2026 Mobile App Risk Management Survey

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
Your Agentic Security Blueprint for iOS 27 Webinar Your Agentic Security Blueprint for iOS 27 Webinar Register Now
magnifying glass icon

Best Practices

From Patient Safety to Data Privacy: Mobile App Risk Management Strategies for Healthtech Leaders

By Amy Schurr / September 3, 2025 / Comments Off on From Patient Safety to Data Privacy: Mobile App Risk Management Strategies for Healthtech Leaders

mHealth and healthtech apps connect people directly to care. Whether linking patients to life-sustaining medical devices or delivering essential health insurance services, mobile apps carry high stakes. A single flaw can compromise patient safety, expose sensitive data or erode trust. This summer, Garrett Schumacher of Velentium Medical joined NowSecure CEO Alan Snyder to discuss his approach […]

Why I Don’t Trust My Kids’ Apps – The Hidden Mobile Privacy Risks Parents Should Know

By Jeff Kneis / July 30, 2025 / Comments Off on Why I Don’t Trust My Kids’ Apps – The Hidden Mobile Privacy Risks Parents Should Know

We’re in an era where parents like me have grown up with smartphones. My parents, as much as I loved them, were what we would refer to as ‘technologically challenged’.  I often had to help them navigate the digital world, teaching them how to spot phishing emails or PayPal scams.  Now, as a parent myself, […]

Top 3 Defense-in-Depth Security Controls to Protect APIs Against Attacks

By Tim Neighbors / July 2, 2025 / Comments Off on Top 3 Defense-in-Depth Security Controls to Protect APIs Against Attacks

Adding robust security controls to your API can significantly improve your mobile application’s security posture. These defenses increase resilience to attacks by raising the barrier for anyone attempting to probe or manipulate your API. This applies to both mobile and web applications. In this blog, we’ll highlight three key controls that can help reduce API […]

How Dangerous Mobile App Permissions Threaten Enterprise Security

By Amy Schurr / June 4, 2025 / Comments Off on How Dangerous Mobile App Permissions Threaten Enterprise Security

Mobile apps often request more access than they need, exposing businesses to unnecessary risk. Dangerous permissions let Android apps tap into sensitive user data and device functions such as reading messages, recording audio, accessing stored files or tracking real-time location. On iOS, dangerous entitlements grant apps elevated privileges that can bypass built-in security controls and […]

OTT App Security: What Streaming Developers Must Know in 2025

By Tim Neighbors / May 14, 2025 / Comments Off on OTT App Security: What Streaming Developers Must Know in 2025

The global over-the-top (OTT) streaming market is projected to reach $343 billion in 2025, growing annually by 6.56%. Revenue from Advertising Video-on-Demand (AVoD) alone is expected to hit $54.54 billion, showcasing the substantial opportunities in this booming market. However, this rapid growth presents significant mobile app security and privacy challenges.  As OTT apps handle vast […]

525,600 Assessments Later — Top Mobile App Risks Since 2022

By Amy Schurr / April 30, 2025 / Comments Off on 525,600 Assessments Later — Top Mobile App Risks Since 2022

Every smartphone in the world today is a potential spy equipped with more than 18 sensors like GPS, accelerometer, gyroscope and microphone that can be weaponized by cyberattackers who take advantage of poorly secured mobile apps. With more than 7.2 billion smartphones in use and 255 billion app downloads in 2023 alone, the global mobile […]

PTaaS for Mobile Apps: The Scalable Alternative to Traditional Penetration Testing

By Tim Neighbors / April 9, 2025 / Comments Off on PTaaS for Mobile Apps: The Scalable Alternative to Traditional Penetration Testing

Traditional penetration testing wasn’t built for today’s mobile release cycles. Annual, semi-annual or even quarterly pen tests don’t cut it anymore. If your mobile app updates weekly, that’s a dozen untested versions before your next scheduled assessment. That’s a dozen chances for a data leak or privacy flaw to slip through. Mobile Penetration Testing as […]

Why Stolen Credentials Are the #1 Threat to Mobile Security

By Tim Neighbors / March 12, 2025 / Comments Off on Why Stolen Credentials Are the #1 Threat to Mobile Security

“Cybercriminals are increasingly logging in rather than hacking into networks through valid accounts.”— IBM Security X-Force Threat Index 2024 “The use of stolen credentials remains the primary way into organizations, with 40% of breaches involving credentials as the top ‘action’ to entry taken.”— Verizon 2024 Data Breach Investigations Report In popular imagination, hackers navigate complex […]

Know Your SDKs: Protect Your Mobile Apps and Users from Hidden Risks

By Andrew Hoog / January 22, 2025 / Comments Off on Know Your SDKs: Protect Your Mobile Apps and Users from Hidden Risks

The Hidden Risks in Mobile SDKs Many app developers are unaware of the potential misuse of their platforms for unauthorized data collection, especially through advertising networks embedded in Software Development Kits (SDKs) in their app’s supply chain. These hidden risks can lead to: By integrating third-party SDKs without proper vetting, developers may unknowingly introduce vulnerabilities […]

Reversing iOS System Libraries Using Radare2: A Deep Dive into Dyld Cache (Part 3)

By Tim Neighbors / September 13, 2024 / Comments Off on Reversing iOS System Libraries Using Radare2: A Deep Dive into Dyld Cache (Part 3)

Welcome to the final blog post in our series about reverse engineering iOS system libraries with radare2. This time we’ll focus on finding cross-references across different libraries present in the dyld shared library cache (or DSC if you’re into acronyms). We’ll discuss various techniques to achieve this, each with its trade-offs between performance and amount […]