Mobile Device Security in the Enterprise

Corporate or personal device, MDM or application-level protection. Which model works when, and what to do when a device is lost.

A mobile device today is a full working tool: email, documents, the MFA app, often VPN access too. From a security perspective, though, it still sits outside the system in many organisations.

Three models

Corporate device, full management. The organisation owns and manages it. The strongest control, but the most expensive, and personal use must be settled.

Personal device, application-level protection. Managing not the device but corporate applications and the data within them. Personal data remains untouched. For most organisations this is the viable path.

Personal device, unmanaged. Web access only, downloads blocked, everything else denied. Where there is no capacity for the first two, this is the minimum.

In practice the second model works best, because it does not meet employee resistance while still addressing the real risk, which is corporate data.

What to configure regardless

Screen lock and encryption. On modern devices encryption is automatic where a screen lock exists. Without one, there is none.

Separating corporate data. A work profile or containerised applications prevent corporate documents landing in a personal cloud.

Remote wipe. Erasing corporate data from a lost device. On personal devices, selective wipe: the work profile only.

Minimum OS version. Do not permit access from unsupported systems. This is enforceable through conditional access.

Conditional access. Limited access from unmanaged or non-compliant devices: browser-based, without downloads.

What most forget: the MFA app usually sits on the same phone used to read email. If the device is lost, both factors were in one place. This is why every user needs a backup authentication method.

Lost device: the sequence

  1. Remote wipe of corporate data. Not the whole device where it is personally owned.
  2. Invalidating sessions. Remote wipe does not terminate sessions living elsewhere.
  3. Revoking MFA registration for that device, and re-registering with the backup method.
  4. Password rotation if a password manager was also on the device.
  5. Reviewing logs: was there access after the loss.

This process must exist in writing, because during the first real case nobody will have time to invent it.

What not to do

Do not force full management onto personal devices. It is legally problematic and employees route around it: they forward mail to a personal account, which is far worse.

Do not forget departures. When someone leaves, wiping corporate data from their personal device is as much part of the process as collecting the laptop.

Do not overlook tablets and smartwatches. If corporate email reaches those too, the same rules apply.

Our IT security services include designing the mobile access architecture.

Back to Insights
Related content

Related content

Questions on this topic?

Our specialists are happy to discuss what this means in your organisation's environment.