Compare BYOD vs. CYOD vs. COPE vs. COBO for a mobile strategy
BYOD offers organizations flexibility for employee devices. COBO offers security. Neither aspect can be the only factor in a mobile device management strategy.
Organizations recognize the need for flexibility when it comes to supporting employee mobile devices. They must balance what employees want with what IT and security require.
There are four enterprise mobility management strategies organizations can choose from:
- Bring your own device (BYOD).
- Choose your own device (CYOD).
- Company-owned, personally enabled (COPE) devices.
- Company-owned, business-only (COBO) devices.
BYOD is one of the most popular mobile device management (MDM) options, including in organizations that have no formal MDM policy. However, due to the security concerns and limited controls associated with BYOD, the other three options are making a comeback.
When weighing BYOD vs. COPE vs. COBO vs. CYOD for a mobile device policy, the IT team should strive for a functional and feasible approach that is acceptable to both the employees and their organization.
What are the basics of BYOD, and is it a good idea?
BYOD refers to any employee-owned type of device -- typically a smartphone or tablet -- that is used for work. Many employees configure their personal cell phones with their work email and use the device for work-related activities. They might install apps that they use to do their jobs, either internal apps or apps that require their work login information.
Bringing their own personal device to work offers the most flexibility for employees, but it does not mean the best protection for the organization. BYOD adopters should consider investing in protection tools that support BYOD and add layers of security. Mobile application management (MAM) puts controls around the corporate apps on personally owned devices, isolating them from the employee's personal apps while ensuring encryption and other security measures.
What are the characteristics of CYOD, and how different is it from other mobile policies?
CYOD gives the organization more control than BYOD. In this scenario, the organization offers a range of brands or models of smartphones and tablets that employees select as their work and personal device. Some enterprise teams consider CYOD a viable option to give employees flexibility. The IT team can fully lock down and manage the device while still allowing personal use as well.
With CYOD, IT can enforce certain security policies on the device. Typical restrictions include complex password requirements, IT approval for app installs, content filtering and GPS tracking. MDM tools enable IT teams to remotely update and oversee CYOD devices.
What does COPE bring to the table?
CYOD is one version of COPE, but not the only one. The corporate-owned and personally enabled policy for devices gives the organization ownership and control over the device. Employees might have input on device make and model, or they might not.
Organizations might select a COPE strategy if employees are not currently using a mobile device or are not willing to continue to pay for their personal device plans. Employees must be willing to adopt a company-owned device that also gives them the flexibility to conduct personal activities on it.
What is a COBO policy, and when does it make the most sense?
COBO is the most restrictive policy for tablets, smartphones or other device types. The organization owns and controls the use of the device.
Under a COBO policy, the corporate-owned device runs business-only apps. These devices might be shared by multiple employees. For this reason, COBO policies are typical for employees such as field techs and warehouse workers.
Consider a COBO policy if there is a limited set of use cases for the mobile devices and security is a concern. COBO is a good fit when multiple users access the device, because it doesn't make sense for these employees to store personal information or install personal-use apps.
How to choose between BYOD, CYOD, COPE and COBO
IT has multiple mobile device implementation strategies to choose from in BYOD, CYOD, COPE and COBO. The strategy must focus on security and protection of the network and data. Take into consideration the relevant compliance requirements and which approach provides the best protections for the organization.
Moving away from BYOD is not always the answer to security concerns that organizations might have. MAM platforms, along with mobile threat defense tools, offer features that can ensure the corporate network is secure when a user brings their personal device for work. These tools reduce enterprise risk while enabling device flexibility. Focus on mobile policies that balance the organization's IT requirements with employee convenience.
Pros and cons of BYOD and COPE
Employees generally request the convenience of a single device for work and personal use, along with privacy and data protection measures and cost-sharing policies.
Consolidated devices
Many employees like the option to have a single device for personal and work use. This setup is more convenient than having two smartphones to keep up with. BYOD and COPE are favorable to employees because these strategies provide them with one device to use for all activities.
Privacy and protection of personal data
Employees raise concerns about privacy when they have corporate mobile devices for personal use. To address this issue, IT teams can implement an MDM or MAM system to protect corporate data. Under this approach, employees need assurance that personal data such as photos, social media accounts and personal texts are not at risk of being leaked or viewed by IT.
Cost
Employees using BYOD or COPE endpoints can see increased service costs as a result of increased bandwidth or data usage on their cellular data plan, covering their work and personal usage. Users might expect their organization to provide financial support or incentives for their smartphone bill. Without financial support, BYOD and COPE lose favor among employees, as COPE or COBO mean the device and its use are fully owned and paid for by the employer.
Editor's note: Robert Sheldon wrote about BYOD and COPE in 2013. Reda Chouffani updated the article in 2021 to include CYOD and COBO and reflect changing EMM technologies. TechTarget editors made further updates in 2026 to improve the reader experience.
Robert Sheldon is a freelance technology writer. He has written numerous books, articles and training materials on a wide range of topics, including big data, generative AI, 5D memory crystals, the dark web and the 11th dimension.
Reda Chouffani runs a consulting practice he co-founded, Biz Technology Solutions Inc., and is CTO at New Charter Technologies. He is a technology consultant with a focus on healthcare and manufacturing, cloud expert and business intelligence architect who helps enterprises make the best use of technology.