“Mobile communication is an overlooked part of cybersecurity”: why the phone is the weak spot in security policy

"Mobile communication is an overlooked part of cybersecurity": why the phone is the weak spot in security policy cover

Most organisations that work with sensitive information have their cybersecurity in reasonable order. There is a policy, there is a CISO, and there are tools to enforce both. Yet one part of the picture tends to get far less attention than it deserves: the phone in every employee's pocket. According to Erwin Tielman, Senior Business Development Manager at Sentyron, that is exactly where a lot of risk quietly accumulates.

A policy, but not a focus

On paper, mobile devices are usually covered. Erwin explains: "Organisations do have a policy for mobile communication. They often hand out a work phone, and there's usually some form of MDM on it. The problem lies in what happens on that device day to day, where consumer apps such as WhatsApp and Telegram are routinely used for work conversations. The threshold is low, because we all use these apps privately as well. That means quite a lot of confidential information ends up being shared in them."

Mobile security also struggles to get a place on the agenda. "Everyone understands cybersecurity. There's a policy for it and there's a CISO for it," Erwin says. "But mobile communication is an overlooked part of it, even though there's a lot of risk involved." Part of the explanation, he believes, is that organisations simply haven't asked the question. "In the Netherlands we're increasingly critical of anything American, yet much of our IT runs on Microsoft. The MDM follows suit, because it's easy and it integrates. You have to ask yourself whether you really want that. Honestly, I think it's partly a matter of unawareness."

Your phone is an endpoint

That unawareness is striking, given how much runs through a smartphone today. The same device is used for email, Teams, MFA, CRM, SharePoint and VPN, and just as easily for Spotify, TikTok and Instagram. "A smartphone today is really an endpoint. It's effectively a small computer with access to the corporate environment, with applications running on the device 24/7." The Dutch National Cyber Security Centre (NCSC) also advises organisations with many smartphones to use MDM, and warns specifically about insufficient visibility into apps that can access contacts, location, microphone, camera and storage.

Erwin sees two main risks when mobile isn't properly addressed. "The biggest risk is that if an incident occurs, you don't know how it happened, because you never thought about the risks or the follow-up actions you could take. The second is control. You have no control over what happens on the device, and I think that's even more important. The same phone is used privately at the weekend too."

Not for everyone, but essential for some

Erwin is clear that high-assurance mobile solutions are not meant for every organisation. "We're not trying to compete with Samsung or the iPhone, those are for the masses. It's about zooming in: when you want more control over what an employee does, which apps are on the device and how data is shared securely." For organisations that work with the government or defence, or in critical infrastructure such as hospitals and water authorities, the question is different. "Do we keep communicating at that level with our current policy and tools? Or do we scale up to something more secure that meets the strict requirements of the parties we work with?"

For a growing group of organisations, that question is no longer optional. Since 1 January 2026, the ABRO (General Security Requirements for Central Government Contracts) applies to government contracts that involve risks to national security. It is explicit about mobile: devices that process information requiring protection may only use connections approved by the NBIV, the national industrial security bureau run by the AIVD and MIVD, and device management is treated as part of the security architecture rather than as an ordinary office application. The ABRO also looks at the origin of security solutions, which raises questions about where an MDM platform comes from, where its infrastructure is located and who has access to keys and data.

"The question that needs to be asked is: is our MDM suitable for the new ABRO rules, and are we confident that classified information can be shared on it? Many organisations are caught off guard. Organisations that suddenly start working more with defence or the government, often as a result of their own success, are overwhelmed by the ABRO. The large consultancies don't help SMEs with this, so they're really searching for answers."

Start with asking the right questions

So where should a CISO begin? The useful conversation starts with concrete scenarios. "What if the government comes to your organisation with new requirements for secure communication? Do you roll that out to everyone, or only to the group that works with that client?" And looking further ahead: "How do you want to secure mobile communication in three to five years, when ordinary smartphones, consumer messaging and foreign cloud platforms no longer meet the assurance requirements of the Dutch government?"

Above all, it comes down to awareness. "Sometimes you should think: maybe this conversation shouldn't happen through this tool. I don't want to be paranoid, but that awareness is something organisations need to build." In the end, he says, it's about the underlying questions. "What is your policy? What is an employee allowed to do, and what not? And how far do you trust American providers?"

Want to explore this further? Join Sentyron's webinar "What if your phone is the leak?" on Thursday 15 October, 10:00-10:45. Register here: https://sentyron.com/webinar-what-if-your-phone-is-the-leak-mobile-security-for-organisations-holding-state-secrets-and-critical-ip/