Can an app approved by Apple or Google still expose your business to security, privacy, and governance risks?
In this episode of Tech Talks Daily, I welcome back Michael Covington, Vice President of Strategy at Jamf, for a conversation about the false confidence that can surround mobile security. Apple and Android provide strong protections, including app review processes, sandboxing, and device authenticity controls. However, Michael argues that a device being secure on day one does not mean it will remain secure throughout its working life.

One of the most interesting points from our conversation is that mobile malware represents only a small part of the problem. Michael says it appears on fewer than 1% of the devices Jamf protects. The wider concerns include vulnerable third-party libraries, aging app versions, excessive permissions, unsafe web connections, compromised identities, software supply chains, and AI functionality introduced without the company fully understanding how it handles data.
Michael also shares findings from Jamf analysis of corporate applications. According to the research he discusses, 95% of the apps examined contained at least one medium or higher severity vulnerability, 10% used vulnerable third-party libraries, and 96% included AI features. For security leaders, this creates a much broader question than whether an app contains malware. They need to understand what the app can access, where it communicates, how it handles data, and whether its capabilities comply with company policy.
We discuss why familiar advice about updates, passwords, and suspicious links continues to fail when employees are busy or working from mobile devices on the front line. Michael explains how automation, clearer deadlines, and access policies can reduce risk without placing every responsibility on the user.
The conversation also covers BYOD security and employee privacy. Modern Apple and Android controls can separate business information from personal apps, allowing employers to manage the work container without inventorying an employee's private digital life. Michael believes many organizations should reassess older BYOD programs that remain intrusive or unnecessarily restrictive.
Finally, we examine the visibility security teams need across device configuration, patch levels, apps, permissions, identity services, web activity, and AI tools. Michael's advice is to start by understanding how people work before introducing heavier controls that may encourage workarounds and shadow IT.
Does your organization know how its mobile risk changes after a device has been issued, or are you relying on the protection it had on day one? Listen to the conversation and share your thoughts with me.
Useful Links

[00:00:00] Your agents aren't producing accurate answers because they don't have a complete semantic understanding of your data. And Denodo is solving this and solving it through semantic consistency. Through semantic consistency, your agents can start making accurate predictions in real time. So see what else Denodo can do by visiting denodo.com to learn more. But now let me introduce you to today's guest.
[00:00:32] Can a mobile app pass an official store review, run on a trusted phone and still remain a security risk to your business? Well, mobile platforms give us strong protection from day one. But my returning guest, Michael Covington, he argues that day one is where confidence can become complacency. Because let's be honest, updates get postponed. Permissions expand. Third-party components age.
[00:01:01] And AI features keep appearing faster than governance policies can keep up. And let's be honest, confession time. We have all hit Remind Me later on a latest update. We have the optimism of someone who genuinely believes tomorrow will be calmer. But it seldom is. But Michael is the Vice President of Strategy at Jamf.
[00:01:25] And today he's going to join us in a discussion on why mobile malware represents only one small part of the problem. Because we're going to discuss vulnerable apps, hidden AI functionality, BYOD privacy, identity controls, and the kind of visibility that security teams need without treating every employee like a suspect.
[00:01:50] So if those mobile devices now carry the working day in our pockets and our entire lives, should businesses finally protect them with the same care as every other business system? We've got a lot to get through today. So join me in welcoming Michael back to the show. So a massive warm welcome back to the show. It's, what, nearly two years since we last spoke. So can you remind everyone listening with a little about who you are and what you do?
[00:02:20] Thanks for having me back. My name is Michael Covington. I am the Vice President of Strategy for Jamf. For those of your listeners that might be new to us, we're recognized leaders in what Gartner calls endpoint management tools. So we're kind of known for our expertise in Apple and mobile ecosystems. Well, it's a pleasure to have you back on to join us. And mobile apps and operating systems, they often promote their built-in security.
[00:02:48] So I've got to ask from your side, you've probably seen it all throughout your career, but where does that protection genuinely help? And where can it create almost a false sense of safety for users and employers that are all managing so many different devices now? Yeah, this is such a great place to start. You know, I feel like mobile today really provides such a great foundation. Apple and the folks over at Google with Android, they both have really good code development practices.
[00:03:17] They follow some pretty strict processes for how they manage mobile apps that are coming in and being published through their respective stores. They've got protections that they've built into the operating systems to really restrict any apps from acting badly. You know, features like sandboxing we often talk about. And they've even started to add over the last several years capabilities that allow enterprises or organizations that are really taking these consumer devices and using them for work to assess the authenticity of these devices.
[00:03:47] And to get back to the question, you know, these devices, the operating systems they're running, they're usually great on day one. The false sense of safety, though, I think comes when people and businesses assume that these devices are remaining secure over the duration of time that they're serving function. And I suspect for many Apple users listening, many are probably guilty of having that false sense of security,
[00:04:15] especially when Apple do promote the fact that, you know, an app is only become trusted when it passes an official App Store review. But from your side, what risk can still remain through excessive permissions, compromised updates, malicious integrations or weaknesses elsewhere on the device? Because it's not as simple as, hey, Apple have passed it, it's safe now, right? It's not. And, you know, for your listeners, I'd really encourage them to think broadly
[00:04:43] when we talk about risk here as it relates to mobile apps. I think maybe a useful stat that I should provide at the top here is around mobile malware, because I think that's probably where a lot of people's minds are going when we talk about app risk here. Mobile malware is actually quite rare. I think we see it in about less than 1% of devices that we protect. But there's a lot of other risks that surround apps. You kind of alluded to a few there. Supply chains.
[00:05:11] So the components that go into mobile apps when they're being built. The way that apps handle data as they're either generating it for the user or pulling it down from the web. And recently, AI integrations. We did some analysis a little earlier this year that showed that 95% of the apps that we looked at, and these were corporate apps being used for business purposes,
[00:05:36] had at least one medium or higher severity vulnerability in the app. We found that 10% of the apps used vulnerable third-party libraries that were just not being managed. And 96% of the apps that we looked at actually contained AI features. And so as you think of all of this, the risk landscape is actually quite diverse.
[00:06:02] It's everything from vulnerabilities that these apps are introducing on top of what may be a hardened operating system. Or it's the introduction of functionality like AI that may actually violate a governance policy that the business has in place. And we've mentioned AI a couple of times there. And I'm curious, we did speak, what, two years ago. How much has changed in the last two years from your side?
[00:06:27] How is AI impacting your work, conversations you're having with your customers, etc.? AI is having a tremendous impact, as you can imagine. We're seeing a lot of businesses really embrace AI, really encourage their users to find new and creative applications for it. And we're seeing developers in particular really go wild with the embrace of AI.
[00:06:54] In fact, so wild that a lot of businesses have lost sight of what AI tools are actually being used within the organization. Now, this obviously brings with it some cost concerns, really around licensing and utilization. But it also brings concern around data that the AI agents are ultimately touching and manipulating. I think it's still very early days, as you can imagine, with AI adoption in enterprise. But I'm encouraged.
[00:07:24] I'm encouraged with where we're at, both in terms of the usage that's out there, but also some of the tooling that's starting to emerge to help businesses govern AI utilization really effectively as they start to roll this out across every different population of users. And for any business leader listening, any advice on how their company should be distinguishing between an app-level security problem, a compromised device, or even an attacker that is abusing a perfectly legitimate user account?
[00:07:55] Yeah, I think at the end of the day, when we were talking about mobile, each and every single one of these risks matter. And that's really why we advocate that organizations with mobile devices at work really try to drive a comprehensive risk assessment or score in policy. So rather than try to distill it down to just one single threat category, try to assess the device as a whole. And there's a lot of tooling out there that I think can be useful.
[00:08:25] You know, a lot of teams today have some form of device management, which is a great start because from there you get a list of the devices that are in your business. You can usually get a list of the mobile apps that are installed. You usually need some additional tools, though, if you want the threat intelligence or the risk analysis that can be layered on top of that to give the business the visibility into where the risk is and some of the controls to mitigate it.
[00:08:51] I think we could speak for an entire hour about all the different tools that are out there today. But the one thing I'd encourage businesses to really think about is how well those tools are integrated. Because as you can imagine, you don't want to treat them as silos because there's so much valuable information within each one of these areas that you really want to try to bring it together so that you can be operationally efficient as you try to do more with mobile in your organization.
[00:09:18] And as consumers and indeed employees, we are all frequently told to install updates on a regular basis. Keep use a strong authentication. Avoid clicking on those suspicious links. But I suspect we both know people who hit skip every day. They skip those updates promising they will do it tomorrow, but they never get around to it and may be guilty of clicking on some of those links that demand urgency promise FOMO if they don't.
[00:09:45] So why do these familiar messages still fall? And what form of education could better change behavior without just pointing that finger of blame at users every time? Yeah, I'm a little embarrassed. I'm raising my hand over here as being guilty. It's charged as being one of those users myself. You know, users will always be the weakest link in the chain, even those that come with the best of intentions. Users are busy. They don't always have the time to install updates.
[00:10:14] It may not be the right moment to suffer downtime when an update is presented. A lot of users nowadays with mobile, they're on the front lines. The mobile device is their only work device, and they're usually client-facing or partner-facing. They're multitasking. If you think of something like strong authentication, the way that we've done it historically is with a super long password. Typing that in on a mobile, small form factor device, it's just not always convenient.
[00:10:44] And I think businesses, they don't always consider the impact that their IT policies will have on the user experience. And in this age of AI, as we were just talking, and automation, I'm really hopeful we're going to see businesses start to take some of that burden off of their end users. Invest in workflows that can improve the mobile experience, but also improve security for the organization.
[00:11:08] So giving people a countdown timer for a number of hours or a number of days before they have to install an update. Or giving them the power of implementing one of these security tools, but perhaps restricting access to something more critical until that task is completed. There's a lot of options out there for businesses. I just think they have to think differently than the desktop world that they're probably operating in as they start to apply these policies to a mobile world.
[00:11:38] And the workplace has become more complex now. I think many people will still be carrying around two phones, one for work, one for their home life, keeping a clear divide between those two worlds. But others will be like, I just don't want to carry two devices. I'll just use my iPhone or my personal device everywhere I go, because that's got my whole life on it. And the problem is, employees then, understandably, will resist intrusive monitoring, which could spill over into their personal lives.
[00:12:06] So how can employees protect company data while also respecting personal privacy? Because the toothpaste is out of the tube. There's no going back now, is there? No, there's not. And, you know, using personally owned devices at work is such a hot topic these days. I think that AI, as well as many regional regulations, it's really pushing the concept of BYOD back to the top of the conversation pile.
[00:12:34] And I think it's important to recognize there are many ways to implement a BYOD program. The unfortunate thing is that we still see many organizations latching on to these older approaches that were either intrusive into privacy, as you just mentioned, or they were limited in the number of apps that they could support and the tools that they could expose to workers.
[00:12:57] The reality check here is that Apple and Android, the operating systems just for better part of five plus years now, have had privacy controls available that put the user in control. Effectively, without going too far into the weeds here, what these capabilities unlock is a partition or a container that sits on the device that's used exclusively for work. And only that container would be controlled.
[00:13:27] And since we've been talking about mobile app risk here, the business loses the ability in this kind of personally owned environment to assess or even inventory any of the personal apps there. So they just don't see them at all. But what they do see is what sits in that container and they have a much greater control over the work data that's allowed into that container and how it is able to flow out of it.
[00:13:54] So it's really interesting from a technology perspective to now have this functionality really baked into the hardware and the operating systems that are running on it. I think now is the time for businesses to really consider reevaluating their BYOD programs and look very closely at this new technology because it really is a game changer. If the use of personal devices at work is something that they want to explore.
[00:14:22] And for anyone listening in mobile management now for an organization, what visibility should their security teams have access, especially around that mobile estate? And which warning signs might reveal risky apps, outdated software, unusual permissions or compromised devices? Because as you said, it is a huge talking point now. And I'd love to give people listening a few actionable takeaways that are managing this stuff. Yeah, thanks for this.
[00:14:52] And, you know, I'll say that my advice for security teams, and this is probably going to come as no surprise, get as much as you can and really view mobile the same way you do the rest of your on-prem infrastructure. But you have to think about how you get that visibility differently. So when it comes to the device, you just don't want an inventory of the device. You want to know the device and all of the configuration details about it.
[00:15:20] What operating system is it running? What patch level is it currently at? What are the controls that are configured? Are third-party app stores allowed, for example, or USB debugging? All of that is really important to just understand the foundation upon which the rest of your mobility program is going to be established. We also really encourage security teams to dig into the devices themselves and the work tools. So look at the apps.
[00:15:49] Perform risk assessments on those apps and understand how they're implementing crypto. Do they have AI functionality? What websites or regions do those apps have the ability to communicate with? All that really helps you assess what it is that the user is going to be utilizing regularly. You can even dig in deeper and look at web connections with security intelligence overlays to show you when the user may have been sent a phishing or a smishing attack.
[00:16:18] When they may have attached to a web service that could have facilitated a drive-by download or forced a malicious process with the device to be implemented. And then, of course, look at the remote connections, the trusted ones and the untrusted ones, that you can understand what your users are doing. The important thing with mobile is that these devices come and go from your corporate networks. So you need to rethink the tooling that you're going to utilize to get this visibility so that you don't have gaps.
[00:16:48] You want to make sure that you understand what the device is doing at all times and that you've got the right touch points to either implement controls, policy controls on demand, or that you can start to effectively have some autonomy on the device and that the device can take action when it senses that something about its risk posture has changed. Best example here is when a user is on an airplane. They're usually in airplane mode when they're in flight, but they can often still be connected with in-flight Wi-Fi.
[00:17:17] It's really important to think through scenarios like that and make sure that you've got the full 360 visibility that's going to be essential to really make sure that these things are protected while they're doing work functions. And, of course, stronger controls can, if they're a little overzealous, introduce friction that encourages people to go out there and try and find sneaky workarounds.
[00:17:39] So how should companies balance security with usability when setting up policies for their apps, their devices, authentication and access? Because users are incredibly clever. They'll always find those workarounds and nothing winds them up more than a little friction. But how do you get around this? Yeah, you're so right about users just want to get work done. They don't want to walk into the blocks. And so I think the key principle here is transparency.
[00:18:08] We really think that policy transparency is key to effective and successful mobile programs. You know, on mobile, we used to see such an extreme approach taken with work devices. Many businesses locked them down. They effectively made them operate like they were kiosks, where just one app would launch on these devices. We really don't see that anymore. And I'm encouraged by that.
[00:18:34] I think that businesses realized that if workers couldn't get things done, they either took that route of trying to find the workaround or worse, they would just put the device in a drawer and they would go find another device that would let them do what it was that was important to them. That's where the business had a loss of investment with these devices that were just sitting in drawers. And then you really had the shadow IT that was taking foot because you didn't know what devices were coming in.
[00:19:03] So I have seen a loosening of the controls, which I think is a really good sign. But for those that are starting new, I really encourage them start with the data. Don't start with heavy controls. You know, Neil, just a minute ago, you asked me about visibility that we encourage security teams to have. And that's the anchor point for everything when it comes to mobile visibility gives you your baseline.
[00:19:27] It gives you a starting point for policy, because with the insights on what your users are doing, what they're trying to do, what they need to access for work. That's where you can start to really assess where you might need to put some guardrails in place and help protect the user from the types of things that they may trip up on on a daily basis. So lighten the load and just get more insights is really the best place to start.
[00:19:54] And I think one of the other things we've seen over the last two to three years is the pace of unprecedented change just continues to ramp up. Everything we took for granted as the best way of doing things is not always the answer now. So if a business suspects that it has maybe placed too much confidence in default mobile protections that always work fine, what should it begin to assess first across app permissions, patching, device management, identity controls, employee?
[00:20:23] It's such a long list, isn't it? It really is. And, you know, I think what's encouraging is that the tooling is starting to merge. So we are starting to see more and more functionality come together from vendors that offer really a one-stop shop to do a lot of the things that are needed here in mobile. But I think you hit the nail on the head in that you really shouldn't be putting too much confidence in those default settings.
[00:20:52] Don't let mobile in the door and then assume that it stays secure for the duration of time that it is serving a business function. You know, we've talked a little bit about device management here today. That's obviously a really important starting point. Whether you're fully corporate-owned devices or if you have some BYOD in the fleet as well, it's foundational. It's essential to really get the rest of the data that you need to assess the risks that are out there.
[00:21:19] The app inventories with the risk assessments can tell you everything from old versions that are installed that might be giving your users some headaches from a usability perspective to causing your security teams to stay up at night because of the exposed vulnerabilities that they are introducing to the device.
[00:21:37] And then all of the visibility that surrounds what the device does when it's online, the web connections, the applications that are being accessed, the core IT services like identity that these devices are pinging up against on an all-too-regular basis.
[00:21:54] I think all of that is really where businesses can start to rein in some of the risks that mobile is introducing and really make sure that they can allow mobile to do more because mobile really has become mission critical for many businesses out there. It's time that they treat it like a first-class device and start to put the right set of controls on it so that they can move forward and really embrace it even more.
[00:22:23] And outside of mobile, another big change I've seen since we last spoke was that offices used to run almost entirely on Windows machines and then Chromebooks came in for more basic needs. And then this year, the MacBook Neo dropped its price, entered the market at an incredibly attractive price, promising to change that assumption around the cheapest laptops.
[00:22:48] Elsewhere in organizations, there are Mac minis using clawed code, clawed desktop, open AI codecs, et cetera. And one of the reasons I wanted to bring this up was I noticed, I think it was last month or the month before, that Jamf launched an AI governance solution for Mac fleets in enterprises. Tell me more about that and the thinking behind that. Was that responding to market pressure? And what are you doing here? Wow. Wow. It's so much in there.
[00:23:15] But yeah, I think that Apple has an incredible product portfolio right now. Really so many different entry points for consumers and businesses alike to get into the right device, the right form factor, the right set of capabilities for their needs.
[00:23:32] You know, some workers have really basic needs where a lot of what they're doing is some basic productivity apps, accessing a lot of SaaS applications and AI tooling through a browser. Other users have much more robust requirements where they're going to be doing a lot of local processing, maybe doing some development, utilizing local AI agents.
[00:23:56] And what we found was that many of our customers, as they have this really diverse set of Macs that are in use within their organizations across different populations of users, they were losing visibility into what AI tooling was in place. And they absolutely did not have the appropriate controls to make sure that their users were utilizing this new functionality in a way that was aligned with the corporate policy.
[00:24:26] And so we introduced some functionality that provides visibility into AI tooling across the entire estate and some pretty detailed controls for how that AI is really brought to life on each individual device by user or by user group. Some pretty exciting times. And this was really based on customer feedback.
[00:24:51] So really the Mac teams that were feeling like they didn't know enough, they came to us and said, how can we use some of the existing tooling that we have with Jamf to get some of this insight? And I'm pleased that the team was able to turn it around so quickly. And I think I'm right in saying this, that Jamf is one of the only solutions that make it easy for teams to manage and secure Apple at scale. And I also think it's the only Apple first platform that unifies management, security, and identity.
[00:25:21] So for anyone listening, maybe we've set off a few reliable moments today. Where can they find out more information and learn more about what you're doing here and future announcements too? Yeah, thanks for that. Jamf.com, J-A-M-F.com is the place to go for more information. You can find lots of assets and resources hanging off of the website and get in touch with the team if you'd like to see more. Excellent.
[00:25:45] Well, we covered a lot today around how users and teams must be educated on the risks associated with mobile app usage, including the potential for app or direct device level compromise too. So many big talking points. I'd be interested in hearing from anybody listening in any organization how you're managing mobiles and Macs and everything in between. But as always, thank you for bringing all this to life today. Thanks for having me.
[00:26:13] I think Michael's message gives businesses a useful starting point. A trusted platform, an approved app, or secure configuration can all help provide strong foundations. But protection against changes as apps, permissions, libraries, identities, and user behavior evolves.
[00:26:34] These are all things that need looking at too because security teams need visibility rather than confidence than are just inherited from the day that the device was first configured. And I love Michael's advice there to begin with the data instead of reaching immediately for heavier restrictions. Employees don't like friction. They just want to finish their work. And when security creates too much friction, people can become remarkably inventive.
[00:27:03] And sadly, their unofficial workaround rarely appears in the company risk register. So better mobile security means understanding the complete device, explaining the policies more clearly, protecting work data on personal phones, and using maybe even automation to reduce the burden that is placed on users. So a massive thank you to Michael for not only returning to the podcast, but sharing his perspective.
[00:27:32] And remember, you can learn more about his work and find other resources over at jamf.com. But having listened to all that, how confident are you that trusted apps across your business will remain trustworthy today? And how many times have you hit skip, update, or remind me later? TechTalksNetwork.com, that's where you'll find me. Other than that, I'll be back again real soon with another guest. Speak to you then. Bye for now.
[00:28:01] Bye for now. Bye for now. Bye for now.

