Transcript
Today we are going to talk about a topic that concerns us all since our smartphones have become our constant companions. They are both our work tool, our wallet, our photo album, even sometimes our passport. And all this makes it a prime target for cyber attackers. Today's topic is how to better understand the mobile attack surface to effectively strengthen it through the complementarity of mobile device management and mobile threat defense. Two components that separately are already very powerful but together create a much stronger defense. So today on the agenda we will first give a brief overview of the threat landscape. We will then present what an MTD solution is, the differentiating factor of the MTD solution that Ivanti offers, some demonstrations and then a question and answer session. Feel free to ask all your questions in the chat right now and my accomplice off stage will give me cues when there are questions from you to make the presentation more interactive. Let's go, we will start by presenting a little bit the threat landscape. So we will begin here by looking at this graph which actually illustrates very clearly the major transformation of our digital usage. If we go back to the origins of this graph around the year 2009, the overwhelming majority of connections were still made from a computer. Then around 2016-2017 we observe a first historical turning point. For the first time mobile catches up with desktop and becomes its equal. This shift could be explained for example by the maturity of smartphones, the emergence of 4G, the explosion of social networks and the massive shift to mobile first. Then the second break we can observe which is visible here is at the end of 2020, beginning of 2021, the mobile takes a decisive lead. This acceleration here coincides with the COVID pandemic where our habits have profoundly transformed. And so today the mobile has established itself as the main screen which explains why protection against mobile threats has become a priority issue. Why is it essential? Well when we look at these numbers we immediately understand 80% of users authenticate from their smartphone and 70% use mobile messaging daily. As a result nearly 60% of global internet traffic goes through mobile and inevitably cyber criminals adapt. More than 80% of phishing attacks are now optimized for mobile. On the vulnerability side 80% of zero-day exploits target iOS and on the Android side we have seen an increase of more than 138% in critical vulnerabilities. In summary mobile has become both the central tool of our digital usage and the primary target for attackers. So you have surely noticed hackers are increasingly interested in our mobile devices but why? Well simply because our smartphones and tablets are everywhere so they give us access to almost everything, our emails, our files, our cloud spaces and to connect to these applications it's as simple as downloading an app from the store. In the end in many companies mobile devices clearly represent a weak link today and yet most of us do not realize the risks. We connect to public Wi-Fi, we leave Bluetooth on, we connect to unsecured or malicious networks that can allow an attacker to monitor or capture our sensitive information. We can also potentially install applications that seem harmless at first glance but that allow remote access to data. A simple download without knowing it, our device can be monitored, remotely controlled or our data can leak. So for the web this is where we will have everything related to social engineering so it will be the entry point to steal personal or professional information and then it's also the opportunity for some users to visit disreputable sites. And of course not forgetting the operating system which among us for example today thinks about constantly checking that the OS is up to date, that it is still upgradable, that it is not a version containing vulnerabilities etc. And there you have it, it's through all these entry points that hackers can find a point, an entry door through all these points due to unpatched vulnerabilities or user behavior errors. Very briefly as a reminder and you all already know this, in our smartphones we have a joyful mix, professional emails alongside personal photos, stored bank cards, health data and so on. In short it's both our office, our safe and our private life all in one pocket. So why are mobile devices more vulnerable? First because we mix personal and professional uses on the same device so attackers can take advantage of this expanded attack surface to access sensitive data through poorly secured applications, for example, but not only that. Then because many applications ask for too many permissions. A malicious application with the right permissions can spy on the user, intercept communications or record keystrokes and also because on mobile phishing attacks are harder to spot. Users will more easily click on malicious links in SMS or in their messaging application. Then we can mention connections to unsecured public Wi-Fi networks. Smartphones are designed to automatically reconnect to a known Wi-Fi network. For example, if on the train I have connected to the SNCF network once in my life, the smartphone records this SSID as you all know, as soon as it is again near a network with the exact same name, it could potentially reconnect automatically. Except that anyone can impersonate the Wi-Fi network of the SNCF or Starbucks. It's very easy to impersonate. And so having a smartphone that connects somewhere to a network that ultimately is not what it claims to be and or is not secure. Then we can also mention the low visibility for IT teams. Unlike PCs, smartphones are rarely integrated into the company's networks, the CIM and EDR, etc. Companies therefore have little visibility on the security status of these devices, especially when in a bring your own device strategy. Finally, it's important to remember that we are dealing with a completely different user experience and ergonomics since we are on a small screen. So on mobile, the user often acts in the moment, the push notification, quick multitasking, the one gesture response. These are automatisms that we have integrated into daily life. And it's a reactivity that has become almost automatic, leaving less room for analysis or doubt. And then on a small screen, there may be fewer potential visual cues for decision making. The URL can be truncated, links may not be hovered over, attachments or buttons may seem normal. The responsive design of emails, applications that can sometimes hide certain elements that would have been more easily identifiable on a PC. A brief recent overview of a mobile threat map in France from May of this year, where we can observe the types of threats that have been recorded by the solution of protection against mobile threats that we offer. And so we can obviously see here a rather significant concentration in the main areas, which are Paris, Bordeaux, Lyon, etc. But it also provides visibility on the type of attack that we have identified in recent months. Do we have any questions in the chat? Apparently not. So I'll continue. Feel free to ask your questions. So we have a report by Malwarebytes Labs revealing a dramatic surge in malware on Android with an increase of 151% in just six months, making it a prime target for cyber criminals. Android Sorry, which obviously dominates the global market with more than 70% of the share, is undergoing a wave of increasingly sophisticated attacks. There are spyware programs capable of stealing contacts, messages and geolocations, which have surged in recent months. Meanwhile, malware is also multiplying through fraudulent SMS, which has increased by 692%. And on top of that, what really doesn't help is that attackers now rely heavily on artificial intelligence to better deceive users. So it's a bit of a race. The contribution of AI lately has really made these attacks even more credible. And so this peak of malicious activity reached its height between February and March, reaching up to four times the initial level of malware detected at the beginning of the year. Cyber criminals had exploited attacks related to taxes, fake tools. They will deploy links, fraudulent applications that pretend to be official services. So here we have a link. You will be able to access the presentation at the end of this webinar where I invite you to visit. Additionally, there is one last point I want to mention, which is that the fragmentation of the Android ecosystem worsens the situation. More than 30% of devices remain stuck on outdated versions without security patches. If we continue to dig a little into current events, there was a zero-click vulnerability that was fixed by WhatsApp at the end of August 2025. So it's very, very recent. It is common to think that we risk being hacked by clicking on a suspicious link or installing a dubious application. And it's true that it's often the case, but we must also take into account that the situation has evolved and that there are also what are called zero-click attacks, which, as their name suggests, require no interaction from the end user. No need to click, open an attachment, or read a message. And sometimes it's a notification or a stealthy message that will be enough to exploit an unknown flaw. And so that's what happened recently with WhatsApp on iPhone and Mac, if I remember correctly, where a vulnerability allowed attackers to install spyware remotely without the victims being able to notice anything. So here, it's a targeted attack. Fewer than 200 people were targeted, but it remains a significant incident because it shows that a phone can be infected without its owner interacting in any way. Still in the news, we have a confirmed espionage incident by Citizen Labs. Several journalists were targeted by the spyware Predator, which was designed by the company Paragon Solutions, despite the fact that the iPhones in question were perfectly up-to-date with the operating system. So it is a very thorough public study. I invite you once again to also check the link I am sharing here. But what we can note here is the international environment is marked by a rise in digital surveillance, mainly orchestrated by governments or entities. So journalists are increasingly exposed to these threats, even when using devices considered secure. To conclude, a few additional statistics. In the first quarter of 2025, one million phishing attacks were recorded. Attacks via mobile banking trojans are four times more numerous. Phishing targeting mobiles accounts for one third of all identified threats, and 61% of companies have already experienced mobile fraud. Here, I tried to provide different sources. There you go. So I included the link each time. I would eventually invite you to consult them if you want to delve deeper into the subject. To conclude this first chapter on the attack surface, very quickly, antivirus was generalized on PCs in 1987. The question that remains relevant is, when will we finally generalize mobile security? Considering all these elements that show cyber attackers only target smartphones and tablets. So this is where protection against mobile threats comes into play. So here it's about protecting on four vectors, both at the device level, to verify that the device is not jailbroken, rooted, that there is no exploit at the operating system level, major vulnerabilities, privilege escalation, ensuring that the OS is unaltered. On the network side, as we saw a little earlier, ensure that when a user connects to the Wi-Fi network, whether in a train station, a cafe, or elsewhere, they are not dealing with an unsecured network, or worse, that they do not encounter a man-in-the-middle attack, of which I will give you a demonstration later. On the application side, we can monitor and protect any application. It's true that Google and Apple do a very good job. They already do this work upstream by scanning all the applications that enter their respective stores. But from time to time, an application slips through the verification nets of the stores. We still see quite a few examples of this in the press. And then it's even more true for applications that would be loaded locally or come from third-party stores. Finally, it also involves protection against phishing, whether through SMS, malicious links, WhatsApp messages, or even by scanning a QR code. Because when you scan a QR code, you have no way of knowing where that URL will point. So there you go. In addition to all that, we can also mention web filtering, which I will talk about in a little more detail later. To summarize, what can we reasonably expect in terms of mechanism capacity when talking about mobile threat protection solutions? Well, obviously, there is threat detection. The idea is to be able to quickly identify if a mobile device is compromised, exposed, or targeted by an attack. Then a major issue not to forget is user privacy. It's a key point, meaning we will protect the employee without monitoring their activity or collecting their personal data. The balance between security and privacy is a truly essential point in this type of solution. Then there is also the network protection I just mentioned to ensure that mobile connections are secure, whether it's a public Wi-Fi, an unknown hotspot, or something else. Another important aspect will be protection against phishing, which I have already mentioned. The evaluation of application risk or app vetting, which I will talk about right after in the next slide. So I analyze it. I won't elaborate on it. But basically, it involves analyzing the applications that are already installed and alerting if an application does not comply with the company's policy. The evaluation of vulnerabilities, so checking that the device is up to date, that it does not have any flaws, et cetera, et cetera. When a threat is detected, corrective measures must be implemented. It could be quarantining an application, temporarily blocking access, et cetera, et cetera. If the attack is confirmed, it is necessary to move to incident response by integrating with company processes, possibly to alert, isolate, or help limit the impact. There is also the issue of compliance monitoring. This involves ensuring that each device adheres to the security rules defined by the company, for example, encryption, lock code, et cetera, et cetera. And finally, a good MTD solution must be able to offer integration capabilities, for example, with components like a CRM. In summary, an effective MTD solution is a coherent set that combines detection, protection, remediation, and integration while respecting user privacy. So I was just talking about app vetting, which is an advanced module that will allow analyzing applications to ensure they do not have risky behaviors or vulnerabilities. The goal is also to be able to define your own custom filters according to your company's security rules and thus filter applications based on various characteristics. Here, I have included examples in a screenshot. And to say, for example, within my organization, I prohibit all applications that use chat GPT, that communicate with a server in Pakistan, that access my SMS, et cetera, et cetera. And to be able to create filters like that, customized to determine if an application meets those criteria, I define it as non-compliant and I don't want it. There you go. So here, we go a bit further in a proactive approach. We will really ensure beforehand that the applications we deploy on the fleet are compatible with those rules and characteristics we have determined. And so often when we talk about protection against mobile threats, clients tell us, but I already have an MDM. And it's true that the MDM is very important because it allows companies to define policies, apply them and enforce them. And it's also the one that has the most important rights on the equipment, on the device. It will offer capabilities to remove applications, block, lock, which are very complementary with an MTD solution because the MTD, it does not allow for applying policy management, et cetera. But it is very strong in actively detecting threats, diagnosing vulnerabilities and then handing over to the mobile device management so that it can go further, notably quarantining professional applications because it has been identified that the severity is too significant, the device is too compromised and so on. So it's really the two solutions that work and function together rather than seeing them as opposing solutions. It's really very complementary. I'm listening, I'm listening. We apparently have three questions. So the first question concerns corrective measures. Can these be remedied automatically or manually by the user? That's a very good question. So the way it is planned to work ideally is to be able to carry them out automatically. The goal being not to place the burden of knowing what to do on the end user. However, it can be relevant to properly alert and warn them. To contribute, I would say to the learning and popularization of end users in everything related to security topics, it can still be very relevant for them to know exactly what is happening. It's something to define. Do we want to give too much information? It can be anxiety-inducing. The user might feel a bit powerless or just the bare minimum to help educate and raise awareness about security issues. But the goal of the solution is still to move towards automating remediation and the actions proposed by the solution. We have other questions. What is the increase in risks on iOS compared to Android? Well, that's a matter of sectarian debate that I'm not sure I want to get into. More seriously, both operating systems are vulnerable. For a long time, it was thought to be more secure than Android, etc. In fact, even more so, especially if we also consider the specificity of what we call iOS shortcuts on iOS, etc., which is an additional attack surface that doesn't exist on Android. In reality, both are equally targeted. Sometimes there are very powerful attacks on iOS, sometimes on Android. There you go. I won't go further. I don't have the exact day-to-day figure that says which of the two platforms is the most vulnerable. Third question. So, repeat it. I will repeat it out loud at the same time as you. The separation of professional and personal uses on devices. A very uncomfortable use for users. Would you have a solution to make this easier? Well, right now, without a solution, without discussing the specific cases in detail, I wouldn't necessarily have a solution pulled out of my magic hat that would require understanding what is uncomfortable for end users. Is there a need to relax certain data leak protection rules to enhance comfort or not, depending on the stakes? And where do we set the balance between freedom of use and security? It's a rather fine balance to determine. It might be worth discussing together, contacting us, so we can talk more in detail about your personalized use cases. So, great question. Thank you, Pascal. So, I'll continue. Well, to summarize a general overview of the added value of MTD. So, it's an integrated solution that can be deployed for iOS and Android users. There is no action required to deploy or activate the client. I will come back to this shortly. The MTD will detect known and unknown attacks on the device, such as network attacks and application attacks, using machine learning algorithms. It also offers protection against phishing attacks through its advanced application analysis engine. The MTD will allow for the analysis of privacy and security risks that could significantly impact the organization. And then the MTD can neutralize threats on devices, even if they are not connected to Wi-Fi or a cellular network, because we integrate local actions, which I will talk about right after. And finally, we have a console and dashboards that will allow you to manage and be informed in real time about what is happening in terms of security on your fleet. So, what are the differentiating factors of the MTD solution offered by Ivanti? If you are already a customer of our MDM solutions, in fact, it is already present. This module is already there, installed from day one. It is just dormant on your devices. And we made the effort to integrate it directly into our agent. This means that to activate it remotely, it requires no action from the end user. They don't need to open anything, accept anything, etc. We push an activation key, and automatically the mobile threat protection is activated. It goes from off to on. We are in a true zero-touch activation. Unlike other solutions on the market, where at some point you still have to open an application or approve a permission, the feedback we get from our clients who rely on this kind of non-integrated solution between the MDM and Ivanti and the MTD can sometimes only reach up to 40 or 50% activation of their fleet, which is not great for a security tool. So, we obviously aim for 100% adoption. The second really differentiating point of the solution is that we have embedded part of the mechanism locally on the device. Under normal circumstances, a scan will be performed on the device, as we can see on the left side of the image here. Then, all the intelligence will be transferred to the cloud or server to perform detection, inform, and send instructions so that the threat can be remedied locally. At Ivanti, we have integrated local actions that allow for protection in a reduced time, since there isn't always this dialogue happening in the cloud, to be able to scan, recognize, and remedy directly locally. This means that even if the equipment goes offline, and let's be clear, a smart and clever attacker, the first thing they will do is cut you off from potentially accessible intelligence outside. Well, you will still be able to benefit from threat protection that will be available even in offline mode. So, let's move on to the demos. Here, I have prepared and prerecorded a small demonstration video of hacking on an Android smartphone. In terms of equipment, I didn't need much, a dongle on my computer, and I set up a Kali Linux with all the appropriate hacking tools. And the goal is to present this to you right away. So, here on the right, I have a user who is going to log into their Outlook email. On the left, I have my hacking console, and we see that here, in fact, I have redirected the user without them knowing. They have been redirected to my server. But for the end user, it's the Outlook login page. It's Office. Everything looks official. They enter their login and password, unless he notices the URL at the top, which is slightly different. But a smart attacker will take a domain name that is very similar. And there, you can already see on the left that I have hacked his username and password. He doesn't know it. For him, everything went well. Look, he is redirected to the right to his mailbox. So, he went to Outlook, he logged in, he has access to his emails. For him, everything is fine. On the left, you can see that, in fact, I have stolen his session cookie. And so, this session cookie, I will copy it. I will go to my computer on Outlook. With a small cookie editing tool, I will just paste what I have stolen. I will refresh the page. And I entered the mailbox of the person I attacked. I hacked their account and session. So, briefly, what happened? A user who connects to the Wi-Fi goes on Outlook, logs in, checks, verifies their emails. For them, everything went well. Meanwhile, there is an attacker who connects to the same Wi-Fi network and specifically targets this user. And that's where the man-in-the-middle attack comes into play, meaning the user thought they were going to the official Outlook server. But, in fact, they are redirected to me with a portal that looks like two pieces in a pod to the official portal and which allows me behind the scenes with techniques such as ARP poisoning, DNS spoofing, and I won't go into more technical detail than that, but which will allow me to redirect the user to my captive portal to be able to retrieve, steal their credentials, and access their email inbox. So, that's an example of a man-in-the-middle attack. There are many other types of attacks, but the goal was to illustrate a bit to better understand what a network attack might look like. Now, if the mobile is equipped with MTD protection, what will the exact same attack look like? So, be careful. I warn you, it's quick. The user goes on Outlook. They tell him, oh, no, no, no, your network there is not secure. There you go. The attack couldn't take place. We cut it off at the pass. It's over. Here's an example of a user experience where someone tries to visit a site and undergoes a man-in-the-middle attack. So, obviously, all this will then be reported in the console with what we call forensics, which will allow for a better understanding of the exact context in which this attack took place, the site the person possibly visited, what networks were surrounding, were around the mobile or smartphone at the time of the attack, et cetera, et cetera. All information that will allow security teams to better understand the context and details of the attack. So, here, it's a man-in-the-middle attack, but it will be the same for all types of attacks. For your information, I don't have the exact number in mind, but we are dealing with more than 100 different types of threats that are configurable in the mobile threat protection solution. There, I showed you only one. And then, to illustrate my point on how easy it is with Ivanti to activate MTD with one click, you see on the right, I have devices managed by Ivanti, Ivanti MDM. I push the activation and configuration of MTD on the devices. I force synchronization if needed. And in the seconds that follow on the devices on the right, we see here the MTD module that has been activated. So, we really see how the activation is done with zero clicks in a truly automatic way, which is really one of the main strengths of our Ivanti solution. We are reaching the end of the presentation. I hope I wasn't too fast. I will give you more time and space to ask me any questions you wish. This is your moment to interact, so I'm listening. Yes, we have a question. So, at Ivanti, we have, when we establish a proof of concept, oh, sorry, excuse me, that's right, I need to repeat the question. This level of granularity in mobile protection requires expertise on the solution that is really available internally. What solution? Here is the question, and so it's a very relevant question. Indeed, not everyone necessarily has expertise in protection against mobile threats. So, initially, I want to say the solution is well designed in the sense that it gives you a criticality indicator. On the console, you will have the ability to know what is critical or less important in terms of the type of attack. So, it already gives you an indication of what absolutely needs to be activated as priority number one, number two, etc. Alongside this, I would say that it can also be relevant to be supported by experts in protection and cyber security whose job is to ensure frequently to the uses and their evolution and perhaps during the initial setup of mobile threat protection to seek some advice to optimize the initial configuration of the solution as best as possible. So, I see the other questions appearing. There are quite a few actually. It's great. It's awesome. You're participating really well. So, I have a small question regarding security. Is it possible with MobileIron to enforce a code during reset to prevent resets initiated by the user themselves? So, we're a bit off topic compared to the topic of the day. I might save it for the end. Otherwise, feel free to contact us for any specific questions about our MDM solution. Then, thank you sincerely for your intervention of very high quality, clear, simplified, concrete, real life. Thank you. Could we get a replay? Yes, there will be a replay and the subtitles. So, there will be the replay and then I think there will also be the link. We will send you the presentation without the videos, but you will receive all that. Are there any other questions? I think I answered that one. We're good. Ah, in SaaS mode or on-premise? Well, the answer is both. We offer the same solution in both SaaS and on-premise. So, I also see another question that just appeared, several. Oh dear. So, is the MTD integrated with Ivanti MDM requiring an additional license? Yes, absolutely. It requires an additional license. It is active but dormant and an activation key needs to be pushed to activate it. There are two license models. The standard model and the plus model. With the plus model, including everything presented on the app waiting part, but much more. Does the solution allow the IT department to analyze all the threats repelled by the solution and all the attacks suffered? Yes, indeed. You have a dashboard on the one hand that lists all the attacks that have occurred on your fleet. So, it already serves as a fairly detailed report and allows for tracking of threats that have been resolved, unresolved, etc. To be able to differentiate between attacks that occurred at the operating system level, at the network level, or rather as malware type, etc. I hope that answers your question. Hello, Elise. Thank you for the webinar. Like any user, the more we protect, the less comfort the user has to work. Systematic alerts, it even happens to admins to temporarily disable the EDR to work. Yes, my question is, what are the ways to alleviate this at Ivanti? The user has advanced access or an immediate request. Should we wait? Should we wait? Okay, then. Overall, how does it work when there is a threat occurring at a given moment on the mobile? The Ivanti agent puts a small system notification at the top that is not intrusive at all, which allows the user to be informed if they wish. They can open it, click on it, and get a bit more detail about that notification. And we could very well leave it like that in monitoring mode initially to evaluate the impact on end users a little so they are not too disturbed at first and then gradually increase and cut off certain accesses that we have identified by distinguishing between what is a real attack and what is not really an attack or is less serious and therefore to be able to automate certain actions afterward that will be considered a bit more intrusive. I am thinking, for example, of a user who connects to an unsecured Wi-Fi network. Initially, we could just warn them. It helps to educate and raise their awareness. Then in the second phase, we could very well say that as soon as you are connected to a malicious Wi-Fi network, I cut off your Wi-Fi access. So there, it might be a bit more relevant for the end user who suddenly finds themselves cut off, disconnected from the network. They might not necessarily understand, but the whole challenge is also to communicate well, to properly support the end users and ultimately, above all, to better inform them daily of each action that is taken and that could potentially represent a danger. It's also important for them to be aware because we can only protect when we've learned the right actions and proper hygiene. I hope that answers the question. Apparently, yes. Does the Ivanti console offer a feature to prevent the agent from being deleted or to alert? So I will assume the question is about preventing the removal of mobile threat protection. If that's not the case, please clarify the question in the chat, but I'll go with that and answer accordingly. So yes, absolutely. Perfect. So yes, indeed, the end user has no choice. They cannot disable the mobile threat protection. I would even go further. We even have a process. This will relate to another question from another user earlier, which was, it's not easy. Double containerization for personal and professional, etc. We even have a mechanism that detects if one of the two containers is not secure. Well, we will punish the user in a way by saying, listen, you haven't done your job well. You haven't secured both containers properly. So I will remove your access. I will remove your access to your professional applications until you fix it. So the goal is not to leave the final user with a choice. And unlike those applications that are not integrated, unlike the Ivanti solution, at some point, the user always has the choice to disable, not open, not allow. Here, they have no choice. We don't give them a choice. We activate it remotely for them and they can't do anything about it. Do we have any other questions? I don't think so. If you still have a few last questions, I'll take them. Don't hesitate. Now is the time. If there are no more, we can stop here for today. You offer a coffee to the customer here. I would like that with pleasure. There you go. Do not hesitate to contact us or your respective account managers if you want to engage in a deeper discussion. Note that thank you. Note that we are also launching test campaigns for MTD solutions where we support you for 30 days currently at the moment. Well, I thank you all for your presence and especially for your involvement and your many interesting and relevant questions. Thank you very much. And then I wish you an excellent day.