Why mobile devices are your biggest unmanaged risk

A laptop left on a train needs a password to open. A phone left on a train sometimes needs nothing at all — it is already unlocked in someone's hand, mid-conversation.

A person checking a smartphone while commuting

The portability problem is not metaphorical

A laptop generally leaves the office in a bag, gets used at a desk, and represents one identifiable, relatively deliberate point of exposure. A phone is out of a pocket dozens of times a day, on trains, in cafes, at school pickup, handed to a child for five minutes of quiet. It is unlocked far more often than a laptop, physically closer to being lost or taken far more often, and carries the same corporate email, MFA app and file access either way.

That difference in handling is the whole risk. Every control built around "a device sitting on a desk behind a locked door" assumes a physical context mobile devices simply do not have.

Weak by default, and rarely fixed

Most consumer phones ship with a six-digit PIN as the default lock method, and most people never change it to anything longer. A six-digit PIN has one million possible combinations — which sounds like a lot until you compare it to a genuinely weak desktop password policy, and remember that a phone's biometric fallback is exactly a six-digit PIN the moment a face does not match or a screen is wet.

Corporate policy on desktop password complexity is usually enforced and audited. Corporate policy on phone passcode length is, in our experience, rarely enforced with the same rigour — even though the phone in question typically has live access to the same mailbox, the same MFA prompts, and often the same file storage as the desktop sitting behind the stronger policy.

What the current threat data actually shows

This is not a theoretical gap. Zimperium's 2026 Global Mobile Threat Report recorded phishing events on employee mobile devices growing 380% since January 2025, with mobile-targeted phishing succeeding at a rate 40% higher than the same attack delivered to a desktop — helped by the fact that 86% of phishing attempts are now AI-assisted, and text messages and QR codes get far less user scepticism than an email does.

The same report found spyware present on nearly one in ten devices — over four times the prior rate — and apps sideloaded from outside official app stores, bypassing Apple and Google's own vetting entirely, on 22% of Android devices and 14% of iOS devices across nearly every industry tracked. None of that requires a device to be lost or stolen. It is already happening to devices sitting in employees' pockets right now.

Why mobile stays the blind spot

Three reasons, consistently: mobile devices are frequently personally owned, which makes organisations hesitant to enforce the same policy rigour they apply to corporate hardware; mobile device management is treated as a configuration project with an end date rather than an ongoing control, so policy drifts once the rollout is declared finished; and mobile threats — phishing texts, malicious apps, network attacks — are largely invisible to a device management platform in the first place, which only enforces configuration rather than watching behaviour. See MDM vs MTD for why that second control matters.

What actually closes the gap

  • Enforce a genuine passcode minimum through policy, not a request — six digits minimum, longer where the platform supports it, with biometric unlock as convenience rather than a substitute for the underlying passcode strength.
  • Enable remote wipe and confirm it actually works before you need it, not during the week a device goes missing.
  • Separate personal and corporate data — work profile containerisation on BYO devices, so a lost personal phone does not mean owning the recovery of corporate data it never should have been mixed with.
  • Add mobile threat defense alongside device management, since MDM enforces configuration but does not watch for a phishing text or a malicious app the way a dedicated mobile threat platform does.

Questions

Are personal (BYO) phones really as risky as company-issued ones?

Often more so in practice, because policy enforcement tends to be softer on personal devices even though the corporate data they can reach is identical. Work profile containerisation is the usual answer — enforce policy on the work container without reaching into personal data.

Is a six-digit PIN actually a meaningful weakness?

On its own, less than the number suggests — most platforms rate-limit guesses. The real risk is a PIN that is short, predictable, and rarely changed, on a device that is unlocked constantly in public, compared with far stronger norms most organisations already enforce on desktop passwords.

Does mobile threat defense replace device management?

No — they answer different questions and are meant to run together. See MDM vs MTD: why you need both for the full distinction.

Mobile threat statistics in this article are drawn from Zimperium's 2026 Global Mobile Threat Report. Figures reflect the report's global dataset, not an Australia-specific measurement.

Managed devices are not the same as protected devices

MDM/UEM and mobile threat defense, deployed together, on whichever platform you already run.