Business Mobile Security Services

Protect the business information employees carry in their pockets

A mobile phone is no longer just a way to make calls.

It may give an employee access to:

  • Business email
  • Microsoft Teams
  • SharePoint
  • OneDrive
  • Customer records
  • Financial information
  • Cloud applications
  • Password-reset tools
  • Authentication codes
  • Business contacts
  • Confidential documents

That makes mobile devices valuable to your organisation.

It also makes them valuable to criminals.

A stolen password, fraudulent text message or lost phone may provide a route into business accounts and information.

The risk is not limited to company-owned devices.

Employees may use personal phones to read email, approve sign-ins, join Teams meetings or access business files.

Without clear mobile-security controls, the organisation may not know which devices are connected, whether they remain supported or what happens when one is lost.

Stratiis helps organisations protect mobile devices, applications, identities and business data without making mobile working unnecessarily difficult.

Secure the device. Protect the account. Keep business information under control.

What is mobile security?

Mobile security is the combination of technology, policies and processes used to protect smartphones, tablets, applications, accounts and mobile data.

It may include:

  • Mobile Device Management
  • Mobile application protection
  • Device encryption
  • Screen-lock policies
  • Multi-factor authentication
  • Conditional Access
  • Phishing protection
  • Application controls
  • Operating-system updates
  • Remote lock and wipe
  • Lost-device procedures
  • Secure Wi-Fi use
  • Mobile threat protection
  • SIM-account security
  • User awareness
  • Joiner and leaver processes

A secure mobile service should consider the full route to business information.

Protecting only the handset is not enough when the employee’s account can still be accessed from another unapproved device.

Why mobile devices create business risk

Mobile devices are small, portable and used in many different environments.

They may be:

  • Lost
  • Stolen
  • Shared
  • Left unlocked
  • Connected to public Wi-Fi
  • Used by family members
  • Replaced without notifying IT
  • Running unsupported software
  • Used to scan malicious QR codes
  • Targeted by fraudulent text messages
  • Connected to personal cloud services
  • Used for multi-factor authentication

Employees may also be more likely to act quickly on a mobile device.

A small screen can make it harder to inspect:

  • Email addresses
  • Website links
  • Login pages
  • Attachment names
  • Security warnings
  • Application permissions

Criminals take advantage of this urgency and reduced visibility.

Is your mobile environment properly protected?

You may recognise some of these situations:

  • Employees access business email from unmanaged phones
  • Nobody knows which devices are connected
  • Personal phones store company documents
  • Former employees remain signed into mobile applications
  • Mobile operating systems are out of date
  • Lost devices are reported informally
  • Business contacts synchronise to personal accounts
  • Employees approve unexpected sign-in prompts
  • SMS is used for every authentication process
  • Personal applications can open company files
  • Users install applications without review
  • Company phones do not have enforced screen locks
  • Shared tablets remain signed into one person’s account
  • Mobile security depends entirely on employee behaviour
  • The organisation cannot remove business data remotely

These risks can be reduced through a managed mobile-security approach.

Our mobile-security services

Stratiis can help with:

  • Mobile Device Management
  • Microsoft Intune
  • Microsoft 365 mobile security
  • Mobile application management
  • Conditional Access
  • Multi-factor authentication
  • Device compliance
  • Application-protection policies
  • Mobile threat protection
  • Phishing protection
  • Secure email access
  • Device encryption
  • Remote lock and wipe
  • Lost-device response
  • BYOD security
  • Company-owned device security
  • Shared-device security
  • Secure mobile onboarding
  • Joiner and leaver processes
  • Mobile-security policies
  • User awareness
  • Mobile estate reviews
  • Ongoing monitoring and support

Mobile security starts with identity

A mobile device is often only the route to a business account.

The information itself may be stored in:

  • Microsoft 365
  • Cloud applications
  • Customer systems
  • File-sharing platforms
  • Finance applications
  • Business databases

If a criminal steals the employee’s password, they may not need the physical phone.

Mobile security should therefore include strong identity controls.

These may include:

  • Multi-factor authentication
  • Conditional Access
  • Sign-in risk detection
  • Strong password policies
  • Passkeys
  • Authentication applications
  • Security keys
  • Session controls
  • Account monitoring

The goal is to make sure the person, device and application are all trusted appropriately.

Multi-factor authentication

Multi-factor authentication requires the user to provide more than a password.

This may involve:

  • An authentication application
  • A security key
  • A biometric check
  • A passkey
  • A temporary code
  • A managed-device certificate

Multi-factor authentication makes stolen passwords less useful.

It should still be configured carefully.

Employees may be targeted with repeated approval requests until they accept one by mistake.

They should understand:

  • Never approve an unexpected sign-in
  • Check the application and location
  • Report repeated prompts
  • Do not share authentication codes
  • Do not confirm a request because someone telephones and asks

Authentication applications

An authentication application may provide stronger protection than relying only on text-message codes.

It may support:

  • Number matching
  • Sign-in details
  • Biometric approval
  • Passwordless access
  • Account alerts

The application itself should be protected by:

  • Device screen lock
  • Biometric security
  • Device encryption
  • Supported software
  • Secure account recovery

The organisation should also have a process for moving authentication to a replacement phone.

SMS authentication

Text-message codes are commonly used for account security.

They are generally better than using only a password.

They may still be affected by:

  • SIM-swap fraud
  • Stolen phones
  • Number reassignment
  • Message interception
  • Social engineering
  • Poor account-recovery processes

Where suitable, organisations may use stronger methods such as:

  • Authentication applications
  • Passkeys
  • Security keys
  • Managed-device authentication
  • Certificate-based access

SMS may remain useful as part of a wider approach, but it should not automatically be the only method for every user and system.

SIM-swap fraud

SIM-swap fraud occurs when a criminal persuades a mobile provider to transfer a victim’s number to another SIM.

The genuine user may suddenly lose mobile service.

The criminal may then receive:

  • Telephone calls
  • Text messages
  • Password-reset codes
  • Authentication codes

Controls may include:

  • Strong mobile-account passwords
  • Account security PINs
  • Restricted account administrators
  • Provider verification procedures
  • Prompt investigation of unexpected service loss
  • Reduced dependence on SMS authentication
  • Monitoring of account changes

An employee who unexpectedly loses mobile service should report it immediately, especially when other suspicious account activity is occurring.

Conditional Access

Conditional Access decides whether a sign-in should be allowed based on defined conditions.

It may consider:

  • User identity
  • Device compliance
  • Application
  • Location
  • Sign-in risk
  • Multi-factor authentication
  • Device ownership
  • Operating system
  • Authentication method

For example, the organisation may allow email access only when:

  • The user completes multi-factor authentication
  • The device is compliant
  • The approved Outlook application is used

Conditional Access helps reduce the risk of company data being accessed from unknown or insecure mobile devices.

Mobile Device Management

Mobile Device Management helps the organisation configure, monitor and secure smartphones and tablets.

It may be used to:

  • Enrol devices
  • Require screen locks
  • Verify encryption
  • Deploy applications
  • Configure email
  • Configure Wi-Fi
  • Check compliance
  • Block unsupported devices
  • Lock lost devices
  • Remove company information
  • Wipe company-owned devices

Mobile Device Management provides the technical foundation for many mobile-security controls.

Mobile application management

Mobile application management protects company data within approved applications.

It may be used without taking full control of a personal device.

Application controls may:

  • Require an application PIN
  • Require biometric verification
  • Encrypt business data
  • Prevent copying into personal applications
  • Block saving to personal cloud storage
  • Restrict screenshots
  • Control file opening
  • Remove business data selectively
  • Require approved applications

This may be appropriate for employees using personal phones.

Company-owned mobile devices

Company-owned devices normally allow stronger security controls.

The organisation may be able to:

  • Control setup
  • Install required applications
  • Restrict unapproved applications
  • Enforce updates
  • Require encryption
  • Control accounts
  • Wipe the entire device
  • Block configuration changes
  • Restrict personal use

Employees should understand how the device may be used and what the organisation can manage.

Bring Your Own Device security

Bring Your Own Device allows employees to use personal phones or tablets for work.

This can improve convenience.

It also creates questions about:

  • Employee privacy
  • Business-data separation
  • Application access
  • Operating-system support
  • Device sharing
  • Lost-device response
  • Selective wipe
  • Support responsibility
  • Personal cloud backup

A secure BYOD design may use:

  • Application-protection policies
  • Work profiles
  • Conditional Access
  • Approved applications
  • Multi-factor authentication
  • Minimum operating-system versions
  • Selective business-data removal

A personal device should not automatically receive the same network and application access as a fully managed company device.

Protecting employee privacy

Mobile security should be proportionate.

Employees using personal devices may reasonably want to know:

  • What the organisation can see
  • Whether personal messages are visible
  • Whether photographs can be accessed
  • Whether location is tracked
  • Which applications are managed
  • What information is collected
  • Whether the whole device can be wiped
  • What happens when they leave

The organisation should provide clear information before enrolment.

A well-designed BYOD approach should protect business data without unnecessarily monitoring personal activity.

Work profiles

Supported mobile devices may allow a separate work area.

This can help separate:

  • Business applications
  • Business documents
  • Company accounts
  • Business contacts
  • Personal applications
  • Personal information

The organisation may manage the work profile while leaving the personal side outside its control.

When employment ends, the work profile can often be removed without deleting personal content.

Device encryption

Encryption helps protect information stored on a mobile device.

If the device is lost, encrypted data is harder to access without the approved passcode.

Encryption should be combined with:

  • Strong screen locks
  • Supported operating systems
  • Remote wipe
  • Secure accounts
  • Prompt loss reporting
  • Application protection

Encryption does not protect information when the device is unlocked and available to an unauthorised person.

Screen locks and biometrics

A mobile device should lock automatically after a short period of inactivity.

Security policies may require:

  • Minimum PIN length
  • Password complexity
  • Biometric unlock
  • Automatic locking
  • Limits on failed attempts
  • No simple or repeated PINs

Biometrics can improve convenience.

They should normally work alongside a secure passcode rather than replacing it entirely.

Rooted and jailbroken devices

Rooted or jailbroken devices have been modified to remove operating-system restrictions.

This can weaken built-in security and allow untrusted software or configuration changes.

Mobile-security policies may:

  • Detect modified devices
  • Mark them as non-compliant
  • Block access
  • Require remediation

Business information should not be accessed from rooted or jailbroken devices.

Operating-system updates

Mobile operating-system updates often correct security vulnerabilities and reliability problems.

Security issues arise when:

  • Employees delay updates
  • Devices are too old to update
  • Manufacturers stop providing support
  • Applications require a newer version
  • Shared devices are forgotten

A managed platform can identify which operating-system versions are in use.

The organisation can then set a minimum supported version.

Unsupported mobile devices

A phone may still turn on and make calls after security support ends.

That does not make it suitable for business data.

Unsupported devices may:

  • Miss security fixes
  • Fail application requirements
  • Become non-compliant
  • Create audit concerns
  • Stop supporting authentication tools
  • Become unreliable

Replacement should be planned around manufacturer support rather than waiting for physical failure.

Mobile applications

Applications may request access to:

  • Contacts
  • Camera
  • Microphone
  • Files
  • Location
  • Messages
  • Photos
  • Bluetooth
  • Notifications

Some access is necessary for the application to work.

Other permissions may be excessive.

The organisation should control or review:

  • Approved business applications
  • High-risk applications
  • Sideloaded software
  • Personal file-sharing applications
  • Unapproved messaging platforms
  • Applications with unnecessary permissions
  • Unsupported software

Unapproved application stores

Mobile operating systems normally provide official application stores.

Installing applications from other sources may increase the risk of:

  • Malware
  • Fake applications
  • Modified software
  • Credential theft
  • Excessive permissions
  • Unsupported updates

Company-owned devices may be configured to block unapproved application stores and sideloading.

Fake mobile applications

Criminals may create fake versions of:

  • Banking applications
  • Authentication tools
  • Delivery services
  • Microsoft applications
  • Business portals
  • Security applications

Employees should install applications only through approved sources.

Where possible, required business applications should be deployed or listed through the organisation’s management platform.

Mobile phishing

Mobile phishing may arrive through:

  • Email
  • SMS
  • Messaging applications
  • Social media
  • QR codes
  • Fake notifications
  • Calendar invitations
  • Collaboration applications

Fraudulent messages may claim:

  • A delivery is waiting
  • A payment failed
  • The employee must sign in
  • Multi-factor authentication expired
  • A manager needs urgent help
  • A document has been shared
  • A mobile bill is overdue

Employees should be trained to stop and verify unexpected requests.

Smishing

Smishing is phishing delivered by text message.

A fraudulent message may include:

  • A malicious link
  • A fake payment request
  • A false security warning
  • A request for personal details
  • A number to call
  • An urgent account problem

Business users may be more likely to trust a message that appears to come from:

  • Microsoft
  • A bank
  • A mobile provider
  • A courier
  • A senior employee
  • A customer
  • A supplier

Employees should not provide passwords, security codes or payment information in response to an unexpected text.

QR-code phishing

QR codes are convenient because users can scan them quickly.

They can also hide the destination before the user opens it.

A malicious QR code may lead to:

  • A fake Microsoft login page
  • A fraudulent payment site
  • Malware
  • A false document-sharing page
  • An attacker-controlled application

Employees should treat unexpected QR codes in the same way as suspicious links.

They should check the destination and context before signing in.

Approval fatigue

A criminal with a stolen password may repeatedly send authentication requests to an employee.

The attacker hopes the user will eventually approve one to stop the notifications.

Employees should:

  • Deny unexpected requests
  • Report repeated prompts
  • Change the password if advised
  • Check recent account activity
  • Never approve a request because someone calls and asks

Number matching and stronger authentication methods can help reduce this risk.

Mobile email security

Employees frequently read email on mobile devices.

Security controls may include:

  • Approved email applications
  • Multi-factor authentication
  • Application-protection policies
  • Attachment controls
  • Link protection
  • Anti-phishing tools
  • Conditional Access
  • Secure account setup
  • Copy-and-paste restrictions

Employees should not configure company email in unapproved applications simply because the device allows it.

Protecting business files

Business documents may be opened through:

  • Outlook
  • Teams
  • SharePoint
  • OneDrive
  • Customer applications
  • File-sharing systems

Mobile-security policies may prevent files from being:

  • Saved to personal cloud storage
  • Opened in personal applications
  • Shared through personal messaging
  • Copied into unmanaged notes
  • Backed up to personal accounts

The controls should focus on the most sensitive information without making ordinary work impossible.

Business contacts on personal phones

Employees may synchronise customer or colleague contacts to personal accounts.

This can create problems when:

  • The employee leaves
  • The personal account is compromised
  • Contacts are backed up outside the organisation
  • The device is shared
  • Customer information is retained indefinitely

The organisation should define how business contacts are stored, synchronised and removed.

Mobile browsers

Employees may use mobile browsers to access business services.

Browser-based access can create risks when:

  • Passwords are saved insecurely
  • Personal browser profiles are used
  • Downloads remain on the device
  • Sessions stay signed in
  • Malicious extensions or applications interact with data
  • The device is unmanaged

Conditional Access and session controls may restrict what unmanaged browsers can do.

Public Wi-Fi

Employees may connect mobile devices to public wireless networks in:

  • Hotels
  • Cafés
  • Airports
  • Trains
  • Conference venues
  • Shared offices

Risks may include:

  • Fake network names
  • Unencrypted connections
  • Traffic interception
  • Malicious login pages
  • Device exposure

Employees should:

  • Confirm the genuine network name
  • Avoid unusual certificate warnings
  • Use approved secure applications
  • Avoid highly sensitive work where possible
  • Use mobile data or an approved hotspot when appropriate
  • Keep device sharing disabled
  • Use VPN services where required

Modern encrypted applications reduce some risk, but public Wi-Fi should still be used carefully.

Mobile hotspots

Mobile hotspots can provide a useful alternative to public Wi-Fi.

They may be used during:

  • Travel
  • Customer-site visits
  • Broadband outages
  • Temporary working
  • Remote projects

Security considerations include:

  • Strong hotspot passwords
  • Approved device use
  • Data limits
  • Automatic shutdown
  • Unauthorised connections
  • Business policy
  • Device battery
  • Mobile coverage

A managed mobile router may be better for repeated or team use.

Bluetooth security

Bluetooth is used for:

  • Headsets
  • Keyboards
  • Cars
  • Speakers
  • Wearable devices
  • File sharing

Employees should:

  • Pair only trusted devices
  • Remove old pairings
  • Avoid leaving devices permanently discoverable
  • Confirm unexpected pairing requests
  • Keep software updated
  • Avoid transferring sensitive files through unapproved methods

Bluetooth does not need to be disabled completely where it supports legitimate work.

It should be used intentionally.

Near-field communication

Near-field communication may support:

  • Contactless payments
  • Access cards
  • Device pairing
  • Information transfer

Users should understand which services are active and report unexpected prompts.

Company devices should not be used for unapproved payment or access applications where this conflicts with policy.

Lost or stolen mobile devices

A lost or stolen device may expose:

  • Business email
  • Authentication applications
  • Company files
  • Customer contacts
  • Text messages
  • Mobile data
  • Saved passwords
  • Active sessions

A clear response process may include:

  • Report the device immediately
  • Confirm the user and device
  • Suspend the SIM
  • Lock the device
  • Revoke active sessions
  • Reset affected credentials
  • Remove or wipe business data
  • Review account activity
  • Assess data exposure
  • Provide a replacement
  • Update the asset record
  • Record the incident

Employees should know who to contact outside normal office hours where the risk is significant.

Remote lock and wipe

A managed device may be locked or wiped remotely.

Remote lock

This can secure the screen and require the correct passcode.

Selective wipe

This removes business applications and data while leaving personal information in place.

Full wipe

This removes all information and resets the device.

The available action depends on:

  • Device ownership
  • Management method
  • Device connectivity
  • Platform support
  • Business risk

A remote command may remain pending until the device reconnects.

Identity and account access should also be secured immediately.

Mobile number security

Business mobile numbers may be used for:

  • Customer communication
  • Account recovery
  • Authentication
  • Banking
  • Messaging applications
  • Published contact details

The organisation should keep control of important numbers.

This includes:

  • Recording ownership
  • Restricting account changes
  • Using provider security PINs
  • Reassigning numbers safely
  • Removing former employees
  • Reviewing call forwarding
  • Protecting porting requests

Mobile account administration

Access to the business mobile-provider account should be limited.

Administrators may be able to:

  • Order SIMs
  • Transfer numbers
  • Activate roaming
  • View usage
  • Change services
  • Request replacements
  • Suspend accounts

Controls may include:

  • Named administrators
  • Strong passwords
  • Multi-factor authentication
  • Security PINs
  • Change approval
  • Regular access reviews
  • Prompt removal of former administrators

A compromised mobile-provider account may allow criminals to interfere with business numbers and services.

Mobile malware

Mobile malware may attempt to:

  • Steal passwords
  • Read messages
  • Monitor activity
  • Display fraudulent login screens
  • Access contacts
  • Record calls or audio
  • Control the device
  • Send premium messages
  • Install additional software

Risk can be reduced through:

  • Supported devices
  • Official application stores
  • Application controls
  • Operating-system updates
  • User awareness
  • Mobile threat protection
  • Device compliance
  • Prompt incident reporting

Mobile threat protection

Mobile threat-protection services may inspect or assess:

  • Malicious applications
  • Unsafe network connections
  • Phishing links
  • Device compromise
  • Operating-system vulnerabilities
  • Risky configurations

They may integrate with device management and Conditional Access.

For example, a high-risk device may be blocked from business systems until the issue is resolved.

The service should be selected according to the organisation’s risk, licensing and device environment.

Mobile antivirus

Traditional desktop antivirus does not always operate in the same way on mobile platforms.

Mobile security may rely on a combination of:

  • Operating-system protection
  • Application-store controls
  • Device management
  • Threat detection
  • Identity security
  • Application protection
  • User awareness

The right solution depends on the mobile operating system and business use.

Installing an application labelled “antivirus” does not automatically create complete mobile protection.

Secure mobile backups

Mobile devices may back up information to:

  • Apple services
  • Google services
  • Manufacturer platforms
  • Personal cloud accounts
  • Business cloud services

The organisation should understand whether business information is included in personal backups.

Company data should remain within approved business systems where possible.

Application-protection policies may restrict personal backup and storage.

Mobile security and Microsoft 365

Microsoft 365 mobile access may involve:

  • Outlook
  • Teams
  • OneDrive
  • SharePoint
  • Authenticator
  • Microsoft business applications

Security may combine:

  • Microsoft Intune
  • Conditional Access
  • Multi-factor authentication
  • Application-protection policies
  • Defender services
  • Identity monitoring
  • Secure email controls
  • Data-loss prevention

The design should reflect existing licences and the sensitivity of the information.

Mobile security and Microsoft Teams

Teams may contain:

  • Customer conversations
  • Employee discussions
  • Shared files
  • Meeting recordings
  • Business decisions
  • Contact information

Mobile controls may:

  • Require approved devices
  • Require an application PIN
  • Prevent copying into personal applications
  • Restrict file downloads
  • Remove business data after a user leaves
  • Require compliant devices for sensitive teams

The organisation should avoid treating Teams chat as less sensitive than email.

Mobile security and Hosted Voice

Employees may use Hosted Voice or Teams Phone applications on mobile devices.

Security should consider:

  • Business caller identity
  • Call history
  • Voicemail
  • Recorded calls
  • Customer contacts
  • Device loss
  • Application access
  • Employee departure

The business number and call data should remain under organisational control.

Shared mobile devices

Shared smartphones and tablets may be used by:

  • Reception teams
  • Repairs teams
  • Warehouse employees
  • Duty managers
  • Frontline workers
  • Community teams
  • Events

Risks include:

  • One user remaining signed in
  • Shared passwords
  • Unclear ownership
  • Customer data visible to the next user
  • Lost devices not being reported
  • Applications installed informally

Shared devices should use an approved sign-in and management model.

Kiosk and dedicated devices

Dedicated mobile devices may run only one or a small number of applications.

Examples include:

  • Visitor check-in tablets
  • Room-booking panels
  • Stock devices
  • Survey tablets
  • Digital signage controllers
  • Field-service terminals

Security controls may:

  • Lock the device to approved applications
  • Block settings changes
  • Disable personal accounts
  • Prevent application installation
  • Restart automatically
  • Report compliance
  • Apply remote updates

Mobile security for remote workers

Remote employees may use mobile devices for:

  • Authentication
  • Email
  • Teams
  • Business calls
  • Cloud files
  • Mobile hotspots
  • Customer applications

Security should consider:

  • Personal Wi-Fi
  • Public networks
  • Device sharing
  • Secure storage
  • Lost-device response
  • Application access
  • Remote support
  • Business and personal separation

Remote working should not mean lower mobile-security standards.

Mobile security for field workers

Field workers may carry devices containing:

  • Customer addresses
  • Tenant details
  • Job schedules
  • Photographs
  • Forms
  • Signatures
  • Safety information
  • Access instructions

Their devices face increased risk of:

  • Loss
  • Theft
  • Damage
  • Unattended use
  • Poor connectivity
  • Shared use

Controls may include:

  • Strong screen locks
  • Remote wipe
  • Short lock periods
  • Application protection
  • Offline-data controls
  • Device encryption
  • Asset tracking
  • Rapid replacement

Mobile security for accountancy firms

Accountancy firms may use mobile devices to access:

  • Client email
  • Tax documents
  • Payroll
  • Cloud accounting
  • SharePoint
  • OneDrive
  • Teams
  • Authentication tools

A lost or unmanaged device could expose confidential client information.

Mobile access should be limited to approved applications and appropriately secured devices.

Mobile security for housing associations

Housing officers, repairs teams and property employees may access:

  • Tenant records
  • Repairs information
  • Property photographs
  • Contact details
  • Case notes
  • Housing systems
  • Microsoft Teams

Mobile-security controls should protect sensitive information while allowing employees to work effectively away from the office.

Photographs and documents should remain in approved business systems rather than personal galleries or cloud accounts.

Mobile security for charities

Charities may use a mixture of:

  • Company devices
  • Personal phones
  • Volunteer devices
  • Shared tablets
  • Temporary project equipment
  • Outreach devices

Service-user and donor information may be particularly sensitive.

The organisation should define which devices are allowed, how access ends and how business information is removed.

Mobile security for professional services firms

Professional services firms may need to protect:

  • Client communications
  • Documents
  • Case information
  • Financial data
  • Meeting content
  • Business contacts

Mobile security should support professional work without allowing confidential data to move into personal applications or storage.

Mobile security for construction and engineering

Construction and engineering teams may use mobile devices for:

  • Drawings
  • Site information
  • Photographs
  • Customer details
  • Risk assessments
  • Forms
  • Navigation
  • Communication

Devices may be exposed to harsh environments and frequent user changes.

The security design should support rugged devices, rapid replacement, remote wipe and clear asset ownership.

Mobile-security policies

A mobile-security policy may explain:

  • Which devices can access company data
  • Whether personal devices are allowed
  • Minimum operating-system requirements
  • Screen-lock requirements
  • Approved applications
  • Lost-device reporting
  • Public Wi-Fi use
  • Mobile hotspot use
  • Rooting and jailbreaking
  • Business-data storage
  • Personal cloud services
  • Roaming
  • Device monitoring
  • Leaver responsibilities
  • Acceptable personal use

The policy should be understandable and supported by technical controls.

A written rule alone does not prevent an unapproved device from accessing company email.

Mobile-security awareness

Employees should understand mobile-specific threats.

Training may cover:

  • Suspicious text messages
  • Fake authentication requests
  • QR-code phishing
  • Malicious applications
  • Public Wi-Fi
  • SIM-swap warning signs
  • Lost-device reporting
  • Safe application installation
  • Business and personal data separation
  • Unexpected account prompts

Training should be practical and linked to situations employees actually encounter.

Mobile-security incident response

A mobile-security incident may involve:

  • Lost or stolen device
  • Suspicious application
  • Fraudulent text
  • Compromised account
  • SIM swap
  • Unapproved device
  • Data copied into a personal service
  • Former employee access
  • Malware warning
  • Repeated authentication prompts

The response process should define:

  • Who reports the incident
  • Who suspends the SIM
  • Who locks or wipes the device
  • Who secures the identity
  • Who reviews account activity
  • Whether data-protection review is required
  • How the user receives a replacement
  • How the incident is documented

Mobile-security monitoring

Monitoring may provide information about:

  • Device compliance
  • Operating-system versions
  • Sign-in risk
  • Unusual locations
  • Application risk
  • Threat detections
  • Unsupported devices
  • Repeated authentication failures
  • Lost-device actions
  • Devices not checking in

Monitoring should be connected to a response process.

A warning has limited value when nobody owns the investigation.

Mobile-security reporting

Useful reporting may help answer:

  • Which devices are unmanaged?
  • Which devices are out of date?
  • Which users access email from personal phones?
  • Which devices are non-compliant?
  • Which applications create risk?
  • Which former employees retain mobile access?
  • Which devices have not checked in recently?
  • Which accounts have suspicious sign-ins?
  • Which devices need replacement?

Reports should lead to practical action rather than becoming another unused dashboard.

Joiner security

When a new employee joins, mobile access should be provided through a controlled process.

This may include:

  • Approved device
  • Business SIM
  • Device enrolment
  • Multi-factor authentication
  • Required applications
  • Security policies
  • Wi-Fi configuration
  • User guidance
  • Asset registration
  • Testing

Employees should not be told simply to add company email to any phone they choose.

Role changes

A change of role may require changes to:

  • Business applications
  • Data access
  • Administrator rights
  • Mobile number
  • Device type
  • Roaming permissions
  • International calling
  • Security requirements

Access should follow the role rather than remaining indefinitely after it is no longer needed.

Leaver security

When an employee leaves, the organisation should:

  • Block sign-in
  • Revoke sessions
  • Remove business data
  • Recover company devices
  • Retain or reassign business numbers
  • Suspend or cancel SIMs
  • Remove authentication methods
  • Remove mobile applications
  • Update the asset record
  • Review customer contact arrangements
  • Prepare devices securely for reuse

This process should happen promptly.

A personal device should no longer retain access to company email, files or Teams after employment ends.

Secure device reuse

Before a company device is reassigned, it should be:

  • Removed from the previous user
  • Wiped
  • Updated
  • Checked for damage
  • Removed from previous activation accounts
  • Re-enrolled
  • Assigned to the new employee
  • Recorded in the asset register
  • Tested

The next employee should not inherit the previous user’s messages, contacts or applications.

Secure disposal

Before a mobile device is recycled or disposed of, the organisation should:

  • Remove accounts
  • Remove SIMs
  • Wipe the device
  • Remove management records
  • Remove activation locks
  • Update asset records
  • Confirm data destruction
  • Use an approved disposal provider

A damaged device may still contain accessible data.

Benefits of managed mobile security

Better control of business access

The organisation can decide which users, devices and applications are approved.

Reduced lost-device risk

Devices can be locked, wiped and removed from company systems.

Stronger identity protection

Multi-factor authentication and Conditional Access reduce password-only access.

Safer personal-device use

Application protection can separate company data from personal information.

Better application control

Business documents can be kept inside approved applications.

Improved visibility

Unsupported, unmanaged and non-compliant devices can be identified.

Faster incident response

Security actions can be taken through an agreed process.

Better joiner and leaver management

Mobile access follows the employee lifecycle.

Improved compliance

The organisation can demonstrate that mobile security standards are applied.

Safer hybrid and field working

Employees can access business systems securely away from the office.

What are the disadvantages of mobile security controls?

Employees may experience additional steps

Enrolment, application PINs and authentication checks can add friction.

Some personal devices may not qualify

Older or unsupported phones may be blocked.

BYOD creates privacy concerns

The organisation must explain what it can manage and see.

Licensing may be required

Some controls depend on Microsoft or third-party security licences.

Policies require testing

An incorrect rule can block legitimate users.

Mobile threats continue to change

Technology and employee awareness need ongoing review.

Not every feature works on every platform

Apple and Android management capabilities differ.

Security can become too restrictive

Controls should protect information without preventing reasonable work.

Common mobile-security mistakes

Protecting the phone but not the identity

A stolen password may allow access from another device.

Allowing unmanaged mobile email

The organisation loses control of where data is stored.

Using SMS as the only authentication method

Stronger options may be available.

Ignoring personal-device privacy

This can damage trust and adoption.

Applying the same policy to every user

Executives, field workers and occasional users may have different risks.

Failing to block unsupported devices

Old phones may continue accessing company systems.

Allowing business files into personal applications

Information may remain after the employee leaves.

Having no lost-device procedure

Employees may delay reporting or contact the wrong person.

Relying on employee awareness alone

Technical controls should support training.

Treating MDM as complete mobile security

Identity, phishing, email and application risks also need protection.

Failing to remove leavers

Business information and authentication methods may remain active.

What should you look for in a mobile-security provider?

Identity expertise

The provider should understand multi-factor authentication, Conditional Access and account risk.

Mobile Device Management knowledge

They should understand Microsoft Intune, Apple and Android management.

Application protection

They should explain how business data is kept within approved applications.

BYOD experience

Personal-device security should respect employee privacy.

Threat awareness

The provider should understand mobile phishing, malicious applications and SIM-swap risk.

Practical policy design

Security should be proportionate and usable.

Microsoft 365 knowledge

Mobile access should align with email, Teams, SharePoint and OneDrive security.

Incident response

Lost-device and compromised-account processes should be documented.

User training

Employees need practical guidance on mobile threats.

Ongoing monitoring

Unsupported and non-compliant devices should be identified.

Questions to ask before improving mobile security

  • Which mobile devices access business data?
  • Are they company-owned or personal?
  • Which applications contain sensitive information?
  • Are unmanaged devices allowed?
  • Is multi-factor authentication required?
  • Is SMS the main authentication method?
  • Is Conditional Access configured?
  • Are devices encrypted?
  • Are screen locks enforced?
  • Which operating systems are supported?
  • Can business data be removed remotely?
  • Can files be saved to personal applications?
  • Are rooted or jailbroken devices blocked?
  • How are applications approved?
  • What happens when a phone is lost?
  • Who suspends the SIM?
  • Who secures the user account?
  • How are leavers removed?
  • What mobile-security training is provided?
  • Which security licences are already available?

Our mobile-security process

1

Discovery

We begin by understanding:

  • Number of mobile users
  • Device ownership
  • Microsoft 365
  • Business applications
  • Sensitive information
  • Current security
  • BYOD
  • Field working
  • Remote working
  • Mobile contracts
  • Authentication methods
  • Existing incidents
  • User-support requirements

2

Mobile-risk assessment

We review:

  • Mobile device access
  • Personal-device use
  • Application access
  • Operating-system versions
  • Device compliance
  • Authentication methods
  • Lost-device process
  • SIM security
  • Business-data storage
  • Public Wi-Fi use
  • Leaver controls
  • Existing policies

3

Identity review

We assess:

  • Multi-factor authentication
  • Authentication methods
  • Conditional Access
  • Sign-in risk
  • Legacy authentication
  • Account recovery
  • Administrator access
  • Mobile-provider account security

4

Device and application design

We define the appropriate controls for:

  • Company-owned devices
  • Personal devices
  • Shared devices
  • Frontline devices
  • Executives
  • Temporary workers
  • Contractors
  • High-risk users

5

Policy design

Policies may cover:

  • Supported devices
  • Encryption
  • Screen locks
  • Operating-system versions
  • Rooted devices
  • Approved applications
  • Business-data sharing
  • Public Wi-Fi
  • Lost devices
  • SIM security
  • BYOD
  • Joiners and leavers
  • Device disposal

6

Technical configuration

We configure appropriate controls such as:

  • Microsoft Intune
  • Application protection
  • Device compliance
  • Conditional Access
  • Multi-factor authentication
  • Threat protection
  • Email security
  • Secure Wi-Fi profiles
  • Remote lock and wipe
  • Reporting
  • Administrator controls

7

Pilot deployment

We test the design with a smaller group covering different:

  • Device types
  • Operating systems
  • Ownership models
  • User roles
  • Applications
  • Working locations

This helps identify access or usability problems before wider deployment.

8

User communication and training

Employees may receive guidance covering:

  • Mobile threats
  • Suspicious texts
  • Authentication prompts
  • QR codes
  • Lost-device reporting
  • Approved applications
  • BYOD privacy
  • Public Wi-Fi
  • Business-data handling
  • Support

9

Wider deployment

We roll out the agreed controls and track:

  • Device enrolment
  • Compliance
  • Application protection
  • Authentication
  • Unsupported devices
  • User issues
  • Policy exceptions
  • Remediation

10

Ongoing support and review

Stratiis can continue to support:

  • Lost devices
  • Compromised accounts
  • New starters
  • Leavers
  • Replacement phones
  • Application changes
  • Compliance
  • Conditional Access
  • Authentication
  • Mobile threats
  • Policy updates
  • Security reporting
  • Licensing
  • User support

Frequently asked questions

What is mobile security?

Mobile security protects smartphones, tablets, applications, identities and business information from loss, theft, fraud and unauthorised access.

Is a screen lock enough to protect a business phone?

No.

A screen lock is important, but mobile security should also include encryption, identity protection, application controls and lost-device response.

Does mobile security require Mobile Device Management?

MDM is a strong foundation for company-owned devices.

Application-level controls may be enough for some personal-device use cases.

Can personal phones be secured without full management?

Yes.

Mobile application management can protect business applications and data without managing every part of the personal phone.

Can the business see personal messages and photographs?

This depends on the management method.

A properly designed BYOD approach should limit visibility to the business information and device-security details the organisation genuinely needs.

Can company data be removed without wiping the whole phone?

Yes, when selective wipe or application-level management is configured appropriately.

What happens when a business phone is lost?

The SIM and accounts should be secured, the device should be locked or wiped, and suspicious activity should be reviewed.

Can a phone be wiped when it is offline?

The wipe command may remain pending until the device reconnects.

Account sessions and the SIM should also be secured immediately.

Is SMS secure for multi-factor authentication?

SMS is better than relying on a password alone but can be affected by SIM-swap fraud and other attacks.

Stronger authentication methods may be appropriate for some users and services.

What is SIM-swap fraud?

It is an attack where a criminal transfers someone’s mobile number to another SIM to receive their calls and text messages.

What is mobile phishing?

Mobile phishing uses fraudulent emails, texts, messages, applications or QR codes to steal passwords or information.

What is smishing?

Smishing is phishing delivered through SMS or text messages.

Are iPhones more secure than Android phones?

Both platforms provide strong security when devices are supported, updated and managed correctly.

Security also depends on applications, identity controls, configuration and user behaviour.

Should rooted or jailbroken phones be blocked?

Yes, in most business environments.

Modified devices may have weakened security controls.

Can old phones continue accessing company email?

They may be technically capable of doing so.

Unsupported phones should normally be blocked because they no longer receive suitable security updates.

Can Microsoft Intune improve mobile security?

Yes.

Intune can manage device compliance, applications, configuration and access when combined with suitable Microsoft identity controls.

What is Conditional Access?

Conditional Access uses factors such as user identity, device security and sign-in risk to decide whether access should be allowed.

Can unmanaged phones be blocked from Microsoft 365?

Yes.

Conditional Access can require approved applications or compliant devices for selected services.

Does mobile antivirus protect everything?

No.

Mobile security also requires identity protection, application controls, supported software and user awareness.

Is public Wi-Fi safe?

It can carry risk.

Employees should use approved applications, verify network names and use mobile data or secure alternatives for sensitive work where appropriate.

Can Stratiis secure company-owned and personal phones?

Yes.

We can design different controls for company-owned, personal, shared and specialist mobile devices.

Can Stratiis help with mobile contracts and SIM security?

Yes.

Stratiis can support SIM-only plans, mobile numbers, device management, account security and wider mobile services.

How much does mobile security cost?

The cost depends on:

  • Number of users
  • Device ownership
  • Microsoft licensing
  • Mobile Device Management
  • Application protection
  • Conditional Access
  • Threat protection
  • Deployment
  • User training
  • Ongoing monitoring
  • Support

Some required capabilities may already be included within existing Microsoft licences.

Protect mobile working without making employees afraid to use their devices

Mobile working should make your organisation more flexible.

It should not leave business information scattered across unknown phones, personal applications and unsupported devices.

The right mobile-security approach protects the device, the employee’s identity and the business data inside approved applications.

It also gives employees clear guidance when something goes wrong.

Stratiis can help you review your current mobile environment and introduce controls that reflect the way your people genuinely work.

Let’s make mobile access safer, easier to manage and less dependent on luck.