2026 Mobile App Risk Management Survey

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
Your Agentic Security Blueprint for iOS 27 Webinar Your Agentic Security Blueprint for iOS 27 Webinar Register Now
magnifying glass icon

Amy Schurr

AI Is Already in Your Mobile Apps. Most Security Programs Haven’t Caught Up.

By / July 15, 2026 / Comments Off on AI Is Already in Your Mobile Apps. Most Security Programs Haven’t Caught Up.

Mobile apps have already made the jump to AI. Security programs haven’t. NowSecure’s 2026 Mobile App Risk Management (MARM) Survey of 485 senior security leaders across finance, healthcare, high tech and retail found that every single respondent now rates mobile apps as very important or critical to the business, and 95% deploy AI inside them […]

The NVD Backlog Is a Symptom. Vulnerability Management Has a Scaling Problem

By / June 3, 2026 / Comments Off on The NVD Backlog Is a Symptom. Vulnerability Management Has a Scaling Problem

Most vulnerability management programs are built on a simple assumption: vulnerabilities are discovered, assigned a CVE, analyzed, prioritized and remediated. A new federal audit suggests that model is under increasing strain. The National Vulnerability Database (NVD) backlog isn’t just a government process issue; it’s evidence that vulnerability volume, software supply-chain complexity and shrinking exploitation timelines […]

What OWASP Vulnerabilities in AI-Generated Code Mean for Mobile App Security

By / May 19, 2026 / Comments Off on What OWASP Vulnerabilities in AI-Generated Code Mean for Mobile App Security

Key Finding: 1 in 4 AI-generated code samples contain at least one confirmed OWASP vulnerability — and mobile apps face elevated risk due to their distributed, client-side execution model, direct exposure to untrusted devices and attack surfaces traditional AppSec tools are not designed to evaluate. Developers are increasingly turning to AI coding assistants to speed […]

Mobile App Privacy Risks Explained: SDKs, Data Collection & Hidden Exposure

By / May 13, 2026 / Comments Off on Mobile App Privacy Risks Explained: SDKs, Data Collection & Hidden Exposure

When regulators issue billion-dollar fines, enterprises can no longer ignore the mobile app privacy blind spot. Organizations face significant compliance exposure because mobile apps that power the business often rely on hidden third-party SDKs and data flows that security teams aren’t monitoring. Most organizations have invested heavily in securing web applications and cloud infrastructure. Mobile […]

The Third-Party Mobile App Risk Hidden Inside Your Approved Apps

By / April 28, 2026 / Comments Off on The Third-Party Mobile App Risk Hidden Inside Your Approved Apps

When Frederick County, Maryland, reviewed a mobile app used by its fire and rescue team, it passed every traditional check. The app connected to an ultrasound device, looked legitimate and had been approved. Binary-level analysis told a different story: the app was exposing protected health information, violating HIPAA in ways that no privacy label, MDM […]

How AI Models Like Mythos Are Changing Mobile AppSec Risk

By / April 20, 2026 / Comments Off on How AI Models Like Mythos Are Changing Mobile AppSec Risk

A Q&A with NowSecure Cofounder Andrew Hoog TL;DR: What this shift means for your AppSec program AI is compressing the time between vulnerability discovery and exploitation thanks to frontier models. Anthropic’s Claude Mythos, designed to reason about code, identify vulnerabilities and simulate attack paths, recently demonstrated it could autonomously discover and exploit vulnerabilities and execute […]