Mobile threat defense (MTD) is security software for smartphones and tablets that detects threats to the device, its apps, the networks it connects to and, in many products, the links users open. It reports risk to a central console and, when connected to a device or endpoint management tool, can trigger actions such as blocking a risky device from company email until the problem is fixed. MTD fills a gap left by device management tools, which configure phones but generally do not look for attacks.
At a glance
- MTD detects mobile threats; it is usually delivered as an app on the device plus a cloud console.
- Common detection areas are device risk (outdated or tampered operating systems), app risk and network risk; many products add phishing link protection.
- It is most useful when integrated with mobile device or unified endpoint management, so detected risk can change a device’s access.
- It runs on iOS and Android, but what it can see is limited by each operating system.
- Feature depth, privacy handling and integrations vary by provider.
What problem it solves
Phones and tablets now hold company email, chat, files, multi-factor authentication apps and customer data, yet they are often the least protected devices in the business. Attackers know this. Phishing by text message and messaging apps (smishing) reaches users outside email filters, malicious or over-permissioned apps can leak data, and public Wi-Fi can expose traffic to interception. A phone running an old operating system with known flaws may still be allowed to sync company mail.
Mobile device management (MDM) and unified endpoint management (UEM) tools set policy, but they typically check settings, not threats. MTD adds the detection layer, giving IT a view of which mobile devices are at risk and a way to act on it.
How it works
On-device app. Users install an MTD app, usually pushed by the management tool on company devices or installed by the user on personal ones. It works within what iOS and Android allow security apps to do.
Device risk. The app checks the operating system version and patch level, whether the device has been jailbroken or rooted, and settings such as screen lock and encryption.
App risk. Depending on the platform and product, MTD analyzes installed apps for known malware, risky permissions, or behavior such as sending data to suspicious servers. Many products also scan apps in the cloud before or after users install them.
Network risk. The app looks for signs of interception, such as rogue Wi-Fi access points or suspicious certificates on the connection.
Phishing protection. Many products check links opened in text messages, messaging apps and browsers, often by inspecting web traffic through a local VPN-style profile on the device.
Response. The MTD console assigns each device a risk level. Integrated with MDM, UEM or conditional access policies, a high-risk device can be blocked from company apps or have company data removed, and the user is told what to fix.
When it matters for buyers
- When mobile devices access sensitive data. Email, CRM, file shares and authenticator apps on phones make them a target.
- When you allow personal devices. Under a BYOD policy, MTD can add risk checks without full device control, depending on the product.
- When smishing is reaching staff. Email security doesn’t see text messages; MTD phishing protection may.
- When insurers, customers or regulations ask about endpoints. Mobile devices are increasingly counted as endpoints in questionnaires.
- When renewing endpoint or UEM contracts. Some endpoint security and UEM vendors bundle mobile threat features, so check what you already own. See our unified endpoint management overview.
Questions to ask vendors
- Which threats do you detect on iOS and on Android, and how do they differ?
- Which MDM, UEM and identity platforms do you integrate with, and what actions can you trigger?
- Does phishing protection cover text messages and third-party messaging apps, and how does it work?
- What data does the app collect on personal devices, and how do you protect employee privacy?
- Can it run on personal devices without full device enrollment?
- What is the impact on battery life and network performance?
- How is it licensed: per user, per device, or bundled with another product?
- Do alerts feed into our SIEM or managed detection service?
How it differs from MDM
MDM is a management tool: it enrolls devices, pushes settings, installs apps and can lock or wipe a lost device. It enforces policy but generally doesn’t detect attacks. MTD is a security tool: it looks for malicious apps, compromised operating systems, risky networks and phishing. The two work best together, with MTD reporting risk and MDM or UEM enforcing the response. Mobile application management (MAM) protects company data inside specific apps and is often paired with MTD on personal devices. MTD is also distinct from endpoint detection and response (EDR), which usually covers laptops and servers in more depth; some vendors sell both under one platform.
