If companies allow staff to use work devices for personal matters, Craig said they're potentially exposed to embarrassment through source of an attack.
"So your reputation may suffer," he said.
"But this type of risk could come from any website your staff may access or any online application or service," he said.
"My advice to an organisation is: first and foremost you need a policy telling your staff what is okay and what is not because ultimately you need some sanctions for behaviour which you're not comfortable with. That's not going to extinguish your risk so you really need to be thinking about what technical measures you need to be implementing to reduce or eliminate the risk of your organisation being attacked through the devices your staff are using and the way they're using them," he said.
Craig said companies could also blacklist certain websites they think might pose a high risk or, at the more sophisticated end of the spectrum, set up technology that separates personal use on devices from those associated with the business.