Knowledge Article

The Two-Device Problem: Why Managing Work and Personal Laptops Undermines Remote Access

See Venn first in Google Search

Add as a preferred source on Google

Secure remote access is core infrastructure for today’s workforce. Remote and hybrid work are permanent parts of how most organizations operate, and a growing share of the workforce – contractors, offshore teams, distributed hires – may never set foot in an office at all. The question isn’t whether people need secure access to company systems from wherever they are. It’s how organizations get there.

For most, the default answer has been the same for years: issue a second, company-managed laptop. Secure remote access, in practice, has usually meant a managed device plus a VPN. But a managed second laptop isn’t a neutral security decision — it comes with its own cost, paid by the person using it every day. New data from a survey we fielded through Dynata puts a number on that cost, and it raises an uncomfortable question: is the two-device model actually making remote access more secure, or just adding friction that pushes people toward the exact workarounds it was meant to prevent?

Free eBook:

Secure Remote Access that Doesn’t Drive Users Crazy!

Secure your entire extended workforce without issuing devices or VDI. Keep your organization agile, compliant, and secure.

What the Data Shows: The Cost of Running Two Devices

48% Say Managing Multiple Devices Hurts Work/Life Boundaries

Nearly half of respondents say juggling a separate work and personal laptop makes it harder, not easier, to keep work and personal life separate. That’s a direct contradiction of what remote and flexible work is supposed to deliver: more control over when and where work happens, not less.

47% Say It Adds Unnecessary Steps to the Workday

Close to half report that running two devices adds steps to routine tasks — switching machines to grab a file, re-authenticating on a second laptop, physically moving between two setups to do work that should take one continuous motion.

43% Say It’s Frustrating Overall

Beyond the specific frictions, over four in ten describe the experience of managing two devices as simply frustrating. That’s a meaningful share of the workforce experiencing the core infrastructure of remote work as a source of daily annoyance rather than an enabler.

18% Report Difficulty Working Flexibly or Remotely

The sharpest finding: nearly one in five say the two-device setup makes it genuinely difficult to work flexibly or remotely at all. For a category built entirely around enabling that flexibility, that’s a significant failure rate.

Why Companies Default to a Second, Managed Device

None of this happens because organizations want to create friction. It happens because of a long-standing assumption about what secure remote access requires.

The Assumption: Secure Means Company-Controlled

The traditional model treats the device as the security boundary: if the company owns and manages the laptop, it can enforce encryption, patch policy, and access controls on it directly. A personal device, by that logic, is inherently less trustworthy simply because IT doesn’t control it. Issuing a second laptop has been the default way to close that gap.

The Reality: A Distributed, Offshore, and Contractor-Heavy Workforce Makes This Model Harder to Sustain

That assumption gets more expensive and harder to sustain as the workforce itself changes shape. Shipping, provisioning, and maintaining a managed laptop for every contractor, offshore hire, or remote employee doesn’t scale the way it used to; and it doesn’t remove the underlying friction either. It just relocates the cost from a security line item to a productivity one, paid daily by the people juggling two machines to do one job.

The Paradox: Mandating a Device Can Undermine the Security It’s Meant to Provide

Here’s the part that should concern security teams specifically: the two-device model doesn’t just cost productivity. It can actively work against the security goal it was built to serve.

An Unfamiliar Device Pushes People Toward Their Own Workflows Anyway

A managed laptop that doesn’t match how someone actually works (different setup, different shortcuts, different feel) doesn’t eliminate their preferred workflow. It just pushes that workflow onto whatever device already fits, which is usually the personal one sitting right next to it.

Restrictive Tooling Breeds Workarounds, And Workarounds Are Where “Secure” Breaks Down

This is the same root cause behind a lot of what looks like shadow IT: when the sanctioned device is annoying enough to use, people find their own way around it. We’ve covered how often that shows up as personal email, personal devices, and unsecured networks carrying company data outside any monitored system. The two-device model is frequently the reason that behavior exists in the first place – not because employees are careless, but because the “secure” option was the harder one to actually use.

Secure BYOD: Removing the Reason for a Second Device

Securing the Work Instead of the Device

The more durable fix isn’t a better-designed managed laptop. It’s changing what the security boundary is built around in the first place. Rather than treating the entire device as the thing that needs controlling, modern secure remote access strategies increasingly focus on isolating business activity in a controlled environment – regardless of which device the person is on. This is called a device-agnostic approach, and it allows companies to enforce access policy and protect company data without requiring a second machine at all. Companies accomplish this by utilizing a secure workspace, or a secure enclave.

Getting Out of the Managed-Hardware Business Without Giving Up Control

This isn’t a security tradeoff. IT still enforces MFA, access policy, and data protection inside that environment exactly as it would on a company-owned device. What changes is that the person doing the work keeps the device, workflow, and shortcuts they already know – which removes the two-device friction at the source, instead of trying to design around it.

What This Looks Like in Practice

One AI platform connecting contractors to niche remote roles needed to onboard people quickly, across locations, without shipping managed hardware to every new contractor. Rather than requiring a second, company-issued laptop, contractors installed a lightweight agent on their own PC or Mac, authenticated with MFA, and were productive the same day — working inside a secure, isolated enclave on the device they already had. No second laptop. No unfamiliar setup to work around. Just secure access to the tools they needed, on the device they were already comfortable using.

Key Takeaways

Secure remote access was built to make flexible, distributed work possible, not to add a second device and a second set of habits on top of it. The data shows that model is costing a meaningful share of the workforce real time, real frustration, and in some cases the flexibility remote work was supposed to provide in the first place. Worse, it can quietly push people toward the exact workarounds that undermine the security it was meant to guarantee. Removing the reason for a second device — by securing the work itself instead of the hardware — closes that gap without asking anyone to give up control.

If you’re weighing whether your remote access model still needs a second, managed laptop for every distributed worker, it’s worth a closer look at how Blue Border™ makes it possible to secure the work instead.

About Blue Border

Blue Border is the secure workspace for contractors, remote teams, and BYOD workforces on any device. Installing Blue Border on a Mac or PC creates a company-controlled secure enclave directly on that device — work stays protected and isolated, while everything outside the enclave remains private.

No VDI. No managing the entire endpoint.

See Blue Border in action here.