When Trusted Mobile Apps Become a Security Risk With Jamf

When Trusted Mobile Apps Become a Security Risk With Jamf

Can an app approved by Apple or Google still expose your business to security, privacy, and governance risks?

In this episode of Tech Talks Daily, I welcome back Michael Covington, Vice President of Strategy at Jamf, for a conversation about the false confidence that can surround mobile security. Apple and Android provide strong protections, including app review processes, sandboxing, and device authenticity controls. However, Michael argues that a device being secure on day one does not mean it will remain secure throughout its working life.

One of the most interesting points from our conversation is that mobile malware represents only a small part of the problem. Michael says it appears on fewer than 1% of the devices Jamf protects. The wider concerns include vulnerable third-party libraries, aging app versions, excessive permissions, unsafe web connections, compromised identities, software supply chains, and AI functionality introduced without the company fully understanding how it handles data.

Michael also shares findings from Jamf analysis of corporate applications. According to the research he discusses, 95% of the apps examined contained at least one medium or higher severity vulnerability, 10% used vulnerable third-party libraries, and 96% included AI features. For security leaders, this creates a much broader question than whether an app contains malware. They need to understand what the app can access, where it communicates, how it handles data, and whether its capabilities comply with company policy.

We discuss why familiar advice about updates, passwords, and suspicious links continues to fail when employees are busy or working from mobile devices on the front line. Michael explains how automation, clearer deadlines, and access policies can reduce risk without placing every responsibility on the user.

The conversation also covers BYOD security and employee privacy. Modern Apple and Android controls can separate business information from personal apps, allowing employers to manage the work container without inventorying an employee's private digital life. Michael believes many organizations should reassess older BYOD programs that remain intrusive or unnecessarily restrictive.

Finally, we examine the visibility security teams need across device configuration, patch levels, apps, permissions, identity services, web activity, and AI tools. Michael's advice is to start by understanding how people work before introducing heavier controls that may encourage workarounds and shadow IT.

Does your organization know how its mobile risk changes after a device has been issued, or are you relying on the protection it had on day one? Listen to the conversation and share your thoughts with me.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(2000)

The Swivel Chair Problem Holding Back Enterprise AI With Clio

The Swivel Chair Problem Holding Back Enterprise AI With Clio

How much of your technology stack is being held together by people swiveling between screens, copying information, and quietly compensating for systems that cannot communicate? In this episode, I spea...

23 Elo 29min

Preparing Small Businesses for Making Tax Digital With ANNA Money

Preparing Small Businesses for Making Tax Digital With ANNA Money

Could Making Tax Digital improve the way small businesses manage their finances, or will it become another administrative burden competing for an already crowded evening? In this episode, I speak with...

22 Elo 21min

Regaining Control of Enterprise Software With Origina

Regaining Control of Enterprise Software With Origina

Who really controls your enterprise technology strategy: your organization or the vendors writing its software contracts? In this episode of Tech Talks Daily, I speak with Tomás O'Leary, founder and C...

21 Elo 33min

Fixing Broken Customer Service Before Agentic AI Arrives With Parloa

Fixing Broken Customer Service Before Agentic AI Arrives With Parloa

Why are companies preparing for agent-to-agent customer service when many customers still cannot get a chatbot to answer a straightforward question? In this episode of Tech Talks Daily, I speak with L...

20 Elo 25min

Building an AI Ready Workforce Without Abandoning Entry Level Talent With Year Up United

Building an AI Ready Workforce Without Abandoning Entry Level Talent With Year Up United

What happens to tomorrow's leadership pipeline when employers automate the entry-level tasks through which beginners learn? In this episode of Tech Talks Daily, I speak with Gary Flowers, Chief Inform...

19 Elo 31min

How BlackLine Turns Finance AI Investment Into Measurable ROI

How BlackLine Turns Finance AI Investment Into Measurable ROI

How should finance leaders measure AI ROI when adoption has slowed and the cost of models, tokens and disconnected tools remains difficult to predict? In this episode of Tech Talks Daily, I welcome Je...

17 Elo 22min

Securing AI Agents at Machine Speed With C1

Securing AI Agents at Machine Speed With C1

What happens when an autonomous AI agent can complete thousands of actions before a traditional access review has even identified that something has gone wrong? In this episode of Tech Talks Daily, I ...

17 Elo 28min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
otetaan-yhdet
rss-seksicast
rss-podme-livebox
tervo-halme
rss-voi-venaja
rss-asiastudio
rss-pinnalla
et-sa-noin-voi-sanoo-esittaa
rss-vaalirankkurit-podcast
rss-kaikki-uusiksi
nakokulma-oikealta-jussi-halla-ahon-blogin-kommentaarit
rss-diet-woke
rss-mina-ukkola
rss-tyolinjalla-pekka-sauri
linda-maria