{"version":1,"type":"rich","provider_name":"Libsyn","provider_url":"https:\/\/www.libsyn.com","height":90,"width":600,"title":"When Trusted Mobile Apps Become a Security Risk With Jamf","description":"Can an app approved by Apple or Google still expose your business to security, privacy, and governance risks? In this episode of Tech Talks Daily, I welcome back Michael Covington, Vice President of Strategy at Jamf, for a conversation about the false confidence that can surround mobile security. Apple and Android provide strong protections, including app review processes, sandboxing, and device authenticity controls. However, Michael argues that a device being secure on day one does not mean it will remain secure throughout its working life. One of the most interesting points from our conversation is that mobile malware represents only a small part of the problem. Michael says it appears on fewer than 1% of the devices Jamf protects. The wider concerns include vulnerable third-party libraries, aging app versions, excessive permissions, unsafe web connections, compromised identities, software supply chains, and AI functionality introduced without the company fully understanding how it handles data. Michael also shares findings from Jamf analysis of corporate applications. According to the research he discusses, 95% of the apps examined contained at least one medium or higher severity vulnerability, 10% used vulnerable third-party libraries, and 96% included AI features. For security leaders, this creates a much broader question than whether an app contains malware. They need to understand what the app can access, where it communicates, how it handles data, and whether its capabilities comply with company policy. We discuss why familiar advice about updates, passwords, and suspicious links continues to fail when employees are busy or working from mobile devices on the front line. Michael explains how automation, clearer deadlines, and access policies can reduce risk without placing every responsibility on the user. The conversation also covers BYOD security and employee privacy. Modern Apple and Android controls can separate business information from personal apps, allowing employers to manage the work container without inventorying an employee\u2019s private digital life. Michael believes many organizations should reassess older BYOD programs that remain intrusive or unnecessarily restrictive. Finally, we examine the visibility security teams need across device configuration, patch levels, apps, permissions, identity services, web activity, and AI tools. Michael\u2019s advice is to start by understanding how people work before introducing heavier controls that may encourage workarounds and shadow IT. Does your organization know how its mobile risk changes after a device has been issued, or are you relying on the protection it had on day one? Listen to the conversation and share your thoughts with me. ","author_name":"Tech Talks Daily","author_url":"https:\/\/techtalksnetwork.com\/","html":"<iframe title=\"Libsyn Player\" style=\"border: none\" src=\"\/\/html5-player.libsyn.com\/embed\/episode\/id\/42387065\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/88AA3C\/\" height=\"90\" width=\"600\" scrolling=\"no\"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen><\/iframe>","thumbnail_url":"https:\/\/assets.libsyn.com\/secure\/item\/42387065"}