In a Special Interview: Quantum Gate Highlights the Need to Reconsider the Adopted Data Protection Structure
Mobile devices have become central to the digital identity of organizations, yet most institutions still rely on tools that were not originally designed to protect them.
Adnan Fakheri, Customer Success Manager at Quantum Gate, explains the main existing gaps and why it has become necessary to reconsider the adopted data protection structure.
1. Why has the use of personal devices in work environments become an issue discussed at the board level today, rather than just a topic within IT policies?
The issue of using personal devices in work environments (BYOD) has never been fully resolved. Rather, it has been handled, managed, contained, and reconsidered from time to time. But what has changed today is that the conditions that made this approach sustainable have all changed simultaneously.
Mobile devices have now become a primary access point to enterprise systems, user identities, and sensitive workflows. Hybrid work has made access via personal devices unavoidable; organizations today are not so much choosing to adopt this model as they are dealing with an already existing reality.
The fundamental change lies in the role the smartphone now plays within the organization. It now carries authentication apps, single sign-on sessions, and multi-factor authentication tokens. When compromised, it becomes possible to access identities, user sessions, and authentication paths across multiple interconnected systems. This is precisely why threats targeting mobile devices are increasing, including phishing via messaging apps, AI-powered attacks, and exploitation of zero-click vulnerabilities, because attackers fully understand the importance of these devices.
Within organizations, pressure has reached the board level because gaps are no longer easy to ignore. Audit results, compliance gaps, and incidents originating from mobile devices are now appearing at the executive level. Traditional tools are no longer sufficient to provide the required assurance levels, and they also raise privacy concerns when used on personal devices. In the region, data sovereignty expectations have become stricter. With the high cost of issuing corporate devices on a large scale and associated complexities, versus the unmanaged risks of personal devices, the matter now requires a decision that cannot be kept on the deferred IT to-do list.
Therefore, boards of directors today treat mobile data exposure as a specific corporate risk for which they must take responsibility. This represents a significant shift compared to how this discussion was framed just two years ago.
2. What is the security threat related to mobile devices that CISOs still underestimate today, and why?
Identity-based attacks are the aspect still missing from most mobile security strategies. Most mobile security frameworks are built around the device itself, not the identity layer. Has the device been compromised? Is there malware on it? Has it been updated and enrolled in management systems? These are logical questions, but they do not always reflect where the most damaging attacks occur today. Phishing via text messages and messaging apps, MFA bypass, and session hijacking do not directly breach defenses; they exploit legitimate workflows and user behavior. In these cases, there is no malicious file to detect, no abnormal process to discover. That is why traditional detection tools are largely blind to them.
Mobile devices are now at the core of enterprise identity, and since they carry SSO sessions, MFA tokens, and authentication apps, compromising one device can open the door to accessing identities, sessions, and authentication paths across multiple enterprise systems. In contrast, detection tools still focus largely on the device and do not see attacks occurring at the identity layer.
Device management does not prevent a user from falling victim to social engineering that tricks them into performing an action that appears legitimate. The device may be healthy, enrolled, and fully compliant with policies, yet the attack succeeds. Because the target was never the device. It was the person using it.
3. Most regulated organizations already use mobile device management or container-based isolation solutions. Where do these approaches fail in practice?
Device control and data control are not the same thing, and it is precisely this gap that causes most mobile device management applications to fall short of the goal without it always being obvious.
Organizations rely on MDM and container isolation expecting data protection, but what they actually get is device management and logical boundaries that appear more robust than they really are. In most implementations, some enterprise data, session data, or cached information remains on the device. This data can leak through authorized actions performed by the user, via copy-paste, local caching, or integration with other applications. Phishing bypasses these controls entirely because it targets the user, not the container. These boundaries may be sufficient to meet compliance requirements, but they are not always enough to stop a determined attacker.
Remote wipe is often seen as the safety net, but it only works when the device is online and responsive. Therefore, containment is not guaranteed at the moment when it is most needed.
Employee resistance to using device management tools on their personal devices consistently leads to partial deployment of these solutions. Employees are reluctant to install management software on devices they own, and organizations often avoid enforcing it due to legal risks associated with accessing personal data. The result is coverage gaps that typically only appear after an incident.
Container isolation does not actually remove data from the device. It protects stored data through rules and encryption that may fail or be bypassed. The secure virtual mobile infrastructure takes a different approach; it does not store enterprise data on the endpoint, while enforcing copy-paste and file access controls within the workspace itself. Thus, there is no locally stored enterprise data that can be leaked, wiped, or recovered, because the data remains within the controlled environment.
4. How can a CISO distinguish between true structural separation and marketing claims?
Structural separation is one of the most used terms in mobile security, and at the same time one of the easiest to test.
Original source: AIT News
Comments (0)
Be the first to comment.