2026-07-28OPINION · INFORMATIONSECURITY · CORPORATEGOVERNANCE · DATAPROTECTION · TRAVELSECURITY · RISKMANAGEMENT5 MIN READ READ
FILED UNDER

Clean Travel Devices Are No Longer Optional

When your employee is standing at a checkpoint is the wrong moment to discover your governance gap.

The Forcing Function Your Security Team Has Been Waiting For

If your organisation sends executives or staff to the United States — and most do — you have a governance problem that this week’s news just made impossible to ignore.

An activist has been charged with a felony in the US after giving border agents a “duress code” that wiped his phone during an airport interrogation. The government’s position, as reported by Ars Technica, is that destroying your own data when a federal officer has compelled its production is a crime. The theory is simple and unpleasant. At the US border you have no Fourth Amendment protection worth relying on, agents can demand access to your devices, and obstructing that access is potentially a felony — including where the obstruction consists of following your employer’s security policy to the letter.

The politics of the individual case are beside the point. What matters is that a conflict which has been building for years has finally produced a concrete legal consequence, and Australian boards have been slow on travel device policy. That slowness now has a price attached.

The Conflict Your Policy Probably Doesn’t Resolve

Most organisations with any security maturity have, somewhere in their documentation, language about protecting confidential data. Some have specific provisions about international travel. Almost none of them resolve the following question: what does an employee do when a foreign government officer demands access to a device containing data your organisation has a legal obligation to protect?

Under Australian privacy law, including the Privacy Act 1988 and its forthcoming reforms, organisations have obligations around the handling of personal information. Under confidentiality provisions in commercial agreements, they have obligations to clients and counterparties. Under the Corporations Act, directors have duties that extend to protecting material non-public information. None of those obligations pause at the departure gate.

The US border regime does not care about any of that. Customs and Border Protection officers operate under authority that has been interpreted, repeatedly and consistently, to permit device searches without warrant or probable cause. The activist’s case suggests the government will now go further — that actively preventing access, even through a pre-configured security mechanism, is obstruction.

Your employee, standing at a border checkpoint, is caught between two legal systems with contradictory demands. Your current policy almost certainly leaves them there alone.

Why Leadership Has Resisted This Fix

Security teams have been recommending clean travel devices for years, and the recommendation has never been complicated. Staff travelling to jurisdictions where devices can be searched at the border — a category that plainly includes the United States — carry purpose-provisioned hardware holding only what the trip requires, with no access to core systems, no stored credentials and nothing sensitive at rest.

Resistance to this has come from the top, for reasons that are understandable and still wrong. The inconvenience is genuine: senior leaders do not want a stripped-back device, they want their mail and their files and the applications they use every day. Provisioning and returning the things creates overhead that IT and procurement would rather not own. And underneath all of it sat a comfortable assumption that this was a problem for journalists and dissidents rather than executives on legitimate business.

That last assumption is the one this case removes. The authority that compels an activist to unlock a phone compels a CFO to unlock a phone on the same terms, and the theory that makes wiping the device a felony does not inquire into what is on it or why you are travelling.

The Second-Order Consequence Worth Naming

The lasting effect of this prosecution will be to make clean travel devices non-negotiable for any organisation that takes its obligations seriously, and it will have nothing to do with security teams becoming more persuasive.

The exposure simply moved. When an employee is compelled to unlock a device holding M&A material, client personal information or board correspondence, and that data later surfaces in a breach notification or a regulatory file, somebody will ask what the organisation had in place to prevent it. “Our executives found the alternative inconvenient” does not read well in that context.

So the case has handed security professionals the argument they have wanted for a decade, which is an odd thing to be grateful for.

What Australian Organisations Specifically Need to Do

The Australian context matters here beyond just travel logistics. APRA-regulated entities operating under CPS 234 have explicit obligations around information security controls proportionate to the threat environment. The threat environment for international travel has materially changed. Regulators examining an incident involving data accessed at a foreign border will look at whether the organisation’s controls were adequate given known and foreseeable risks. This prosecution is now part of the foreseeable risk landscape.

For boards, none of the remedy is technically difficult. It is a governance decision: adopt a clean travel device policy for jurisdictions where warrantless device access is lawful, a list that takes in the US and several others, and apply it to senior leaders first. They carry the most sensitive material, and their compliance is what tells everyone else the policy is real.

General counsel and company secretaries have a narrower job. The conflict between your data protection obligations and a foreign government’s border authority needs resolving in policy, at a desk, before an employee is asked to resolve it at a checkpoint with a queue behind them.

The Takeaway

Read this as a case study in what happens when people are left to work out, in real time and under pressure, something their organisation should have decided for them months earlier.

If your staff are flying to the US with devices that reach sensitive data and you have not provisioned clean equipment, the risk has been deferred rather than managed. Deferral was defensible while the conflict was theoretical. It stopped being theoretical this month.

Next dossier
Three Months in Isolation: Is Your Critical Infrastructure Ready? →
Engage the author
Stephen Betros is currently taking on briefs.
Brief Stephen
Share