Debunking mobile device security risk myths

Misinformation about mobile device security spreads faster than a viral meme. These misconceptions tend to create a false sense of security, which is precisely what cybercriminals rely on. 

So, it’s time to separate fact from fiction. Let’s debunk some of the most common mobile device security risk myths.

Myth 1: Mobile phones are more secure than desktops

Spurred by the outdated belief that most breaches occur within Windows systems, most people assume that mobile devices are innately safer than desktops. 

Despite built-in security features such as biometric authentication, encryption, and sandboxing, mobile devices are just as vulnerable to cybersecurity risks as computers. 

Their portable nature, the rise in mobile phishing, and side-loaded apps are just some of the reasons for this.  

On the whole, no device is more secure than any other, and each has unique vulnerabilities.

Myth 2: No one can track my phone if location services are off

Disabling location services helps but doesn’t make your device completely invisible. Whether you use an iOS or Android phone, there are ways to track it without GPS. 

Proximity-based tracking is an alternative that uses signal strength, access points, and device interactions to infer locations. Examples include:

Cell tower triangulation

First developed to help emergency services locate callers, cell tower triangulation measures the time delay a signal takes to travel back to multiple towers from your phone. Then, it translates the delay into a distance that gives an estimated device location.

Wi-Fi tracking

Wi-Fi tracking detects unique identifiers, like the media access control (MAC) address of devices that connect to or pass near Wi-Fi access points. Tracking these identifiers as the device moves allows systems to gather location data without an active network connection.

Bluetooth tracking

Bluetooth tracking relies on signals emitted by Bluetooth-enabled devices when they are within range of sensors or beacons. 

Beacons are often present in:

  • Airports
  • Retail shops 
  • Smart buildings 
  • Museums

Want to know more about the mobile threats facing small businesses? Check out our latest research report

Myth 3: I’ll know if my phone’s been hacked

It’s easy to assume you’ll be able to tell if your phone’s been hacked. Unfortunately, that’s not always the case. Estimates suggest that over 70% of malware employs stealth-oriented techniques to minimise visibility and evade detection. 

Stealth malware operates quietly in the background without the signs we’ve come to associate with comprised devices, such as: 

  • Freezing 
  • Strange pop-ups
  • Overheating 
  • Poor battery life 
  • Unexplained account activity 

Its primary purpose is to silently collect sensitive data, including passwords, messages, and banking information.

Myth 4: Only high-profile individuals need to worry about mobile security

While celebrities, executives, and politicians are prime targets for cybercriminals, most cyberattacks target ordinary people. 

The majority of cyberattacks are automated and launched at scale – an approach that will only increase with the rise of AI-powered cybercrime. 

The ‘spray and pray’ method targets a large number of individuals through mass, automated attacks. Even if a small fraction of the attacks succeed, hackers can still acquire vast amounts of confidential information.

Myth 5: I can’t be hacked twice

If you’ve ever heard the saying that lightning never strikes the same place twice, you’ll know it’s neither true for lightning nor cyberattacks. 

In reality, being hacked once makes you more vulnerable to future attacks, not less. Let’s look at why.  

  • Exposed personal information: hackers may have access to sensitive data like passwords or security questions. They can sell this information on the dark web. 
  • Credential stuffing: once your login details are exposed, cybercriminals are likely to use them to try and access other accounts and platforms.
  • Copycat attacks: if a company experiences a breach, and it’s covered in the media, other hackers might take notice and attempt similar attacks.

Myth 6: iPhones are immune to viruses

Apple devices have historically been more secure than Android devices due to iOS's closed nature and built-in security features. 

However, it’s a mobile security risk myth that they don’t get viruses. They’re rare but not unheard of.

Jailbreaking is a common tactic that cybercriminals use to remove the software restrictions operating systems impose, making the device, vulnerable to malware and viruses.

Myth 7: Multi-factor authentication provides complete security

There’s no doubt that enabling multi-factor authentication (MFA) significantly improves cybersecurity, but it’s not infallible. 

Cybercriminals have developed ways to bypass MFA. Some of their tactics include: 

  • MFA fatigue attacks: cybercriminals flood your device with repeated MFA requests, hoping you’ll approve one. 
  • SIM swapping: hackers steal your phone number via SIM swapping, redirecting MFA codes to their device. 
  • Brute-force attacks: some MFA relies on weak security questions, which hackers can guess.

Know the facts, protect your mobile device

It’s time to face the facts – cybercrime is only getting more sophisticated. Don’t be misled by mobile device security risk myths, which breed complacency and make you vulnerable to threats. Instead, stay up to date on cybersecurity developments and keep your mobile device safe.

Did you know 59% of SMEs provide no mobile cybersecurity training to staff? Find out why this is a problem and what to do about it in our SME Mobile Threat Report.



5 types of mobile ransomware and how to protect your devices

Mobile ransomware is one of the most disruptive types of cybercrime, often resulting in substantial downtime, financial loss, and reputational damage. 

With our mobile devices storing everything from banking credentials to confidential conversations and documents, it’s a cyber threat you can’t afford to ignore.

What is mobile ransomware?

Mobile ransomware is a type of malware. Hackers use it to encrypt files and block system access to extort money.2024 was a significant year for ransomware, with the number of attacks rising by 13%. It was also the year the largest ransomware payment was recorded – £60 million ($75 million) to the Dark Angels.

How does mobile ransomware work?

Although there’s some variation between the different kinds of ransomware, they all follow the same three stages: infection, data encryption, and ransom demand. 

Cybercriminals use several methods to deliver ransomware to mobile devices, including: 

1. Phishing 

Phishing remains the delivery method of choice for mobile ransomware. Spear phishing is especially popular as it enables hackers to target specific, high-profile individuals.

Want to know more about the mobile-specific threats faced by small businesses like yours? Check out our latest research report.

2. Exploit kits

Hackers use these toolkits to scan devices for security vulnerabilities and install ransomware. 

3. Downloads

Cybercriminals disguise ransomware as legitimate apps. Once installed, the ransomware is free to spread. On the other hand, drive-by downloads don’t need user interaction – malware installs automatically when you visit a harmful website.

Types of mobile ransomware

Here are the five most common types of ransomware to be aware of.

1. Crypto ransomware

This well-known ransomware encrypts files and data, making them inaccessible without a decryption key. The attacker then demands payment, generally in the form of cryptocurrency. Cybercriminals favour cryptocurrency for its anonymity, global reach, and lack of regulation. 

Doublelocker is a notable variant of Android crypto-ransomware. It encrypts files and can change your device's PIN.

2. Locker ransomware

Rather than encrypting files, locker ransomware completely shuts you out of your device. Cybercriminals typically leave a note demanding payment to unlock it.

3. Scareware

This tactic creates fake panic but real danger. It mimics antivirus warnings and claims your device is infected, instructing you to download paid antivirus software. The kicker is that your device wasn’t infected in the first place but gets infected when you download the fake software. 

For example, a pop-up says, “Your device has 1,435 viruses! Pay £40 NOW to remove them!”

4. Leakware

Also known as extortionware or doxware. Instead of encrypting your files, leakware steals sensitive information and threatens to make it public.

5.Ransomware as a service (RaaS)

RaaS enables cybercriminals to buy or rent ransomware code from other hackers. It makes ransomware easily accessible, even to those with limited coding skills. According to the World Economic Forum, RaaS kits cost as little as £30 ($40).  

What are the most targeted industries?

Manufacturing is the most targeted sector in the UK, particularly small companies with 50-200 employees, followed by finance and healthcare.

Responding to a ransomware attack: to pay or not to pay?

Now, that is the question. UK law enforcement discourages victims from paying ransoms, as there’s no assurance that you’ll regain access to your device or data. Plus, complying with ransom demands increases the likelihood of being retargeted.

Here’s how to respond instead: 

  • Isolate affected systems: disconnect infected devices from the network to avoid ransomware spreading
  • Engage experts: consult cybersecurity professionals to guide your remediation efforts. 
  • Report the incident: notify law enforcement agencies
  • Restore backups: if available, use clean backups to restore data once you’ve eradicated the malware

How to keep your mobile devices and business safe

Following mobile device security best practices can help reduce your risks. Here are a few simple examples: 

  • Keep your operating system updated and patch security vulnerabilities
  • Regularly back up your data to an external hard drive or cloud storage 
  • Use strong passwords and enable multifactor authentication
  • Avoid downloading apps from unofficial sources 
  • Install reputable antivirus and anti-malware software to detect threats

Don’t let your data get held hostage

Cybercrime is increasingly targeting mobile devices, and ransomware is no exception.  Understanding the different types of mobile ransomware and taking proactive security measures helps keep your devices and data safe.

Did you know 59% of SMEs provide no mobile cybersecurity training to staff? Find out why this is a problem and what to do about it in our SME Mobile Threat Report.

What PPN 014 means for your business

Procurement Policy Note (PPN) 014 changes the requirements for government and public sector body tenders in the UK. Here’s everything you need to know.

What is PPN 014?

PPN 014 is a government directive aimed at reducing cyber risk in public sector supply chains. Essentially, if your business supplies services or products to government departments or bodies, you’ll be required to prove you have basic cybersecurity controls in place. The simplest way to do this is to complete Cyber Essentials certification.

Why has PPN 014 been enacted?

Simply put, supply chain attacks pose a huge problem. More than 75% of software supply chains experienced cyberattacks in 2024, at a rate of one every two days. What’s more, supply chain attacks are projected to cost the global economy $138 billion (£108 billion) by 2031. 

At the same time, according to government research, UK businesses are ill-prepared for supply chain risks. Only one in ten businesses say they review supplier risk (11%, vs. 9% of charities). PPN 014 is an attempt to plug this gap.

Want to know more about the risks posed by supply chains? Check out our guide to supply chain attacks

History and timeframes

Since 2014, suppliers bidding for certain government contracts have been expected to demonstrate a minimum level of cybersecurity. Earlier PPNs ( PPN 09/14 and PPN 09/23) built this foundation and PPN 014 updates it in line with recent legislation such as the Procurement Act 2023 and Procurement Regulations 2024.

If you’re a business PPN 014 applies to (more on which in the next section) there are a couple of dates to bear in mind:

  1. 24th February 2025 – all procurements that begin on or after this date are subject to the new rules

2. Contracts awarded up to (and including) the 23rd February 2025 will continue to follow the earlier PPN 09/23  requirements

Who is in scope for PPN 014?

If you work with any of the following, you’ll be considered ‘in scope’ for PPN 014 the next time you bid for a contract: 

  • Central government departments and executive agencies
  • Non-departmental public bodies (NDPBs)
  • NHS bodies

To bid for any of these contracts you must be prepared to demonstrate that your cybersecurity meets the standards laid out by PPN 014.

What you need to do to meet PPN 014

Procurement requirements can appear daunting, especially if you’re new to thinking about your cybersecurity. However, the provisions of PPN 014 are actually quite simple and shouldn’t require wading through hours of paperwork or reinventing the wheel. Here’s what you should do.

1. Get Cyber Essentials certified

First things first, you need to complete Cyber Essentials or Cyber Essentials Plus certification. Cyber Essentials certification will help you put in place the five basic security controls required by PPN 014. 

Plus, it’ll protect your company. Cyber Essentials is proven to defend against 98.5% of the most common cyber threats. And, organisations with Cyber Essentials are 92% less likely to claim on cyber insurance policies.

All in all, it’s the easiest route to meeting PPN 014 requirements.

2. Check your certification scope

Once you’ve completed Cyber Essentials, you need to check the scope of your certificate. Does it cover the parts of your business that are relevant to the contract you’re bidding for?

If your operations are split across multiple locations, offices or areas you’ll need to clarify which parts are included. In most cases, this will have been something you tackled when undertaking the assessment. However, it’s always worth checking nothing has changed as it could invalidate your evidence if part of your operations fall outside the scope of your certificate.

3. Prepare documentation

Next, you’ll need to provide evidence of your certification when tendering. You should receive either a digital or physical certificate once you complete the assessment.

4. Keep an eye on your renewal date

Cyber Essentials is an annual certification so you’ll need to renew it once a year to account for any changes in your business. With this in mind, it’s worth keeping an eye on when your renewal date is coming up so you don’t become ineligible for government contracts.

How to prepare for PPN 014

1. Review the guidance

Visit the National Cyber Security Centre’s (NCSC) Cyber Essentials website and use the readiness toolkit to understand the requirements.

2. Understand your contractual requirements

Check tender documents carefully to confirm whether Cyber Essentials certification (or equivalent) is needed. If in doubt, you can always ask the contracting authority or your managed service provider for clarification.

3. Talk to CyberSmart

CyberSmart is dedicated to helping small businesses build Complete Cyber Confidence within their organisations. If you’re struggling with the requirements of PPN 014 or need to start the Cyber Essentials certification process, talk to us, we can help. We offer unlimited guidance and support, free 25k cyber insurance on completion, and we often get you certified in as little as 24 hours. 

If you already work with an MSP (Managed Service Provider) or IT company, let us know so we can speak with them to support you through the process.

How can Managed Service Providers help?

Of course, if you’re an MSP who works with government bodies you’ll need to comply with the requirements of PPN 014 yourself. If this is the case, you likely need a Cyber Essentials certification (something we recommend for all MSPs, regardless of who you work with).

However, you may also need to help your clients meet these requirements. Whether by managing their IT services, helping them complete Cyber Essentials, or advising on security best practices, you have a vital role to play.

Supporting your clients

There are a few key things you can do to support your clients with PPN 014, these are:

Subcontractor management

If you work with other vendors or subcontractors, make sure they meet the necessary cybersecurity standards. By far the simplest way to do this is to insist that anyone you work with has a valid Cyber Essentials certification as a minimum requirement.

Provide advice

Many businesses, particularly SMEs, won’t be aware that they need to complete Cyber Essentials to bid for government contracts. This is your chance to walk them through the process, offer advice on best practices and, ultimately, help them become more secure.

Offer pre-tender support

Offer assistance to clients in preparing tenders that require PPN 014 compliance by outlining the certification roadmap and available resources such as the NCSC’s Active Cyber Defence guidance.

Finally, if you need support, reach out to CyberSmart. We work with over 800 MSPs across the UK and beyond. Find out how partnering with CyberSmart could benefit your business here.

Supply chain CTA 2



Everything you need to know about the upcoming Willow Question Set for Cyber Essentials

Spring is on the horizon and, in the cybersecurity world, that often means only one thing: changes to the Cyber Essentials question set. Titled Willow, a new question set is due to go live on 28th April 2025, replacing 2023’s Montpellier question set.

The Willow Question Set introduces several key updates to enhance organisations’ protection and reflect modern work practices. Here’s everything you need to know. 

Why is the change happening? 

As cyber threats continue to evolve, so too must our defences. In recognition of this, IASME and the National Cyber Security Centre (NCSC) have made some subtle tweaks to the question set. 

It’s best to think of these changes as a natural evolution of Cyber Essentials to account for new forms of authentication and changing working practices. Plus, they should help make the assessment process smoother by providing better guidance for anyone completing the certification.

What are the key updates in the Willow Question Set?

Scope clarification

The new question set provides clearer guidelines on what must be included in the scope of the assessment. For example, this includes any device accessing organisational data or services, even if they connect to cloud services rather than internal systems. 

Firewall management

Under the Willow Question Set, all firewalls and routers must be listed in the network equipment section. There’s also a requirement for home and remote routers to use software firewalls.

The language around firewall management has also been updated in an attempt to drive businesses to review their firewall rules regularly.

Password management

Willow updates existing password policy best practices by emphasising the need for secure configurations. It also introduces passwordless authentication as an acceptable method for securing firewalls and routers. However, passwordless systems may still require brute-force protection methods – such as randomly generated passwords, using letters and symbols etc – if they use backup passwords.

Vulnerability fixes

The terminology for patching throughout the assessment has been changed to “vulnerability fixes.” This is to better reflect the importance of patching and includes configuration or registry changes for vulnerabilities with a CVSS score of 7 or higher, or those classified as high or critical risk.

Definitions and language

There are a few minor changes to the language within the question set. For example, updating the term "plugin" to "extension" and changing references from "home working" to "home and remote working.”

What about Cyber Essentials Plus?

As well as being subject to a new question set, there are some key changes to the Cyber Essentials Plus certification process to be aware of. Assessment tests 1 (Remote Vulnerability), 3 (Malware protection), 5 (Account Separation) remain the same. However, there have been some tweaks to tests 2 and 4.

Test 2 – Internal Vulnerability Assessment

The sampling process for the Internal Vulnerability assessment has changed substantially:

  1. Auditors must conduct sampling immediately before the audit. In previous years, the sample was drawn from the self-assessment report.
  2. Assessors validate the way sampling is conducted This means an assessor will need to see the methods used to determine the number of devices in scope for the assessment.
  3. The assessor or certification body will hold and store sampling evidence for the one-year duration of the certificate. IASME can also request this information at any time.
  4. The specific devices included in the assessment, including the vulnerability scanning and end user tests, will be now be determined by the assessor. 
  5. The random sample of devices picked by the assessor will be sent to the applicant no more than 3 working days in advance.
  6. Internal vulnerability scans will now include ‘configurational changes’ as failure conditions. In the past, high severity vulnerabilities like Unquoted Windows File Path, or Registry Key issues weren't considered conditions for failure – they are now.

Test 4 – Multi-factor Authentication for Cloud Services

Rather than testing all cloud services, as in previous years, a sample is taken instead.

Only cloud services that are accessible by users or devices included on the random scope are tested. If none of the users can access a specific cloud service, then that service is not tested.

Impact on your business

The impact of these changes on your business should be positive. The Willow Question Set provides better guidance and clarity for anyone undergoing Cyber Essentials Certification. Not only will it make the assessment processes easier, but it’ll also better equip your business to meet modern cyber threats. 

However, it’s well worth familiarising yourself with the new requirements before your next renewal.

Managed service providers

The same is true if you’re an organisation providing Cyber Essentials for businesses. Your customers should be able to get through the assessment with less support and finish it better protected to boot.

Again, it’s definitely worth getting to grips with the new requirements so you can offer support to customers where they need it.

If you have any questions about the changes or want to know more about what they mean for your business, please get in touch. We’ll be happy to walk you through it.

Did you know 59% of SMEs provide no mobile cybersecurity training to staff? Find out why this is a problem and what to do about it in our SME Mobile Threat Report.


Common mobile security threats and prevention strategies

Mobile devices are a vital part of everyday life, and unfortunately, so are the forces that threaten them. From phishing to malware, mobile devices are exposed to more risks than traditional endpoints like desktops and laptops.

With that in mind, it’s crucial to understand common mobile security threats and how to prevent them.

5 common mobile security threats

1. Phishing

If there is a number one mobile security threat, phishing is it. It’s a type of social engineering attack in which cybercriminals impersonate legitimate sources to get users to reveal personal information like passwords or banking details. 

Like tackle and bait, phishing and domain spoofing go hand in hand. Domain spoofing involves creating a copycat version of a legitimate website to fool victims. At first glance, the site appears genuine, closer inspection reveals subtle differences. 

For example, a hacker might use a domain name like “evvri.com” instead of “evri.com”.

2. Mobile malware

There are various types of mobile malware, each designed to exploit vulnerabilities in mobile devices. These include viruses, worms, trojans, ransomware, and spyware. Each type has a unique method of operation and can cause varying degrees of harm to your device and data.

  • Bank trojans pose as legitimate applications and compromise users’ financial data, such as bank logins and passwords
  • Remote access trojans (RATs) enable cybercriminals to control an infected device remotely
  • Ransomware locks users out of their accounts or steal information to demand a ransom payment
Want to know more about the mobile-specific threats faced by small businesses like yours? Check out our latest research report.

3. Unsecured Wi-Fi

Public Wi-Fi networks are notoriously dangerous and leave you vulnerable to man-in-the-middle attacks (MITM). MITM attacks occur when a cybercriminal secretly intercepts communications to steal sensitive information.

Network spoofing

Network spoofing is another risk when connecting to public Wi-Fi. Cybercriminals set up fake access points that look like regular Wi-Fi networks, intending to steal personal information.

These traps are set in public locations like coffee shops, libraries, and shopping centres. Networks are named things like “Free Wi-Fi” and require users to create an account to gain access. 

Once you’ve entered your email address and password, they’re stored for criminal activities. This is also known as credential harvesting.

Credential stuffing

Credential stuffing exploits our tendency to use the same username and password combinations. Automation allows cybercriminals to launch attacks on a large scale, primarily for financial gain.

4. Side-loaded apps

Sideloading is the practice of installing mobile apps from sources other than official app stores. People use sideloading to access apps that are unavailable in their location, unlock restricted features, and download free or cheap entertainment. 

Side-loaded apps are a prevalent mobile security threat and the perfect entrance for malware and adware. Users who engage in sideloading are 200% more likely to have malware on their devices than those who don’t.

5. Data leakage

Have you ever wondered why an app needs access to your microphone, camera, and contacts? Chances are it doesn’t. Enabling these permissions makes you more vulnerable to data leakage, which occurs when someone accidentally exposes sensitive information. 

Data leaks are different from data breaches in that they occur when sensitive information is accidentally exposed, whereas a data breach occurs when it’s intentionally stolen. For example, sending an email containing confidential information to the wrong recipient.

Mobile security threat prevention strategies

Whether used for work or play, our mobile devices are a gateway to personal information. Over 78% of people use mobile devices to conduct sensitive transactions such as banking, accessing healthcare data, or sharing business information. 

Given the significant volume of sensitive information stored on our mobile devices, it’s crucial to comprehend mobile security threats and prevention strategies.

Leverage built-in device security features

Modern mobile devices have built-in security features – ranging from encryption to biometric authentication and screen locks. Most of these features aren't enabled by default and require you to activate them manually.

Backup data

Get into the habit of regularly backing up your data. Most devices have automatic backup features, enabling you to store important information in a secure location or in the cloud.

Enable remote lock and wipe

If you’ve ever lost or had a device stolen before, you’ll know the panic that sweeps through you as you realise someone has access to all your personal information. 

Being able to lock and wipe your device remotely mitigates this risk and adds peace of mind.

Use VPNs and turn off Bluetooth

Public networks and Bluetooth are common attack vectors for cybercriminals. If you can’t avoid connecting to public Wi-Fi, it’s vital to use a virtual private network (VPN). VPNs use encryption to create a secure connection and hide your location. 

When it comes to your Bluetooth, it’s essential to switch it off whenever you’re not using it. Plus, make sure you don’t connect to unknown devices.

Set strong passwords

It seems obvious, but never underestimate the importance of setting strong passwords. A password is your first line of defence and can be the difference between a secure system and a breached one. 

Password dos: 

  • Set a unique password for all of your online accounts 
  • Enable multi-factor authentication and biometric access 
  • Use a password generator and manager 
  • Create a long and complex password of at least 12 to 16 characters, containing a variation of uppercase, lowercase, numbers, and special characters

Password don’ts: 

  • Reuse the same password for multiple accounts 
  • Use common words and phrases – for example, password123
  • Use personal, easily-accessible information like your name or birthday 
  • Use keys next to one another on the keyboard 
  • Enable the save password option
Implement app-specific passwords

Many apps allow you to set unique passwords or pins to gain access. Choosing this option is a wise step to minimise mobile device security risks, especially when using apps that contain sensitive information, such as banking apps.

Audit apps

Ever downloaded an app to use it once and never again? We all have. That’s why it’s important to regularly review your apps and delete the ones you no longer use. To take things a step further, make sure to remove your personal information from those apps before you delete them.

As for the apps you use regularly, update them with the same fervour with which you use them – and turn on any auto-updates if that’s an option.

Only install legitimate apps

Verify apps before you install them. The first step is to only download apps from trusted sources, like Google Play or the Apple App Store. 

Here are some other things you should look out for before downloading an app:

  • Search for digital signatures, logos, and contact details
  • Google it to make sure it’s legit 
  • Read the reviews in the app store 
  • Review required permissions

Avoid a close call

In a world where mobile security threats are all too common, adopting simple prevention strategies can make a world of difference.

Did you know 59% of SMEs provide no mobile cybersecurity training to staff? Find out why this is a problem and what to do about it in our SME Mobile Threat Report.

7 reasons every business needs mobile device security training

With cyber incidents ranked as the top global risk, it’s clear that cybersecurity is more than just an IT issue. As our reliance on mobile devices becomes greater, so does the need for robust mobile device security training. 

Not convinced? Here’s why you need to dial up your mobile device security awareness.

1. The growing reliance on mobile devices for work

Once considered an office taboo, 60% of organisations now expect their employees to use mobile devices to carry out work tasks. 

While the use of mobile devices for work improves productivity, it can be a risky business. Mobile devices are generally difficult to secure, and it’s equally challenging to control what employees do with them once they leave the office. They could connect to unsecured Wi-Fi on public transport, set simple passwords, or lose their devices. 

With mobile device security training, you can help employees understand the risks of using mobile devices for work and the best practices to follow.

Want to know more about the mobile-specific threats faced by small businesses like yours? Check out our latest research report.

2. The increase in mobile threats

Mobile devices are the fastest-growing point of entry for cyberattacks, according to Verizon. 

Why do they make such good targets? For one, they have fewer security measures in place. But mainly, it’s because of our behaviour. We tend to use mobile devices on the go, which means we’re distracted and in a hurry, causing us to overlook the telltale signs of cybercrime. 

Increasing mobile device security awareness highlights the social engineering tactics cybercriminals use to trick us, minimising complacency.

3. The proliferation of AI

AI has made its mark on every industry – and cybersecurity is no exception. Cybercriminals use generative AI to increase the scale and sophistication of their attacks. 

AI-enabled cyber threats include: 

  • Convincing, personalised phishing messages 
  • Sophisticated mobile malware, able to avoid detection 
  • Realistic deepfakes 

While AI can enhance cyber-attacks, it can also help detect and avoid them. Many businesses are investigating ways to integrate AI into their cybersecurity strategies. However, generative AI relies heavily on data inputs, so it’s essential to understand how to handle data responsibly to avoid privacy breaches.

4. The truth about human error

To err is human – and the data proves it. Human error is responsible for 85% of cyber breaches. Whether that’s because of hitting send on an email addressed to the wrong recipient, accidentally forwarding confidential information, or clicking on phishing links. 

Human error falls into two categories– skills-based error and decision-based error. 

Skills-based errors result from a lack of technical knowledge. For example, not enabling multi-factor authentication because you don’t know how. 

Decision-based errors occur when an individual makes a poor choice due to bad judgment or insufficient knowledge. For instance, choosing to postpone an update, believing it’s unnecessary to install it immediately.

Providing cybersecurity training and building a positive culture increases mobile device security awareness and reduces human error. 

5. The cost of breaches

Mobile device security training plays a key role in avoiding data breaches. According to the Allianz Risk Barometer, this is the most concerning type of cyberattack. We suspect that’s because of their severe financial ramifications. 

Over half of UK businesses have suffered a cyber-attack in the last five years, leading to a total revenue loss of £44 billion. In addition to the direct costs of a cyber-attack, the financial implications of downtime, legal fees, and lost revenue prove significant. Perhaps more challenging to recover from than financial loss is reputational loss. Among businesses that have experienced a cyber-attack, 47% report greater difficulty in attracting new customers, while 43% say they’ve lost existing customers.

6. The power of quick response

According to gov.uk 36% of medium and large organisations don’t have an incident response plan. This is worrying, considering that quick, decisive action minimises dwell time. 

Dwell time is the amount of time a cybercriminal has free access to a system – from suspected entry to detection. The longer you take to respond, the more opportunity there is to steal sensitive information, escalate privileges, and spread malware. 

Mobile device security training helps employees understand how to respond to breaches and gives them the confidence to flag anomalies. This reduces dwell time and lessens the impact of the attack.

7. The importance of staying compliant

Cybersecurity compliance is the measure of your regulations and standards that protect sensitive data and digital assets. These vary by industry, location, and organisation size. GDPR, HIPAA, and CPPA are some widely recognised regulations. 

Failure to meet relevant regulations can result in legal action, fines, and suspension of operations. For example, GDPR infringements could result in a fine of up to €20 million or 4% of your global annual revenue, whichever is higher. 

Not to mention that HIPAA and SOC 2 require companies to provide security awareness training to be compliant.

Don’t leave your colleagues to their own devices

One of the most valuable outcomes of mobile device security training is building a culture of cyber awareness. When employees understand risks and best practices, they become more security-conscious, and a security-conscious workforce is far less likely to fall victim to cyber-attacks.

Did you know 59% of SMEs provide no mobile cybersecurity training to staff? Find out why this is a problem and what to do about it in our SME Mobile Threat Report.




Mobile phishing: how to spot and stop attacks

Mobile devices are ubiquitous. But for all the good they do, their pervasiveness makes individuals and businesses more vulnerable to mobile phishing attacks. 

The rising tide of mobile phishing 

Cybercriminals have cottoned on to our growing reliance on mobile phones and unsurprisingly have shifted their focus from desktop to mobile. According to Zimperium, 82% of phishing sites now specifically target mobile devices

Mobile phishing is a type of cyber fraud that uses social engineering to get individuals to share sensitive information or click harmful links. These ‘mobile-first’ attacks have not only increased in volume but also in complexity, making them harder to spot.

Common types of mobile phishing attacks

  • Smshing: phishing campaigns that use SMS
  • Voice phishing: also known as vishing, this is when a cybercriminal impersonates a person or a business over the phone
  • Social media phishing: impersonating legitimate accounts and sending messages to solicit personal details
  • QR code phishing or quishing: malicious QR codes that redirect users to phishing websites

Want to know more about the mobile threats facing SMEs? Check out our latest research report.

Why mobile phishing is effective

The proliferation of smartphone use has undoubtedly contributed to the rise of mobile phishing, but it’s not the only reason for its rise in popularity.

Smaller screens, simplified interfaces, and hidden URLs make it difficult to identify the telltale signs of phishing. 

What’s more, users behave differently on smartphones versus desktops. Just think about how you casually check your mobile device in between tasks, waiting in queues, using public transport, or simply lounging around at home. There’s an inherent sense of complacency. Coupled with the pressure to respond quickly, you’re less likely to treat phishing attempts with the same scrutiny on mobile as you would on desktop. 

Generative AI is also playing a part in helping cybercriminals enhance their phishing attacks. These advanced language models enable hackers to create highly convincing messages without the characteristic grammar and spelling mistakes often found in phishing attempts. A Verizon report highlights the growing threat of AI, showing that 77% of respondents think AI-assisted attacks, including deepfakes and SMShing, are likely to succeed.

Bring your own device (BYOD) practices continue to pose a significant risk, even with the increase in return-to-work mandates. Data leakages, less control over device security, and compliance are just some of the challenges of BYOD, making it an appealing attack vector for phishing.

5 ways to identify a mobile phishing attempt  

Don’t take the bait. Here are some tips on recognising a mobile phishing attack.

1. Check the sender’s contact details 

Phishing attempts often come from addresses or domains that look similar to legitimate ones. Before taking action, double-check the email address, website, or number against the one you know. 

2. Look for basic mistakes

Generic greetings such as “Hello customer”, spelling mistakes and grammatical errors are clear signs that the message is not genuine. 

3. Slow down when there’s urgency 

“Act now”, “Claim your prize before it expires”, and other messages that pressure you to respond immediately should raise a red flag. 

4. Don’t open attachments 

Attachments that you weren’t expecting can contain malware. Verify what the attachment is with the sender and hover over it before opening. 

5. Trust your instincts

Be wary of messages requesting personal details, passwords, or banking information. If something seems too good to be true – like notifications about winning competitions or receiving refunds – it probably is.

How to protect yourself against mobile phishing attacks

Although mobile phishing attacks are becoming more complex, protecting yourself is simple. Here are some basic steps you can take.

Enable multi-factor authentication

Multi-factor authentication uses a secondary form of verification to enhance security. It ensures that even if a cybercriminal cracks your password, they won’t be able to access your account.

Run regular software updates

It’s tempting to select the ‘install later’ option when an update notification pops up, but it’s important to let updates run as soon as they’re available to patch any security vulnerabilities.

Review app permissions

Only grant permissions essential for an app's functionality. Assess whether the app truly needs access to your microphone, camera, contacts, location, or other features.

Install mobile security software

Antivirus and anti-phishing apps provide real-time protection for your device. Better still, you could use a threat detection app to tie it all together. However, before you install any apps make sure you’re using a trusted source – like an official app store.

Always check the source 

The best way to check the legitimacy of a message is to contact the sender directly using their known contact information. If it’s a website, type the domain into your browser instead of clicking the link. If it’s a colleague or friend, message them on their usual number or email address.

Stay informed

Mobile phishing tactics change all the time. Check out other articles on our blog to stay up to date with all the latest cybersecurity trends.

Don’t get reeled in

If mobile phishing shows us one thing, it’s that cybercriminals are constantly evolving. As phishing attacks become more sophisticated, your best defence is to question and double-check everything. Adopting proactive measures, practising good cyber hygiene, and staying alert will keep you one step ahead.

Did you know 59% of SMEs provide no mobile cybersecurity training to staff? Find out why this is a problem and what to do about it in our SME Mobile Threat Report.





10 mobile device security best practices every business should follow

Whether it’s replying to emails during your morning commute or logging into Slack while you enjoy a well-earned break, mobile devices have become indispensable to how we work. Laptops, smartphones, and tablets let us communicate and collaborate from anywhere with a reliable internet connection. This flexibility allows us to be just as productive on the move as we are in the office.

As with any innovation, there are drawbacks. Mobile devices are a gateway to sensitive corporate information and confidential client files, making them an extremely tempting target for hackers. So, it’s essential you have robust security measures in place to protect your data.

With that in mind, here are ten mobile device security best practices every business should implement.

Strengthen your defences with these mobile device security best practices

1. Create a mobile usage policy

A mobile usage policy establishes clear guidelines on how to use company-owned and personal devices safely. It outlines the security requirements staff must follow as well as the consequences for non-compliance.

Implementing a policy in your business ensures everyone follows the same standards and procedures, increasing your resilience to cyber threats.

Want to know more about the mobile threats facing small businesses? Check out our latest research report

2. Enable biometrics

Biometric authentication makes it harder for unauthorised users to access mobile devices. It replaces traditional verification methods, like passwords or personal identification numbers (PINs), with unique biomarkers – typically a fingerprint or face scan. These are difficult to crack without advanced technology, which means they’re more secure than simple six-digit PINs.

3. Encourage multi-factor authentication

Even the strongest passwords are crackable with enough time and the right tools. That’s why mobile device security best practice recommends activating multi-factor authentication (MFA) on all employee devices.

MFA is a security measure that requires two or more verification methods to access accounts, applications, or systems. This can be any combination of passwords, PINs, one-time codes, biometrics, or other reliable forms of authentication. It’s much harder for cybercriminals to break through multiple layers of security, which increases your protection against unauthorised access.

4. Encrypt devices

Encryption converts device data into unreadable code you need a key to access, keeping it safe from prying eyes. Most devices come with some form of built-in encryption. For example, Google encrypts all Pixel phones by default.

For added protection, consider investing in a mobile encryption app. These tools offer advanced security features such as hybrid encryption, secure messaging, and periodic code audits.

5. Stay on top of updates

Apple, Google, and Microsoft release security patches regularly to safeguard mobile devices against vulnerabilities. Install these updates as soon as they become available, or turn on automatic updates to ensure device security is always up to date.

6. Restrict app downloads

Unregulated, third-party app stores are breeding grounds for mobile malware and other cyber threats. To reduce your exposure, restrict app downloads to reputable sources. For example, the Apple App Store or Google Play.

It’s also sensible to review an app’s access permissions before installation and adapt them accordingly (if possible) to protect sensitive information.

7. Use a VPN

A virtual private network (VPN) masks your IP address and encrypts your internet connection, making it harder for cybercriminals to monitor your activity and intercept sensitive data. 

VPNs are essential when using public Wi-Fi networks, which offer little to no protection against hackers. Just remember that even the most advanced VPNs can’t make public networks entirely secure. As such, mobile device security best practices recommend avoiding unsecured networks unless absolutely necessary.

8. Back up critical data

Data backups are a crucial failsafe that enable you to recover important files quickly if a device is lost or stolen. For added peace of mind, follow the 3-2-1 rule. This recommends creating three copies of sensitive data on two different media, with one of them stored off-site.

Popular storage media include external hard drives, network-attached storage devices, and cloud storage platforms.

9. Run regular cybersecurity training

According to Verizon, 68% of data breaches involve a non-malicious human element. This covers everything from leaving a mobile device unattended in public places to falling victim to a phishing attack. Although it’s impossible to eliminate these risks entirely, educating staff in mobile device security best practices goes a long way to protecting your business.

10. Establish an incident response plan

No device is 100% immune to cyber threats. The important thing is how you react should the worst happen. 

A clear and comprehensive incident response plan helps you contain device breaches and get back to business as usual faster. Additionally, employees feel more confident responding to cyber threats and feel more comfortable reporting them, helping you spot threats earlier.

(Best) practice makes perfect

In the face of increasingly sophisticated cyber threats, mobile security is no longer optional. Following these mobile device security best practices help you lay a solid foundation for your cybersecurity. Deployed alongside specialist mobile security tools, they protect your business from the financial, operational, and reputational consequences of a data breach.

Did you know 59% of SMEs provide no mobile cybersecurity training to staff? Find out why this is a problem and what to do about it in our SME Mobile Threat Report.

What is SVG phishing and how do you defend against it?

Phishing is one of the oldest cybercrime techniques in the book. Indeed, the first phishing email is thought to have originated back in the mists of time, around the year 1995. However, that doesn’t mean cybercriminals haven’t got creative in the years since. Added to recent innovations like smishing and Facebook Messenger scams, there’s a new threat to contend with: SVG phishing.

Here’s everything you need to know about this new threat, including what it is, how it works and, most importantly, how to counter it.

What is SVG phishing?

SVG phishing refers to the use of Scalable Vector Graphics (SVG) files in phishing attacks. An SVG is an image file format for creating and editing two-dimensional graphics. SVG files are a popular format for web and graphic design because they can be scaled up and down easily. 

Cybercriminals use these files to deliver malware or direct victims to spoof forms that steal victims’ credentials.

Why do cybercriminals use SVG phishing attacks?

SVG phishing has gained traction in the cyber underworld because of its ability to evade traditional security measures. SVG files are less frequently flagged as potentially suspicious by security tools designed to detect more common file types like PDFs. This allows phishing emails containing SVG attachments to bypass many email filters, giving cybercriminals a route into target organisations. 

How do SVG phishing attacks work in practice?

In practice, SVG attacks work much like any other phishing scam. Typically, a cybercriminal disguises the SVG files as legitimate documents or requests, using social engineering techniques to convince victims to open them.

It could be a request to edit a file from your ‘boss’ or a report that ‘requires your attention right now’, regardless, the techniques aren’t any more sophisticated than a typical phishing scam.

Once opened, these files can execute JavaScript, redirecting users to malicious websites, displaying fake login forms designed to capture sensitive information like passwords, or releasing malware into company systems. 

However, while many SVG attacks aren’t particularly sophisticated, cybercriminals are getting smarter in how they launch them. There’s evidence of some campaigns using images that mimic documents like Excel spreadsheets, these include embedded forms for credential harvesting.

Are there any famous examples?

SVG phishing techniques have been in use since at least 2015, but media reports tend not to differentiate them from other types of phishing. Nevertheless, there are a couple of recent examples that researchers have identified.

1. Agent Tesla Keylogger:  January – February 2024

Agent Tesla is a keylogger. It monitors keystrokes, takes screenshots, and steals passwords from various applications before sending the data back to the bad guys. It’s not a new form of malware; cybercriminals have been using it since around 2014, but in 2024, cybercriminals started delivering it via SVG files. 

This campaign used a spoof Microsoft Excel spreadsheet, delivered via phishing emails. Once the victim opened the spreadsheet a script was run unleashing Agent Tesla.

2. XWorm RAT:  December 2023 – present

The catchily named XWorm RAT is another form of malware, used for keylogging and stealing cryptocurrency wallets.

These campaigns used various techniques. Some used links embedded in phishing emails, and others included SVG files as attachments. Once opened, these SVG files initiated the download of zip archives containing XWorm RAT, unleashing the malware on the victim. 

For some great examples of real-world SVG campaigns, we recommend checking out Cofense’s excellent phishing database

What can you do to protect your business? 

There’s no doubt SVG phishing poses a serious threat, able to avoid detection by many email filtering tools. But that doesn’t mean there’s nothing you can do to protect your business.

Staff training

We’re always championing the benefits of staff security training, but it’s particularly important when it comes to phishing. By their nature, phishing campaigns rely on social engineering techniques so, if you can train staff to recognise the tell-tale signs, you can effectively neuter the threat.

What training looks like will depend on the expertise within your organisation. You could 

Implement realistic phishing simulations to test employee awareness or something more simple like webinars and videos. However you approach it, the key is that employees can quickly recognise suspicious emails and attachments. 

Limit SVG Handling

One surefire way to mitigate the threat posed by SVG phishing is to limit what your email or browser can do. You can configure email platforms and browsers to block or restrict script execution within SVG files. This stops hidden nasties like Agent Telsa or XWorm RAT from running their malicious code.

Configure email filtering

In a similar vein to the previous point, more advanced email security solutions will be able to analyse attachments for malicious content. Check whether yours can analyse scripts embedded in SVG files. However, it’s worth noting that many email providers can’t do this yet, which is part of the reason for the success of SVG phishing campaigns.

Use CDR Technology

Admittedly, this solution is likely to be beyond the financial reach of most small businesses. Content Disarm and Reconstruction (CDR) solutions are expensive and tend to be the preserve of large corporations and those organisations that need to spend a lot on security.

But, if you’re feeling particularly flush, CDR is a great option for disarming SVG phishing. CDR systems treat all incoming files as potentially harmful. They deconstruct any incoming files, removing anything malicious, before rebuilding them and sending them on to the recipient.  

Put policies in place 

If your staff don’t understand the dangers of SVG files or the safe behaviours expected of them, they’re much more likely to fall prey to a scam.

Develop policies for handling email attachments, especially those from unknown or dubious sources. You could also consider restricting certain file types in email communications unless they’re absolutely necessary for operations. 
Once you’ve set these policies, you need to ensure employees adhere to them. The best way to do this is to make them readily available (they’re no use buried in a long-forgotten corner of a shared drive) and log who’s read them. 

Dangerous, but avoidable...

SVG phishing is dangerous, but it doesn’t have to be an insurmountable problem. By implementing these strategies, your business can significantly reduce the risks and protect company data.

Want to know more about the threats facing small businesses like yours? Check out our latest research report on the mobile threats facing SMEs.

What is mobile malware, and how do you protect against it?

Mobile devices are essential to the hybrid workforce. Having remote access to critical business systems and data enables teams to communicate, collaborate, and work more efficiently – wherever they are. But this convenience also makes mobile devices an ideal target for cybercriminals. 

Among the growing list of threats, mobile malware is perhaps the most prevalent.

What is mobile malware?

Mobile malware is the umbrella term for malicious software specifically designed to target smartphones, tablets, and similar devices. It comes in various forms:

  • Viruses
  • Ransomware
  • Spyware
  • Trojan Horses
  • Worms

Cybercriminals employ a range of methods to deliver their nefarious payloads. These include disguising malicious software as legitimate apps – which infiltrate your device when you attempt to download them – and concealing compromised links or attachments in phishing emails and SMSs. Typically, the hacker’s goal is to:

  • Lock or delete important files
  • Steal sensitive data or hold it to ransom
  • Steal bank account details or financial information
  • Damage or hijack business devices
  • Spy on rival businesses

iOS vs Android: what’s more secure?

Like all Apple products, iOS has built-in safeguards to protect against cyber threats. This makes it more secure than Android, which uses an open-source model. However, neither operating system is infallible.

Common signs of infection

Mobile malware can cause serious harm if left unchecked – from costly operational downtime to reputational damage, fines, and even legal action. So, it’s crucial you know how to spot the signs of infection.

Give your device a thorough health check if you see any of these symptoms.

  • Poor performance
  • Drained battery
  • Overheating
  • Frequent crashing
  • Persistent pop-ups
  • Suspicious app downloads
  • Unexplained charges

8 tips to protect your business devices

Protecting your business devices against mobile malware doesn’t have to be time-consuming or expensive. From using secure Wi-Fi to investing in dedicated mobile device security, here are some quick, cost-effective steps to strengthen your defences.

1. Install security patches immediately

Apple and Android devices receive regular security patches – roughly every month or two. These critical updates fix flaws and vulnerabilities in your device’s operating systems. Install them as soon as possible or switch on automatic updates to close any obvious gaps in your security.

2. Only use trusted apps

Unregulated, third-party app stores are a haven for mobile malware and other cybersecurity threats. Mitigate this risk by enforcing stringent security policies that require employees to use trusted storefronts, like the Apple App Store and Google Play.

As obvious as it might sound, you can significantly reduce your cybersecurity risks by avoiding suspicious links and attachments. If you don’t recognise the sender’s email address, notice something strange about the message, or receive an unusual request, don’t click. It’s better to be safe than sorry.

4. Enforce a strong password policy

Have you ever used a well-known phrase as a password? Maybe a pet’s name? Perhaps you use the same one for every account? Don’t worry; there’s no judgement here. No one really likes passwords, but they’re a crucial component of mobile security.

Keep your devices and data secure by implementing a strong password policy that requires employees to use unique, complex passwords for every device. Follow these best practices to make them easier to manage:

  • Use a combination of four random nouns. E.g. fenceplanetoctopussauce
  • Use a mixture of upper- and lower-case letters, numbers, and special characters
  • Use a dedicated password manager to generate passwords for you and store them in a secure vault

5. Enable multi-factor authentication

Strong passwords alone may not be enough to deter tenacious cybercriminals. For added protection, enable multi-factor authentication (MFA) on your business devices and accounts. This requires employees to use two or more forms of verification, such as:

  • Passwords
  • PINs
  • Biometrics (e.g., a fingerprint or face scan)
  • Software tokens

6. Use password-protected Wi-Fi

Public networks are a convenient gateway to the internet, but they’re also exposed. To prevent cybercriminals from intercepting sensitive messages or launching harmful man-in-the-middle attacks, ensure employees only use password-protected Wi-Fi when working away from the office. If that isn’t possible, use a virtual private network (VPN) to encrypt network data and prevent unauthorised access.

7. Train your employees

68% of all breaches are the result of human error. So, running regular training sessions that teach staff how to identify and respond to cyber risks goes a long way to mitigating them. This includes when and how to share sensitive data, how to spot phishing attempts, and how to remove mobile malware. 

8. Install mobile cybersecurity software

For the highest level of security, you can’t beat dedicated mobile device security software. Designed specifically for smartphones and tablets, it constantly scans devices for common security risks, such as:

  • Misconfigurations
  • System vulnerabilities
  • Suspicious apps
  • Malicious content

It can also block untrustworthy websites and repel attacks in real-time. This gives you more time to respond if something does get past your defences.

Mitigate the mobile malware threat

Mobile malware attacks continue to rise as more employees use their smartphones for work. But by understanding the threat and adopting these simple measures, you can enjoy the benefits of hybrid working safely and securely.

Want to know more about mobile specific threats your business faces? Check out our SME Mobile Threat Report.