There are more than 4.3 billion active mobile internet users worldwide, who downloaded more than 230 billion apps and accounted for more than 55% of total online traffic last year. The increase in remote working policies has brought an onslaught of IT security challenges. Hackers are waging war on your data, and they are getting to you through your most vulnerable fronts – your mobile devices.
3 Main Mobile Device Management Scenarios
- Corporate: The device, applications and data are the property of, and controlled by, the company. The user is given a unique corporate identity with multi-factor authentication (MFA) support.
- Personal (BYOD): The device is owned by the user, but they sign into the company’s portal to auto-install and configure Outlook, OneDrive, Teams, and other company apps. The company partially manages the device and applications, but personal and corporate identities are kept separate.
- Personal (MAM-WE): The device is owned by the user, subject to Microsoft Application Management – Without Enrollment protocols. Users sign into each app and configure it individually. The apps are partially managed by the company and given dual identities, separating corporate data from personal data.
The team agreed that, in all these mobile device management scenarios, application protection policies should include PINs and include “do not copy/paste” rules. The panel then discussed the top security threats to mobile devices.
The Top 7 Mobile Device Security Threats

Data Leakage
Data leakage can happen in many ways, such as employees saving emails to a personal cloud storage drive, malware on their phones, or simply using unvetted mobile apps. In fact, mobile applications are not as secure as their desktop counterparts and can increase the risk of data leakage to unauthorized external users.
Your IT team can prevent data leakage by extending their Data Loss Prevention and Information Protection policies to their remote users’ mobile devices. They should also implement protocols that block users and applications from transferring data from corporate-owned apps to personal apps.
Unsecured WiFi
The rise in remote work means employees are working from anywhere, including by accessing open wireless networks like those in coffee shops. A mobile device that is connected to a public, often unsecured, network is vulnerable. And since not all mobile applications validate certificate authorities, the device is left open to attack by bad actors.
You can reduce the risk of a data breach over unsecured Wi-Fi by providing employees with managed corporate phones and encrypting traffic with a VPN service. Labeling and encrypting your company’s sensitive data can prevent it from being exploited if it falls into the wrong hands. However, enforcing mobile management policies that allow corporate data to be accessed and transferred only through corporate-approved, controlled apps is the best way to keep it out of the wrong hands in the first place.
Network Spoofing
Network spoofing occurs when a bad actor masquerades as a legitimate network and tricks mobile device users into believing it is a trusted source. For example, a spoofer can listen in on the wireless network at a local coffee shop and identify a user they want to hack. They then create an access point with the same name as the coffee shop and wait for their mark to log in, giving the spoofer access to the mobile device.
Spoofers can attack using various protocols, including Dynamic Host Configuration Protocol (DHCP), Web Proxy Auto-Discovery Protocol (WPAD), and other systems, to bait users into providing their credentials. To avoid spoofing, users should disable legacy protocols on their mobile devices and ensure that corporate data is transferred via secure protocols, with proper application policies in place.
Phishing
Phishing is a type of social engineering in which an attacker sends a fraudulent email (phishing) or text/SMS message (smishing). The spoofer tricks the user into handing over sensitive information, such as their passwords, and deploys malicious software, like ransomware, onto their mobile device. Recently, bad actors have been hacking COVID-19 vaccine booking systems and smishing the contact database. (In fact, this happened to Amol during the webinar – no joke.)
To prevent phishing/smishing attacks, ensure you have protection mechanisms installed on all mobile devices. Corporate IT protocols should be in place so that, even if a user opens a link in an email, it is scanned for malicious activity before the user can proceed. You should also restrict access to your corporate IT infrastructure from any unmanaged devices and applications that your company’s IT team cannot control.
Spyware
Spyware is used to monitor and collect data. It is usually installed when a user clicks a malicious advertisement or falls for a scam that tricks them into downloading it. Mobile phones are a prime target for spyware because they have numerous data-gathering sensors, including cameras on both sides, microphones, accelerometers, and GPS locators. And, because mobile phones are also used for MFAs and push notifications, hackers love to exploit them.
To prevent spyware from being downloaded onto your employees’ mobile devices, you should utilize the same corporate anti-malware strategy that applies to your company’s IT enterprise. Integrating advanced threat protection mechanisms, like Defender for Endpoint, into your company’s overall malware strategy is also critical.
Broken Cryptography
Validated mobile and desktop web browsers give users a sense of security. It is best practice to have this cryptography in mobile applications as well, but that isn’t always the case. Broken cryptography exposes sensitive data on the mobile device to bad actors who can assume the man-in-the-middle position between the target’s mobile application and the back-end API, pulling clear-text credentials off the phone.
To avoid broken cryptography, ensure your users’ mobile devices and applications are properly managed in accordance with your company’s IT security protocols. Only corporate-approved devices should have access to your corporate data, and jailbroken devices must be blocked.
Improper Session Handling
Improper session handling occurs when a session token is unintentionally leaked during a transaction session between a user’s mobile app and a backend server, allowing hackers to access your IT infrastructure. Another scenario is when a mobile application sends login/password information with every API request, leaving the mobile device exposed to a cyberattack.
To ensure proper session handling, please delineate between corporate-managed and non-corporate-managed applications, and ensure that all applications have undergone extensive vulnerability testing. HTTP sessions should be random and not guessable to reduce their predictability.
Mobile Application Security Testing
Mobile devices and applications are vulnerable to hackers and should undergo regular security checks. There should be equal attention paid to mobile devices as to desktop applications. Custom-developed mobile applications should be comprehensively tested, and back-end applications should undergo Dynamic Application Security Testing (DAST) to validate server-side controls. Key features, such as network captures, log reviews, disk activity, and credential exposures, need to be analyzed to ensure your users’ mobile devices and applications are secure.
Wrapping Up
CrucialLogics’ experts can help your IT team with these and other cybersecurity issues. We can also help educate your remote workforce on mobile device security. Want to learn more? Schedule a call with one of our experts by completing the form below or the contact form.


