four of them show up almost every time.

Nobody can answer "what was on it." This is the first and worst question, because it is the one a customer will ask if the incident touches their data. Without a managed device, there is no record of what was synced, no inventory of installed applications, no view of which cloud drives were configured for offline access. The company can produce a theory. It cannot produce a fact. In a procurement conversation or a customer notification, the gap between those two things is enormous.

Cutting access is not the same as removing data. Resetting a password and revoking sessions is a real and useful step, and it should be the first one. But it addresses future access, not the copy that already exists on the disk. On an unmanaged device with no full-disk encryption, an unattended laptop is a filing cabinet with the key in the lock. The company's control ends at the login screen, and the login screen is not where the data is.

Staff resist device management for a reason that is entirely legitimate. When the systems administrator raises MDM after the incident, the objection from the commercial team is immediate and predictable: you are not putting monitoring software on my personal phone. This is often treated by IT as an irrational obstacle. It is not. Most people have no idea what device management can and cannot see, and the honest answer — that a well-configured work profile cannot read their personal photos, messages or browsing — is not something they have ever been told in plain language. A BYOD programme that does not lead with that answer will get low enrolment, and low enrolment is worse than no programme, because it produces a false sense of coverage.

Leavers keep company mail. The quietest failure of all. When someone resigns, the laptop comes back — usually. The phone does not, because it was never the company's. The mail account gets disabled, eventually. But the mail already on the device stays there, along with any documents that were opened and cached. Nobody thinks about it, because there is no mechanism that would have made anybody think about it. The leaving process only removes the things somebody remembered to write down.

Brocent's perspective: separability beats control

The instinct after an incident is to reach for control — issue corporate phones, lock everything down, mandate management on every device. That instinct produces expensive fleets and quiet non-compliance in equal measure.

The more durable framing is different. The goal is not to control an employee's device. The goal is to make the corporate half of any device separable, inventoried and revocable.

Separable means the company's applications and data sit in a defined container on a personal device, distinct from the person's own material, so that removing one does not touch the other. Inventoried means the company knows, at any moment and without asking anyone, which devices are enrolled, what their encryption and patch state is, and what corporate applications they hold. Revocable means the company can remove its own half on demand, in minutes, without needing physical possession of the device or the cooperation of the person holding it.

Those three properties are what let a company answer the questions that matter. They are also, not incidentally, what makes a BYOD programme acceptable to the people being asked to enrol. An employee who understands that the company can remove its work profile and nothing else has a reason to say yes. An employee who suspects the company can read their messages has every reason to say no, and to be quietly right to do so.

This is the same argument Brocent makes about endpoints generally — see managed endpoint security — but device management is where it becomes concrete, because the boundary between company and person is physically visible on the screen.

What this looks like in practice

Brocent's MDM and BYOD Management service is built around the design decisions that determine whether a programme works, rather than around a single product. Five of them matter most.

Platform choice follows the fleet, not the vendor relationship. Brocent deploys Microsoft Intune, Jamf Pro or VMware Workspace ONE depending on what the environment actually is. Intune is the natural choice for a Microsoft-centric organisation already running Microsoft 365 identity — most Singapore SaaS companies are in this category by default. Jamf Pro is the right answer for an Apple-heavy environment, which describes a good number of engineering-led companies. Workspace ONE fits mixed-OS enterprise deployments. Choosing the platform to match the fleet, rather than making the fleet match a platform, is the difference between a rollout that finishes and one that stalls at sixty per cent.

Zero-touch enrolment removes the setup bottleneck. Apple DEP for iOS and macOS, Android Zero-Touch, and Windows Autopilot let a corporate-owned device configure itself out of the box, without manual IT setup — including when the device is shipped directly to a remote hire who has never been to the office. For a company hiring in Jakarta or Kuala Lumpur, this is not a convenience feature. It is the difference between a new joiner being productive on day one and a systems administrator spending an afternoon on a video call walking someone through a build.

Containerisation is what makes BYOD honest. On employee-owned devices, Brocent implements managed containers — work profiles — that separate corporate applications and data from personal content. Corporate data can be removed from the container without touching the person's photos, messages or apps. This is the technical fact that makes the privacy conversation a real answer rather than a reassurance.

Policy enforcement is the part that survives the questionnaire. Encryption (BitLocker, FileVault, device encryption), PIN and password complexity, screen-lock timeout, jailbreak and root detection, and conditional access so that a non-compliant device cannot reach corporate resources at all. Conditional access is the underrated item here: it turns policy from something you audit after the fact into something that is simply true, because a device that falls out of compliance loses access until it comes back.

Wipe is two different actions, deliberately. Corporate data can be remotely wiped from any enrolled device within minutes of a loss report. Full wipe applies to corporate-owned devices. Selective wipe — corporate data only — applies to BYOD. That distinction is not a technicality. It is the whole basis on which an employee agrees to enrol a personal phone.

And one honest commercial fact worth stating out loud: MDM is an add-on at every Brocent managed IT plan tier. It is not one of the thirteen items included in every plan — those are things like 24/7 NOC monitoring, help desk, managed firewall, patch management, backup and DR, password and credential management, and a named vCIO. Device management sits alongside them as a priced addition. Saying so is more useful than implying it comes free, because a company budgeting for this needs to know it is a line item. The current structure and pricing are on the managed IT support page and in pricing.

Three ways to handle devices, and what each one really costs

No device management — "trust and hope"

  • What it is: Company laptops and personal phones with no enrolment, no baseline and no central visibility. A written policy with nothing enforcing it.
  • What it costs: Nothing on the invoice. The cost is entirely in what you cannot say — no inventory, no answer to "what was on it," no ability to remove data from a device you no longer hold, and a security questionnaire you answer with adjectives instead of facts.
  • Who it suits: Genuinely, a company of five people where everyone can see everyone's screen. It stops suiting anyone at around the point the first person starts travelling with customer data.

Corporate devices only, fully managed

  • What it is: The company issues every device, including phones, and manages all of them under full control. No personal device touches company data.
  • What it costs: Real capital and real friction. You are buying and refreshing a second phone fleet, and you are asking people to carry two handsets. Some will. Many will quietly forward mail to their personal device instead, which recreates the original problem while giving you the illusion that you have solved it.
  • Who it suits: Regulated environments with a genuine mandate for it, and roles where the device is a tool rather than a personal item. It is a defensible model — it is just an expensive one, and its failure mode is invisible non-compliance.

Containerised BYOD plus managed corporate devices — the model Brocent recommends

  • What it is: Corporate laptops fully managed with encryption, patching, conditional access and full-wipe capability. Personal phones and tablets enrolled with a work profile that holds only the company's applications and data, subject to selective wipe.
  • What it costs: A priced add-on per tier, plus the real work of designing enrolment, policy and the communication that goes with it. Not free, and not instant.
  • Why it holds up: It gets high enrolment because it is genuinely limited, it produces an inventory that is accurate because devices report their own state, and it gives a clean answer on every question a customer's procurement team is likely to ask. It also makes offboarding an action rather than an act of faith.

Where this connects to the rest of the stack

Device management is not a standalone purchase. It sits on top of identity — conditional access only means something if the identity provider is properly configured — and next to endpoint protection, which is what watches the managed device once it is enrolled. Brocent's managed endpoint security and MDM and BYOD Management are designed to be deployed together for that reason.

For a Singapore company already on a managed IT plan, the practical next step is scoping: how many corporate devices, how many BYOD enrolments, which platform the fleet argues for, and what the enrolment communication needs to say to get the sales team to participate willingly. That is a conversation, not a quote — get in touch and we will walk through it against your actual fleet.

Frequently asked questions

Can our IT provider read my personal messages on a BYOD phone?

No — not in a properly configured work-profile deployment, which is what Brocent implements. The management scope covers the corporate container: the company's applications, the company's data, and the device-level compliance state (is it encrypted, is it patched, is it jailbroken). It does not extend into personal photos, personal messaging apps, personal browsing history or personal accounts. This is worth saying explicitly to staff during enrolment, in writing, because the assumption that management means surveillance is the single biggest reason BYOD programmes fail to get uptake.

What actually happens when a device is wiped — do I lose my photos?

That depends entirely on which wipe is issued, and the distinction is deliberate. A selective wipe, which is what applies to a personal device, removes the corporate container — company mail, company documents, company apps — and leaves everything else untouched. A full wipe, which applies to corporate-owned devices, returns the device to factory state. A BYOD device should never receive a full wipe, and a correctly configured policy will not permit it.

How fast can a lost device actually be wiped?

Corporate data can be remotely wiped from an enrolled device within minutes of the loss being reported. The practical caveat is honest and worth stating: the wipe command reaches the device when the device next has network connectivity. A phone that is switched off in a bag will receive the instruction when it is switched on. This is why enrolment plus encryption matters more than wipe alone — encryption is what protects the data during the window before the device checks in, and the wipe is what removes it afterwards.

Do we need MDM if we already have Microsoft 365?

Microsoft 365 gives you identity, conditional-access capability and, depending on licensing, the Intune platform itself. What it does not give you is a designed deployment: enrolment profiles, compliance policies, application distribution, the work-profile configuration for BYOD, and the operational routine of watching the compliance state and acting on it. The licence is the raw material. The gap between owning Intune and having a working device-management programme is design and operation, which is what Brocent's service covers.

Is MDM included in a managed IT plan, or priced separately?

Separately. MDM is an add-on at every plan tier — it is genuinely not one of the thirteen items included at every level. We prefer to state this plainly rather than let it be discovered at scoping. The included-everywhere items are things like 24/7 NOC monitoring, help desk, managed firewall, patch management, backup and DR, password and credential management and a named vCIO; device management sits next to them as a priced addition. Current structure is on the managed IT support page.

What happens to an ex-employee's personal phone when they leave?

With enrolment in place, offboarding includes a selective wipe of the work profile: company mail, documents and applications are removed, the person's own device and content are untouched, and the removal is recorded. Without enrolment, the honest answer is that the company disables the account and the cached copy stays on the device indefinitely. This is why device management belongs in the offboarding conversation and not only in the security one.

We're a ninety-person company. Is this overkill?

Size is the wrong measure. The right measure is what leaves the building. A ninety-person company whose commercial team carries customer implementation documents through four countries a month has a materially larger exposure than a three-hundred-person company where everyone works on-site against a server that never moves. If your customer data travels, device management is proportionate. If it genuinely does not, it can wait.

How long does a rollout take?

For a fleet of this size, the design work — platform selection, policy definition, enrolment profiles, the BYOD communication — is the substantial part, and it is measured in weeks rather than months. Corporate device enrolment can proceed quickly, particularly if new machines are brought in through zero-touch. BYOD enrolment is paced by people, not technology: it goes as fast as staff are willing to opt in, which is why the privacy explanation is a delivery-critical component rather than a nicety.

Share:

Ready to take action?

Turn these insights into a roadmap for your business.

Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.

📋

Free Checklist

10 Critical Checks Before Expanding IT to Greater China

PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.

Request the checklist →

📬 Monthly Asia IT Insights

China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.

No spam. Unsubscribe anytime.