In 2025, Brazil recorded 830,890 phones taken in robberies and thefts, according to the 2026 National Public Security Yearbook, published by the Brazilian Forum on Public Security — an average of nearly 95 devices every hour, every day of the year. The survey counts 308,723 robberies, down 18.6% from 2024, and 483,561 thefts, roughly unchanged.

The phone that disappears isn't just a handset. It's the company email synced to it, the finance team's chat group, the price sheet saved for quick reference mid-visit, and the system app already logged in, no password needed. All of that travels together, because someone put it there, one day, so the sales rep could move faster.

The detail that changes everything: it's his phone. It's his SIM card. The company never had ownership of either — it only put data inside. And that's exactly why, when the device disappears, most companies discover they have nothing ready to do about it.

The problem in detail

Anyone working out in the field — a sales rep, a technician, a delivery driver — carries their personal phone as a work tool all day. It's where the chat app used with clients lives, where email arrives first, and where the system password got saved so it wouldn't need typing again at every stop.

The Yearbook also shows where this risk concentrates: the city of São Paulo alone accounts for 20% of all phone robberies and thefts in the country, despite holding 5.6% of the national population. For anyone selling or serving clients in the field in any large urban center, this isn't a distant risk — it's routine.

Recovering the device is rare. The Yearbook itself describes a resale chain that crosses borders, with phones stolen in Brazil ending up in electronics markets abroad. In practice, a company should treat every lost personal phone as gone for good — not as something that might come back.

The loss isn't just the device. It's the client who gets a strange message from the number they trust, still thinking they're talking to the same sales rep. It's the price sheet that starts circulating outside the company. It's system access, still active, with no one sure for how long.

And there's a second door that opens the same way, though it's talked about less: someone who left the company still has the company email synced on their own phone, and no one removed it. That's not the focus here, but it's the same problem from another angle — company data sitting inside a device the company doesn't control.

Why the usual approach doesn't work

The usual approach is trusting that "everyone looks after their own phone" and going no further. It works until a client calls sounding suspicious, or the sales rep reports, days later, that the phone was lost over the weekend.

Another version of the same approach is verbal guidance — "don't save your password," "don't keep the price sheet on your phone" — with no mechanism behind it. Guidance without a control depends on everyone remembering it on a busy ordinary day, which is exactly when it fails.

It's also common to treat "IT security" as a computer-only topic — antivirus on the machine, backup on the server — leaving the personal phone completely out, even though, for many companies, it's the device that touches clients and systems the most during the day.

And when someone leaves the company, it's common to remember disabling the office computer's email and forget that the same email is still synced on that person's personal phone — which keeps receiving everything, even after they've stopped working there.

What has to be in place

A prepared environment doesn't require buying every employee a phone. It requires separating, from the start, what belongs to the company from what belongs to the person.

A work profile kept separate from personal use on the same phone. Company email, the system app and work files sit in their own space inside the phone — photos, personal chats and the rest of the device stay the owner's alone, with the company never seeing or touching them.

A way to manage the company's access on the device remotely. This is a feature that lets the company remotely erase only what belongs to it inside the phone — the email, the system app, the saved file — without touching the owner's photos, personal messages, or any other app. Manufacturers call this a few different things; what matters is that the company can clean up its own part without touching anyone's personal life.

A second confirmation step on every access made from a personal phone. Even if the device is stolen unlocked, that second step — a code, a notification — still keeps whoever has it out of company email and systems.

A written agreement before granting access from a personal device. What the company can remotely erase, what it will never touch, and that access disappears the same day someone reports a lost phone — or the same day they leave the company.

A record of which accounts and systems each personal phone can reach. Without that map, every lost device turns into an investigation from scratch: no one knows for sure what to revoke first, or whether something got left behind.

A company-owned phone for anyone handling sensitive data all day long. For someone carrying price sheets and system access constantly, a company phone — one the company can manage fully — costs less than the risk of leaving all of that on a device outside its reach.

This is how Skills IT works: separating company access from the person's device, setting up remote wipe for only the corporate part, and cutting off that access the same day it stops being needed.

The gain for the company

The gain starts with not having to reconstruct, under pressure, what a lost phone could reach. When the access map already exists, revoking it takes minutes — not a full day of people trying to remember which systems that person was logged into.

There's also a gain that only shows up when it's missing: the deadline. Per ANPD guidance, losing a device with personal data belonging to a client or employee can require the company to report the incident within three business days, when that unprotected data could pose a real risk to those affected. Finding this out in the middle of a crisis costs far more than having already separated company data beforehand.

Less visible, but just as real: the client keeps trusting the number they've always talked to, because that number never became a door for a scam. And the owner or director stops wondering, every time someone leaves or loses their phone, exactly what that device had access to.

Questions to bring to your next meeting

  1. Does anyone know, today, what each team member's personal phone can access from the company? If the answer is "sort of," there's no map to revoke anything when a device is lost.
  2. Is there anything in writing agreed with whoever uses their own phone for work? Without it, no one knows what the company can or can't erase when the device disappears.
  3. If a sales rep lost their phone right now, how long would it take to cut off system access? If the answer isn't minutes, email and systems stay open to whoever has the device.
  4. Is there a second confirmation step beyond the password on every access from a personal phone? Without it, the password saved on the lost device is enough to get in.
  5. Does whoever handles pricing and clients all day have a company phone, or their own? The answer decides whether this is worth treating as an investment, instead of waiting for the loss to happen.