In one of the updates, they mention that they hope they'll be able to get company equipment (presumably a computer/laptop) back from "John". So I'm sure the "spying" software (pretty standard fare for most corporate IT departments) was on company hardware, not personal hardware.
If a company said I could bring my own laptop, but that I'd have to install their "security" software on it, I would definitely decline. Ditto for an MDM on my phone.