2026 Mobile App Risk Management Survey

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
Your Agentic Security Blueprint for iOS 27 Webinar Your Agentic Security Blueprint for iOS 27 Webinar Register Now
magnifying glass icon

Best Practices

OWASP MAScon Vienna Showed the Future of Mobile Application Security

By Jeff Kneis / July 2, 2026 / Comments Off on OWASP MAScon Vienna Showed the Future of Mobile Application Security

What Happened at OWASP MAScon Vienna? The inaugural OWASP MAScon in Vienna, Austria, demonstrated what many in the mobile application security community already suspected: demand for a dedicated, deeply technical mobile AppSec conference is strong. Held as part of OWASP Global AppSec EU 2026 at the Austria Center Vienna, MAScon brought together mobile security researchers, […]

OWASP Releases MASTG v2.0 — NowSecure Contributed 320+ Pull Requests to Make It Happen

By Jeff Kneis / June 26, 2026 / Comments Off on OWASP Releases MASTG v2.0 — NowSecure Contributed 320+ Pull Requests to Make It Happen

MASTG v2.0 gives CISOs, auditors and regulators a measurable, evidence-based answer to mobile app risk. The OWASP Foundation released on June 30th the Mobile Application Security Testing Guide (MASTG) v2.0, marking a fundamental shift in how mobile security is defined and executed. This milestone release concludes a three-year, community-driven effort to transform the Mobile Application […]

The NVD Backlog Is a Symptom. Vulnerability Management Has a Scaling Problem

By Jeff Kneis / June 3, 2026 / Comments Off on The NVD Backlog Is a Symptom. Vulnerability Management Has a Scaling Problem

Most vulnerability management programs are built on a simple assumption: vulnerabilities are discovered, assigned a CVE, analyzed, prioritized and remediated. A new federal audit suggests that model is under increasing strain. The National Vulnerability Database (NVD) backlog isn’t just a government process issue; it’s evidence that vulnerability volume, software supply-chain complexity and shrinking exploitation timelines […]

Governing AI-Generated Mobile Apps: A CISO Blueprint for Security at Scale

By Jeff Kneis / May 6, 2026 / Comments Off on Governing AI-Generated Mobile Apps: A CISO Blueprint for Security at Scale

Why Line of Business and the CISO can finally be on the same team. AI is rapidly transforming how mobile applications are built. One emerging approach, often referred to as vibe coding — AI-assisted generation of mobile applications using natural language prompts — is enabling teams to create apps faster than ever before. But speed […]

The Vercel Breach Is a Mobile Supply-Chain Problem, Too

By Jeff Kneis / April 20, 2026 / Comments Off on The Vercel Breach Is a Mobile Supply-Chain Problem, Too

Today Vercel confirmed a security incident but the real risk may not be where most teams are looking. Attackers reportedly pivoted through a compromised OAuth grant at Context AI, took over a Vercel employee’s Google account, and accessed customer API keys, source code and database contents. Vercel has advised customers to rotate anything marked “non-sensitive.” […]

AI Vibe Coding for Mobile Apps: Easy or Secure?

By Jeff Kneis / April 7, 2026 / Comments Off on AI Vibe Coding for Mobile Apps: Easy or Secure?

AI-generated (“vibe coded”) mobile apps can be built in hours but often lack basic security controls like encryption, secure storage and compliance requirements. This blog series outlines the process I went through building my own app capturing key observations and lessons useful for those of us using AI for personal and business use. I am […]

OWASP Mobile Application Security Explained: How to Put MASVS, MASTG and MASWE Into Practice

By Amy Schurr / January 21, 2026 / Comments Off on OWASP Mobile Application Security Explained: How to Put MASVS, MASTG and MASWE Into Practice

OWASP Mobile Application Security provides an industry-recognized foundation for reducing mobile app risk, yet many organizations struggle to apply these standards in day-to-day practice. With multiple resources — the Mobile Application Security Verification Standard (MASVS), the Mobile Application Security Weakness Enumeration (MASWE) and the Mobile Application Security Testing Guide (MASTG) — teams often lack clarity […]

5 Signs You Need a Mobile App Risk Management (MARM) Program

By Amy Schurr / December 31, 2025 / Comments Off on 5 Signs You Need a Mobile App Risk Management (MARM) Program

As mobile apps proliferate throughout the business, the attack surface and regulatory scrutiny expands just as quickly. For CISOs and VPs of AppSec, the question is no longer if mobile app security needs structure; it’s how soon you can adopt one. If your organization’s mobile app security efforts feel reactive, fragmented or manual, it’s time […]

AI Governance for Mobile Apps: How to Secure AI, Data and Compliance and Scale

By NowSecure Marketing / December 15, 2025 / Comments Off on AI Governance for Mobile Apps: How to Secure AI, Data and Compliance and Scale

AI Security in Mobile Apps: The Hidden Threat Multiplying Faster Than You Think Mobile applications have become the primary gateway to enterprise data, customer information and business operations. But there’s a rapidly evolving threat that most organizations are completely blind to: artificial intelligence (AI) embedded throughout their mobile app ecosystem. Recent analysis reveals a startling […]

New NowSecure Research Targets Mobile App Privacy Risks: What You Don’t See Is Hurting You

By Jeff Kneis / September 29, 2025 / Comments Off on New NowSecure Research Targets Mobile App Privacy Risks: What You Don’t See Is Hurting You

Mobile applications power how we live and work, but behind the convenience lies a web of hidden data collection that puts users and enterprises at risk.  Increased user profiling and real-time data harvesting (such as those implicated in the Gravy Analytics incident) has raised the stakes for protecting mobile app users from privacy leaks. Safeguarding […]