Skip to content
Client login

Free Audit

Security & surveillance

The phone is the workstation: what leaves with it

Orders arrive on a phone the business never bought. The number, the session left open, and what goes on the day somebody leaves.

Published on 26 May 2026 — Algeria Agency

The companion article tells four stories: the stolen laptop, the reused password, the message asking for new bank details, and the encrypted files. All four happen on a computer.

In most of the businesses we equip, though, the computer is not where the work arrives. Orders arrive on a phone, the customer conversation lives on a phone, and the quotation goes out as a photograph from a phone.

That phone was not bought by the business, is administered by nobody, and often belongs to an employee. It is the most-used workstation in the company and the only one that appears on no inventory.

This page covers what leaves with it, in order of what costs most: the number first, then the messaging account, then the sessions left open elsewhere. It is not a page about phones, it is a page about what happens when a company asset lives in somebody’s pocket.

The workstation nobody bought

Look at where your work arrived from this week. For most of our clients the answer is a messaging conversation on a phone, not a mailbox on a computer.

That means the company’s most important workstation was never chosen, never configured, never backed up, and appears on no inventory line. It arrived because the customers were already there.

This is not a criticism and there is nothing to correct in that choice: the channel is the market’s, and a business refusing to be on it loses real customers in exchange for a principle. The telephony article and the social media article say the same from their side.

What has to be corrected is elsewhere, and it is a consequence of ownership rather than of technology: this working tool lives inside a personal object, bought by somebody else, which goes home every evening and will leave one day for good.

The next four sections cover the four things that leave with it, in order of cost: the number, the account, the history, and the sessions open elsewhere. None requires buying anything; two require a conversation better had now.

The number belongs to whoever holds the SIM

This is the central section of the page and the one whose outcome is most final: the number your customers dial belongs to the person whose name is on the line.

In the majority of businesses under ten people that we see, that name is an employee’s, a partner’s who is no longer there, or the owner’s in a personal capacity. The line was opened on a day when that was fastest, and nobody ever thought about it again.

The consequence is visible only at the moment of departure, and by then it is irreversible. A line transfers with its holder’s agreement; without it, the business loses a number printed on its vehicles, its shopfront and its cards, and known to all its customers for years.

What that really costs is not measured in line charges: it is the customers who call a number that no longer answers, and who do not call back because they assume you have closed. It is the quietest loss in this whole pillar.

The correction is made while the relationship is good and takes one visit to a branch: the line in the company’s name, with its invoice, paid by it. The phone can stay personal — the device does not matter. **The number is the asset**, exactly as the telephony article says about the switchboard.

The business messaging account

The second asset is the messaging account orders arrive on, and it is attached to the number from the previous section — which means it follows the same road.

One thing is worth knowing before anything else: these platforms offer a business account distinct from the personal one, free, and businesses of this size almost never use it. It is not a gimmick — it separates the work conversation from the person’s private life, which is useful to both.

What the business account concretely provides is short: a profile carrying the company’s name, hours and address; saved quick replies; and a visible distinction, for the customer, between writing to the business and writing to somebody.

What it does not provide, and this has to be known: it does not make the account transferable. The account stays attached to the number, and section 2 still decides everything. A business that sets up the business account on a personal line has put its shopfront inside somebody else’s house.

And one practical consequence for the day of departure: conversations do not move from one device to another without a backup the person makes deliberately. That is asked for beforehand, never after, and it is section 5’s subject.

The session left open on the office computer

The desktop version of messaging is what makes the work bearable: you type on a keyboard, you send a file without routing it through the phone. Almost all our client businesses use it.

It creates an exposure nobody watches: the session stays open on that machine, independently of the phone, and gives access to every conversation to whoever sits down in front of it.

The case that actually happens is not espionage. It is the shared reception computer, where the owner’s session has been open for six months, and where three different people sit each day — one of whom reads, with no particular intent, a conversation that does not concern them.

The check takes a minute and is done from the phone: all these platforms show the list of connected devices, with dates. Look at it today. You will almost certainly find a device you do not recognise — often an old computer, sometimes a machine that was sold or given away.

Two acts then suffice: disconnect anything unidentifiable, and make a habit of repeating the round each quarter, alongside the maintenance review. It is the cheapest measure in this article and the one that closes the most doors.

The stolen phone: the first twenty minutes

A lost or stolen phone is the only event on this page decided in minutes, and the order of the acts is not the one emotion dictates.

The first act is not blocking the handset: it is stopping the SIM with the operator. The reason is mechanical — whoever holds the SIM receives the verification codes by message, and can therefore take over the messaging account on their own phone.

The second act is obtaining a SIM with the same number, which is done at a branch and costs little. That SIM is what will let you take the account back, and it is why the number matters more than the device.

The third is telling people. A message to important customers saying the business lost that number for a few hours prevents exactly the attack that follows this kind of incident: somebody asking, from your account, for a transfer or a change of bank details. That is the neighbouring article’s third story, transposed.

What makes those three acts possible in twenty minutes is a sheet written calmly: the operator’s number, the line number, the branch address, and who to tell. The same sheet as in the line-outage article, in the same place, for the same reason — nobody goes looking for a branch address in those moments.

When the employee holding the phone leaves

This case is commoner than theft and handled worse, because it has none of the urgency that forces action.

Four things go at once: the number if the line is in their name, the history of conversations with customers, the groups the business was present in, and access to the open sessions from section 4.

The history is the one most regretted and it cannot be claimed afterwards. Two years of conversation with a customer holds the prices charged, the commitments made, the complaints handled. It exists only on that device and it is not yours in any practical sense.

What can be prepared, and takes ten minutes on the last day rather than three weeks of discussion: a backup of the business conversations exported and handed over, the line transferred if it is in the company’s name, group administration passed to somebody else, and every session disconnected.

The organisational point that makes this workable is the same as for badges: the list is handled on the last day worked, the one on the payroll, and not at the exit interview. A contested departure is precisely the case where the interview does not happen and where these four things matter most.

What not to do in the name of security

This section exists because the measures most often proposed on this subject cost more than they return, and that has to be said before advising anything.

Do not install a phone management tool on a personal device. It is the standard recommendation in corporate documentation, it is correct for a three-hundred-person organisation with company-issued handsets, and on a phone belonging to an employee it is an intrusion nobody will accept — and it will be worked around within the week.

Do not ban consumer messaging in favour of a "professional" channel your customers do not use. We have seen that decision taken twice and produce the same result twice: customers went on writing on the old channel, and the business took four months to notice.

Do not impose a dedicated second line if nobody wants to carry two phones. The useful rule is simpler and it is in section 2: the number belongs to the business, the device belongs to whoever it belongs to.

The logic common to those three refusals is the one the neighbouring article applies to content filtering: a security measure that slows down the answer to a customer costs this business more than the risk it covers, and a measure that is worked around covers no risk at all.

The three settings that cost nothing

Three settings do most of the real work on this subject. Together they take five minutes, on every phone carrying work.

The first is the messaging app’s two-step verification code. It has nothing to do with the phone’s unlock code: it is a code asked for when the account is installed on a new device, and it is **the only thing** stopping somebody who has obtained your SIM from taking over your account. Almost nobody enables it.

The second is the screen lock, with a code rather than a pattern. A pattern can be read from the finger trace on the glass and replayed from memory by somebody who watched once.

The third is automatic conversation backup, enabled and verified once. It is what makes section 5 possible and it is also what saves a device dropped in water, which happens more often than theft.

Write the verification code from this section somewhere other than the phone, with the company’s other papers. A code stored only in the device it protects is a code lost at exactly the moment it is needed — the circularity from the hosting-account article, in a smaller object.

Groups, and what old material they hold

Messaging groups are the real coordination tool of many Algerian businesses, and nobody maintains them because they look as though they belong to nobody.

Last year’s site group still contains the four subcontractors, the former team leader and that period’s client. It also contains the photographs, the prices and the exchanges of those months, and it stays readable by all those people indefinitely.

Two rules suffice and they are organisational rather than security matters. A project group is closed when the project ends — not left, closed — and it takes ten seconds on the day the balance is invoiced.

And a group mixing customers with subcontractors is not a working channel, it is a permanent meeting open to people whose interests differ. It is also, very concretely, where a customer discovers the name of the subcontractor they can call directly next year.

The annual check is short: open the group list and look at the dates. Those that have received nothing in six months get closed; the others are read through once to check who is still in them. Half an hour a year.

What the phone should not carry

The phone is a good workstation for conversation and a bad place for three things in particular, which have to be named because they arrive there by themselves.

The first is photographs of documents. A customer’s identity card sent for a file, a photographed cheque, an invoice with a tax number: those images stay in the phone’s gallery, rise into the person’s personal backup, and sometimes end up in a photo service shared with their family.

The second is a password sent as a message. It stays readable in the history for years, it is copied into the backup, and it is the first place anybody who gains access to the account looks. A password sent through this channel is a password to change, not a password delivered.

The third is the only copy of a document. A photograph of a delivery note taken on site exists only there until somebody files it elsewhere, and phones get lost.

The rule covering all three fits in one sentence: what arrives on the phone passes through it and does not settle there. A ten-minute weekly habit — filing the documents received, deleting photographs of identity papers once the file is complete — is enough, and it is more sustainable than any rule forbidding those things from arriving.

An incident: what this page does not cover

If somebody has taken over your account, or a message asking for money has gone out from your number, you are in an incident and this is not the right page.

The first hour is covered by the neighbouring security article, in its section 9, and its order applies unchanged: regain control, warn the people concerned, and do not destroy what would allow the thing to be understood.

We add only one point specific to this channel, and it is worth knowing in advance: taking back a messaging account runs through possession of the SIM, which means stopping it and buying a replacement with the same number are the acts that regain control. That is section 5, and it is also why the sheet it asks for is useful.

The thing not to do, and it is the one that comes naturally: do not delete the fraudulent conversation. It is what you will show the customer, the bank, or whoever needs to see it, and it disappears permanently if you erase it to stop having to look at it.

And warn widely rather than narrowly. A short message to all your active customers costs ten minutes and stops the attack; a message to three people leaves the rest receiving a transfer request from a number they have known for four years.

What we do, and what we refuse to do

What we refuse first: installing anything at all on an employee’s personal phone. No management tool, no monitoring application, no backup into a company account. It gets asked for, it gets sold, and it turns a private device into company property without anybody having decided it.

We also refuse to recommend abandoning consumer messaging for a channel your customers do not use. It would be the easiest recommendation to write and it would cost real customers against a theoretical risk.

And we refuse to treat this as a technical subject. The two things that decide everything — whose line it is, and what happens on the day somebody leaves — are conversations between partners, not settings.

What we do fits in two hours: checking the connected devices on every account, enabling section 8’s three settings, the SIM-stop sheet written and posted, the group list reviewed, and the conversation about the line — with a visit to the branch alongside you if you want one.

And one thing to do today, in one minute: open the list of devices connected to your messaging account. If you see something you do not recognise, you have just found the most open door in your business, and it closes with one gesture.

Frequently asked questions

Whose name should the business number be in?

The company’s, with its invoice, paid by it — and the handset can stay personal. In most businesses under ten people the line is in an employee’s name or a partner’s who has left, and that only shows at departure, when it is irreversible. What is lost then is not a subscription, it is the customers calling a number that no longer answers.

What is the most important setting on a business phone?

The messaging app’s two-step verification code, which has nothing to do with the unlock code. It is a code requested when the account is installed on a new device, and it is the only thing stopping somebody who has obtained your SIM from taking over your account. Write it down somewhere other than the phone.

A business phone is stolen. What comes first?

Stopping the SIM with the operator, before even blocking the handset: whoever holds the SIM receives the verification codes and can take over the messaging account. Then a replacement SIM with the same number, which is what gives the account back. Then a message to important customers, because the transfer request from your number arrives within hours.

What do we do when the person holding the phone leaves?

Four things on the last day worked, the one on the payroll, not at the exit interview: the line transferred if it is in the company’s name, a backup of the business conversations exported and handed over, group administration passed on, and every session disconnected. The history cannot be claimed afterwards.

Should we ban consumer messaging at work?

No. We have seen that decision taken twice: customers went on writing on the old channel and the business took four months to notice. A security measure that slows down the answer to a customer costs more than the risk it covers, and a measure that is worked around covers none. Use the platform’s business account instead, which is free.

How do we know whether somebody can read our conversations?

Open the list of connected devices from the phone — every one of these platforms shows it, with dates. You will almost certainly find something you do not recognise: an old computer, a machine that was sold, the shared reception computer where a session has been open for six months. Disconnect anything unidentifiable and repeat the round each quarter.

Where we come in

The list of devices signed in to your mail almost always holds a phone you do not recognise. What that list cannot say is what was read.

  • We make the three settings changes in two hours, on company accounts.
  • We write the escalation sheet: who to warn, in what order, with which numbers.
  • We review the groups your name is still in without your knowing.

No tool goes onto an employee’s private device from us: not management, not security, however hard it is pressed for.

Read next

Let us talk about your project

A free audit, no commitment: we look at your online presence and tell you what is holding it back.

We measure how this site is used with Google Analytics, to learn which pages actually help. You can stop that measurement at any time from the footer. Cookie policy