Webinar On Demand - 45 min
Mobile Device Security Re-imagined for the AI Era
25 June 2026
AI changed the mobile picture in three big ways. It gave every attacker nation-state capability. It closed the window defenders rely on to react. And it opened a data-leak channel that didn’t exist three years ago. The controls most companies put in place two or three years back weren’t built for any of it.
On 25 June 2026, Corrata hosted this webinar titled “Mobile Device Security Re-imagined for the AI Era”.
This webinar covered:
- Where the mobile blind spot sits in a modern security stack, and why regulators now require you to close it
- The four AI-era threats hitting mobile right now
- What a fully protected mobile fleet looks like, the five layers, and why most vendors stop at three
Hello, everybody. Thank you so much for joining us for today's webinar on mobile device security reimagined for the AI era. I appreciate everybody showing up on time. We do normally get a few last minute shagglers, so we are gonna give it three minutes, and then we're gonna kick off the session. So looking forward to bringing you through what we built out here. It's gonna be really relevant to the case for that landscape. And and, yeah, I'll I'll be back to you in in two to three minutes without people kinda filtering. Thanks so much. I think with that, we will, we'll kick off today's session. I want to, again, thank everybody for joining. Over the next thirty minutes, I'm gonna cover something that, we feel is gender genuinely, underappreciated in most security stocks right now, and that's the mobile device. We're gonna look at the AI landscape and why it's increasingly more important to be focusing on the mobile endpoint as a as a key item on your security agenda over the over the next year and and years to come as that threat kind of expands. We're gonna look at what's changed, why AI specifically has made this urgent and what good protection actually looks like in our opinion. And and I'll share some real detection data from our own customer base that I think will surprise a few people, and we'll have time at the end for some questions. So firstly, just some housekeeping points. Today's session will run for about thirty minutes. We'll hopefully leave five to ten minutes at the end for a short q and a. Please do submit your questions. And the questions that I don't get to answer at the end of today's call, we will come back to you over email to make sure everybody's getting their, their thoughts, responded to. And today's call will, of course, be recorded, and we will circulate it across to all attendees and those registered that didn't attend after the session. So let's get started. Quickly, a little bit of context on Corrata before we dive in for those on the call who aren't familiar with ourselves. Corrata, we are a mobile EDR and advanced DLP solution for iOS and Android devices. Everything that we do have, operates and happens on the device. We inspect one hundred percent of traffic. We detect threats across ten different threat signals against industry averages of four. So we have a very advanced method in how we can assess network security and network connections to make sure that protocols and connection bases that are being used are secure enough for your organization to be fully protected. And then we have very advanced features over AI, how we both protect users from us and from the risk, but how we also implement it and how we're going to implement it through our product to offer you the next frontier of threat protection. We provide three key value propositions to businesses, which is one hundred percent visibility into every area of mobile threats that I've mentioned a moment ago, a zero trust, which is giving all security teams and partners, of course, the confidence in knowing that any device corporate or personal personal authenticating through to your environment is secure and safe enough to do so. And then it's the privacy piece. So we are a privacy first solution. We have very much built our product with the end users' privacy concerns in mind, but then also with legislation and different regulations across European, you know, countries and different territories, making sure that we're well within the parameters of acceptable use within these areas in terms of what data we're holding, what data we're we're we're we're keeping, and, of course, what we're actually assessing on the device itself. So to start off today's session, I wanna ask everybody a question that you can answer to yourself. If I was to ask you all to map your security stack as it sits right now for your company or for your your your your, if you're a partner on today's call, for your customer's company, most attendees would probably say that we have really good efforts made in other endpoint security, email security, network security, cloud security. These are different elements that we see typically resourced quite well, both financially and from a from a manpower perspective. And most of us have these covered, and most of our attendees will have these covered quite well. Now on the flip side of that, we'll ask yourself, what's protecting that device that is sitting in every employee contractor's pocket and typically have access to a lot of our systems internally? And with that, typically travels across different Wi Fi networks in and out of different types of different types of Wi Fi sources. This essentially is what we define as the mobile security blind spot. The data that we see around us is stark in terms of eighty five percent of organizations reported increased mobile attacks in twenty twenty five, yet only seventeen percent of these organizations surveyed have any form of protection in place against this threat. Ninety five percent of employees are actively using Gen AI on mobiles with sixty four percent of organizations naming it as their single biggest security concern over the coming few years. And fifty percent of the mobile devices we see and typically run within organizations are operating on outdated operating systems. And we all know as as either security professionals or leaders that this is mobile security one zero one and just make sure you're operating on the most up to date software possible. This essentially means that half of every mobile of the fleet half of every mobile fleet in this room is running out of date software or at least mobile devices across your managed fleet or your customer's fleet is running out of date software. That used to be manageable. I'll get into now in a moment why that's becoming unmanageable. We look at things like how much time we used to have to patch these these issues before they could be exploited. We then look at the regulated issues. So, you know, now for highly regulated sector clients and and and those in between, this is now compliance this is now compliance imperative. It's not just a, you know, a best practice. NIST two and DORA, as we know, are mandating that you need to have demonstrate you need to demonstrate mobile threat visibility. You need to be able to have insight into these threats, and you need to be able to report on specific types of threats in different time frames dependent on the severity of the case. So this this isn't just a gap anymore from an internal point of view. From a compliance point of view, it can be a massive visibility gap as well. So this was a massive problem before AI. Let's move into let's move into and talk about how AI has changed this and what it's essentially done to that mobile security blind spot. It has existed for years, the blind spot, as we all know. Why is it now critical? Three main things happened with AI and have happened over the last number of years with AI. Firstly, AI has made attackers smarter and much more capable. Exploits that used to take months to build now take minutes to deploy. They used to be very resource heavy. They're not really anymore. And as we know, it's only seventeen percent of organizations have any defense against the the surge within this category. The time advantage has flipped. We used to assume defenders had more time than than attackers. That's completely gone. The meantime to exploit is now negative seventy days. The patch doesn't exist before the attack lands. We used to have I think it was on average sixty three to sixty four days to patch these and these vulnerabilities. That's gone. It's much quicker. And as I mentioned, that time advantage has completely flipped to the other side. And with this, we've seen a completely new data lead channel appear, one that didn't exist before twenty twenty two. An employee can paste client database paste paste the client database into a consumer AI tool in, you know, minutes, in seconds, on their phone without anything essentially stopping them or noticing that is happening. Sixty four percent of organizations, as we know, have labeled this as their biggest mobile risk now. Faster attackers, no response window, a data leak channel with zero visibility and typically zero control, that's essentially how it's reshaped the blind spot, and it kinda does a good job in painting the the the risk world that we're we're we're currently operating in. Let me make this a little bit more concrete with the four risk factors that we see most frequently brought to us by our customers. Hyper personalized AI generated phishing is hitting a fifty four percent click through rate. Traditionally, these campaigns, when they weren't as personalized or as easy to deploy, were about twelve percent successful. We're now seeing over half of these campaigns are being successful. Twenty eight percent of CVEs are being exploited within twenty four hours of disclosure. No patching cycles that we have internally, they can't keep up with this this this pace. Your employees are sharing sensitive data with LLMs completely without approval, thinking that they're doing a better job being more productive, forty three percent by the number. And as I said, it's not rogue behavior. It's not trying to create risk for the business. They're trying to do what we are trying to do our jobs quicker, more productively for the business without knowing all of the massive risk that it's opening when we do share that client data file or we do share that contract or we do share whatever the the the file is to, you know, dissect the phone numbers or to give me the top target accounts or whatever the use case, we're opening up a massive data lead point there. And then we have the agent the agentic overreach. So AI agents are being granted permissions on mobile devices that go way beyond their intended purpose and what users are downloading them for. Typically, mic, camera, location, context are being accessed. The average social app now requests ten unnecessary permissions. So it typically breaks down to, you know, your employees aren't granting access to features anymore. They're granting access to everything when they're deploying these applications on their phone, again, to help them work in a more product productive, more successful manner. These four vectors are live in your environment right now. The ones that we see across all of our customers and all of our partners, the ones that we're talking through talking to day in, day out. The question that we put back to our prospects, our customers, our partners is whether they have any visibility into what's happening across their mobile fleet when they look at these different risk factors, and how quickly they're moving. Now I want to show you something that isn't an industry report. It's always really important when we do share these stats around the risk and how it's moving and where it's going that we can benchmark it against what we're seeing across our feed of devices globally. So this is our own data pulled from customer customer both from our active customer base in late April, then again in early June, just six weeks apart. What it shows is is some might say in ways expected, but in other ways, very, very alarming. Eighty four percent of customers were regularly accessing AI services across this period, probably as expected, but there's a forty percent month on month growth in AI traffic. What we're seeing now and what's increasing really quickly is thirty two percent of all threats detected are AI based. So that's essentially one out of every threat that we see coming through our database is AI based, and that number is rising. And to benchmark it at how quickly it's rising, it would it didn't really exist two to three years ago. So the landscape is really churning far faster. You can notice a chart there on the right of our page. What this represents in the blue slice is returning AI domains, solutions and tools that we're we're used to seeing that people have embedded into their day to day life that they're using frequently, that they either have permission to use, or they're using in some context. But but ones that we know exist and ones that we've seen registered before across our fleet of devices. The orange slice on the other hand is new AI domains appearing completely for the first time. This represents nearly seventy percent over a six week period. That in itself is the is the is the is the really big kind of point of fear. That's the speed in which ShadowAI, as we know, is moving and is growing. We can't govern this with quarterly policy reviews. By the time, you know, the policy is signed off internally, the landscape has already moved on likely by a further seventy percent. We need protection that reacts to behavior in real time, that gives visibility in real time, and allows us to implement these policies in real time, not just a list that gets updated quarterly, monthly, whatever it might be, and then gets implemented and then filters through down to the phone, and then it's a best guess because there's no visibility. Comprehensive insights, comprehensive protection, and ease of protection is critical to combat the pace in which this risk is moving and growing over, as we can see here, just a six week period. So we've spoken about the historical blind spot in mobile. So we know that we have businesses take a huge amount of time and resource in protecting other areas of the company, which are vitally important. And we've looked at how AI has completely reshaped, I suppose, the risk aligned to mobile and and reshaped that blind spot. And then we've looked about how that filters into actual risk factors and and what they're achieving on the back of that. We now know that the data proves that there's a real risk. We all know there's a real risk, but we now know the pace in which that risk is evolving through our our our active user base, which just kinda concrete stuff that massive gap and the constant kind of reworks that are needed to stay on top of these, of these potential business risks. So in the face of all that, I suppose what is enough protection? We think about it internally as five layers in the face of AI, and we'll go through each one individually. Layer one is all about governance, so it's defining sanctioned products against unsanctioned products. We all know and love different versions of AI. They do help us do our job in a very productive way, and they are vital in some areas of the business. But we need to know what has been approved for use, and then we need to sanction those solutions so they can be used in a productive way. And we need to force that across our entire fleet, which is both corporate and personally owned phones and tablets to make sure that this policy has no holes, that there's no backdoor in, that there's no way to use these solutions, you know, outside of an app in a network layer to make sure that the the the full device is covered. Layer two is visibility. One hundred percent of traffic is inspected on device and with live security scores being assigned to that device so we know which device might be vulnerable and which might not be vulnerable. Within the traffic inspection, making sure that we're taking advantage of the advanced solutions that are on the market. Ourselves, we work off ten threat signals, some, you know, DNS, IP, SNI, TLS, Cypher suites, HTTP host, understanding port activity. This comprehensive insight is vital to understand the the connections that we're making when we're transferring data, when we're accessing internal systems are secure enough and are safe enough for us to be able to do that in a in a in a in a safe way. Layer three is enhanced threat detection, on device SLM analysis, encrypted traffic, and behavioral insights in real time being mapped together. I will get to that in a moment. No data leaves the device. Full spectrum coverage against all types of phishing, SMS, WhatsApp, QR code, coverage all the way up to our advanced and really, really, really sophisticated attacks, like of likes of our Pegasus class firewire detection methods, and making sure that we're covered by all means and not just by our QR code phishing campaigns. We're making sure there's coverage across all possible risk risk factors. We then look at data protection, precision DLP at the network layer, content and destination is analyzed, not just URL categories, consumer LLMs, AI coding assistance, unapproved SDKs blocked, personal identification information leakage leakage via ad networks is protected. And then finally, look at how do we respond and remediate within this context, and it's automatically quarantining these infected or possibly vulnerable devices away from our core our corporate environments in a really quick and meaningful way before a human has time to act, making sure that these these these happen natively to these happen automatically in the face of a threat, in the face of vulnerable vulnerability on the device that might bring risk into into the business. We wanna make sure that solutions are natively fitting into what we already have in a company, into our corporate security landscape, that there's no friction, that all the solutions are working in tandem to, you know, one final goal of protection. And then when there is an issue on device, guide itself remediation so the end user can resolve issues themselves, helping with, you know, keeping tickets away from support desks and making sure everybody's kind of accountable for their own device within context. Most vendors we see in the market will cover, you know, three of these layers. We very much work to cover all five. It's very important to have a completely all rounded protection posture in the face of the growing landscape that we've we've we've just covered. So to spend a moment specifically on DLP because it is where most of the questions that we get from our customers and from our partners come from. The problem with a lot of DLP solutions on the market, as good as they are, a lot of them give you all or nothing capabilities, block all AI, block all file sharing, and so on and so on. That doesn't really work in the context in the way we work anymore. You need to know what content is going where. And as I mentioned before, we need to have the ability to be able to engage with these solutions in a safe way because fundamentally, they do help us. Being able to sanction allow traffic to sanction and unsanctioned products, vital. Having insight into all of those different AI solutions that are being accessed and blocking if needed or just getting that visibility on personal devices is key. Being able to go that bit further on our network analysis within our DPI, being able to inspect t l I TLS versions and Cypher suites to understand that if there is data in transit, that it is safe. And then as I mentioned, the PPI controls around these ad agencies that are harvesting personal identification information were then resale. So what does the next frontier of protection look like? And I wanna close the technical section with something forward looking because I think it really illustrates where mobile threat detection has to go within the context and the conversation that we're having today. The opportunity has always been that encrypted traffic is has always been a blind spot on mobile. Most MTD solutions, not ourselves, cannot see into the likes of our TLS sessions to understand encryption protocols to make sure that there is efficient security in place for those dot dot dot dot in transit use case. LLMs have real strength here. You know, they can learn behavioral patterns, rule based systems. They can match up data points to make sure that we're detecting in real time. The complication has always been that cloud LLMs create new problems for businesses, and ruining traffic externally to a cloud LM introduces latency issues and, of course, new privacy risks. And the solution that we have come up with for Corrata is a custom built SLM operating directly on the device trained specifically on mobile threat patterns running entirely on device, as I mentioned, which is critical within this this use case. It's analyzing traffic behavior and connection metadata in real time. Nothing leaves the phone, connecting the dots to help combat against these potential data leaks in real time. That's the next frontier, and that's the future of mobile threat detection operating fully on device itself. So let's walk through a real scenario using this diagram because I think it really makes the architecture click. I'll bring you through a full story play play by play here. It's nine fourteen AM. An employee downloads a file from an internal resource. Could be a client contract, a data set, anything sensitive really, that our on device DPI is watching all traffic, you know, as it happens right on the device. So nothing goes to the cloud. We have protected it. Four minutes later, the same employee tries to upload a file to, you know, an AI service, one the organization probably hasn't approved. Let's just for this use case, say, they want an organization has not approved. Now here's where it gets really interesting. Our on device SLM can join those dots. It sees that a file was just pulled from an internal source, whatever that might be. And minutes later, something is heading to an unapproved AI tool. That pattern, the download of the file size and the upload to an unsanctioned destination looks like data being taken out of the organization. The SLM flags it as a potential high risk. And then this is the thing that traditional MTDs, threat detection solutions can't do. Rule based detection detection sees two separate events. The SLM sees the sequence and understands the intent. The data has been taken out of the solution and is being put back into a new place. Then the flow brings you into the policy section. So then it hits the policy decision. What does your policy say? Three outcomes. Block it outright and record the event. Allow it through, but alert the security team inter immediately, and queue for admin review. That section there is critical for our personal devices. Or is it within policy and let it through with no action? Either way, rather tells the security team what happened, full timeline to your console, your same solution or admin inbox, however you wanna receive that that that that alert. The critical point throughout all this is nothing left to device. Everything has happened completely on device. No traffic was routed to a cloud or an external LLM for analysis. The intelligence runs completely on the phone. This is a this you can kinda think about it. Think think think of the Corrata SLM operating on your device as everybody's own personal security analyst on each phone or tablet working twenty four seven, mapping this data while you all potentially sleep. And that's that's the end goal, is that the protection and the analysis is always happening, to combat any potential leaks or any potential, risks for the business. So the product value in the face, again, to reemphasize, we've covered the mobile blind spot traditionally as it has existed and the stuff that make us, you know, a scary place to operate. We then look at how AI over the last number of years has reshaped that blind spot and the risk. We've come into then how the individual risk factors are achieving greatest success and, are really, you know, scaling up at at at a really, really fast speed, through the ease of use and deployment and ease of personalization. Marking that into our own data really proves that we can get a handle on what we can see six weeks later. Seventy percent of it is completely new. So we need to take steps as as as security leaders and as individuals to make sure that we have guardrails in place that give us full full visibility and allow us to change policy as and when needed, and but visibility really is that key point. So where do we offer value here? When we talk to our customers, prospects, our partners, it really boils down to four places within this conversation. And it's weird, I suppose, security leaders, CSO. It's why, I suppose, security leaders, CSOs, IT managers, CEOs choose Corrata to be their security partner for mobile mobile devices. And and I'll be pretty direct about what differentiates us. So GigOM has ranked us as a number one in as number one in the mobile threat detector radar. We have ten years plus of on device traffic inspection experience, and that's the foundation of detection quality. We have a native DLP built in, not bolted on. It happens in the same motion as threat detection on the network layer, not as a separate product, giving you granular access to be able to implement policy that makes sense for your business. Privacy by design is one of our core value propositions. No location tracking. No file scanning. No browsing history. That's why employees actually adopt and accept it on personal devices. We're there to protect. When you're implementing policies, there are essentially two use cases that you need to consider as corporate devices, which, yes, we can deploy to MDMs. Yes. We can lock them down through policy. We can't do that on our personal devices. We need to be able to adapt our policies around personal devices to just gain visibility, and that's what we allow you to do. Higher adoption means a higher protection rate across your global fleet. And with that, it's it's it's ease of deployment, but they should also say ease of ease of, ongoing management. We deploy we can deploy in under twenty four hours. We integrate fully with existing MDM solutions, other existing security solutions in the business. We don't need to rip anything out, of course, if there's no MTD solution there as it is. This gives a number of benefits to a business. There's no heavy implementation period or timelines that you know, budgets or resources that get used up to get crowded deployed. But then from an ongoing management position, we empower end users to remediate issues, which is which is crucial for IT support desks and crucial for users staying connected to their resources, step by step in app instructions, easy to uninstall malware, easy to update configuration settings directly from within our app, makes it a nice product to use from an end user perspective, but a really nice product for IT workload as well. So I'd like to thank everybody, firstly, for for your time today. I won't recap what we've spoken about, but I think that gives us a really good appreciation to the AI era and and what we have to do as mobile security vendors to properly protect users and and clients and customers and everybody within this this this massively increasing landscape of threat. So with that, I am going to pop over to the q and a section. If you could give me one moment, I think I saw a number of questions come in. Yeah. Okay. So we have a couple of questions in there, I think. The first question I can see here is how does CRADA handle BYOD specifically? How do you get employees to actually accept it on personal devices? I assume that that I I I I'm pretty I I probably answered that near and full on the on the privacy piece. It's vital for us that we're seen as a solution at once that the end users want to adopt. It's traditionally really hard to get mobile security agents onto those personal devices for two reasons. One, users don't wanna feel like they're being tracked, like they're being monitored, or like they're being restricted. But then two, you know, through other European territories, GDPR, different regulations, we wanted to make sure that we had a solution that was really, really compliant. And based on our architecture, because we operate fully on the device, that all network traffic is fully scanned and assessed on the device itself, and nothing leaves nothing ever leaves outside registered threats. We can give huge confidence to to security teams and to works councils that that we are collecting and handling the most minimum amount of data to be able to assess this network security. Our adoption rates are quite high for that instance because we don't loop because we don't route traffic to external servers through VPNs. This really protects the usability of the device, so we're not affecting the battery life. We're not affecting the connectivity of the device. So it really has minimum effect on the actual phone or tablet that it's running on. And for all those reasons, we see our our adoption rates through personal devices, be it always a phase two deployment. We see them we we see it quite high. Hope that answers that question. What's the performance impact on the device both now and post LLM launch? So just right. I I think I've just I've just answered that question as it is today. Yes. Within the context of an LLM, obviously, the whole problem with with shipping LLMs to devices is they really affect the usability of the phone, the connectivity, the life, the speed because they're they're so large. That's why we are developing what's being called an SLM, so small language model. And this is for a number of reasons. Firstly, absolutely protect the usability of the device to make sure that we're not there's no lag or latency in effect there. But then also, we know that we're being deployed for for a certain number of use cases. So we're making it as lean as possible to make sure that use cases that are obvious across our customer bases are being covered off without any additional need for anything else being engaged with. So it's it's purpose built, purposefully deployed to device in the complete context that it needs to be deployed to do the job that we want it to do in the industry that did and and that the industry needs it to do. So early testing there is really good. It's a product that we're we're, working to launch by the end of the year and more to come on that in upcoming newsletters. How does your policy engine work for ShadowAI? How granular can you get, and who manages the allow block list? So this is this is really important. This is a key that we differentiate us. We want to be a user to be able get as granular as possible. And so as I mentioned, sanctioned, unsanctioned products, there's no need for businesses to go in and block all AI. We wanna offer our users capability to go in and sanction specific solutions. So when you go into the policy section as an admin of Corrata, so it's whoever the business has chosen as an admin can go in and then click policy. Basically, they're just searching a a solution name and clicking block fully block traffic fully or allow traffic and give me a report on on the back end. How most of our customers deploy our DLP solution is in two phases. Firstly, they turn it on, and they turn on everything to allow them report. And then by the end of a four to six week period, they get a really good insight into what's being used across the business, and then they build a policy off that, which has proven to be a really productive way to do it. Do do what's the next question? So we already we already have MDM in place. How do you make the case internally for a dedicated mobile layer? I mean, I think the case now specifically, traditionally, it's always been MDM as the starting point and and and more often not the finishing point. If we think about it in this way, MDM is really great for managing what devices can do, but doesn't offer any protection on the network side, any protection of our phishing campaigns. Yes. You can put in controls in terms of app engagement, but once a user brings that activity to our network layer, it's completely gone out of the out of the remit of the MDM. So that's where we essentially sit in. So when we look at these campaigns that are hyper personalized, delivered at scale now, and the increased number of AI threats one in every three over a six week period, we then look at the scale of ShadowAI growing at nearly seventy percent over the same period in terms of, you know, domains we haven't seen, it puts really strong emphasis of a knee on a need for a a really advanced MTD product sitting on the device, operating on the network layer to give full protection within that category as well. I think we will leave it there. I think there's two more questions there that I will come back to. But in the interest of time, I wanted to just close off by saying thank you to everybody for joining this session today. As I mentioned, it has been recorded, and it will be circulated later. And if there are any questions, please feel free to reach out to sales at karate dot com, and we'd be happy to take this conversation offline. Thank you all very much, and I hope you all enjoy the lovely weather.