What Sideloading Costs an Organisation
Sideloading installs an app from outside the official store, bypassing the review, signing, and update checks that store distribution provides. On a device that also holds work email, that one install can carry credential-stealing malware, request permissions no reviewed app would be granted, and never receive a security patch again.
The reason it keeps happening is that the motivation is almost never malicious. Staff sideload to get a free version of a paid tool, to install something unavailable in their region, or because a contractor was told to use a client's internal app. All three are reasonable-sounding, none of them are visible to IT, and the exposure lands on a device the organisation may not manage. What does not belong on screen is your own control detail: which management profiles are enforced, what the device compliance checks actually test, and how exceptions are approved belong in the IT runbook.
The template traces the risk through eight scenes: two defining sideloading against normal installation, two on the three common motivations and why each feels reasonable, one on what a malicious sideloaded app can reach on a shared device, one on the patching problem, one on the rule for personal devices holding work data, and one on what to do if something was already installed.

