2026 Mobile App Risk Management Survey

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
Your Agentic Security Blueprint for iOS 27 Webinar Your Agentic Security Blueprint for iOS 27 Webinar Register Now
magnifying glass icon

Best Practices

Best Practices for Mobile App Pen Testing

By Amy Schurr / June 20, 2019 / Comments Off on Best Practices for Mobile App Pen Testing

Mobile app security professionals who connect and engage with the broader mobile appsec community can amplify their efforts and learn from each other. Combined, the NowSecure services team members have pen tested thousands of mobile apps. They share three key best practices for mobile app pen testing that practitioners can adopt to meet their organizations’ needs.

How to Staff a Strong Mobile AppSec Team

By Amy Schurr / May 29, 2019 / Comments Off on How to Staff a Strong Mobile AppSec Team

Looking to build some mobile application security muscle? Staffing a strong team begins with identifying the right blend of skills and experience and pairing those people with appropriate tools and processes.

Peering Inside the Mobile Attack Surface

By Amy Schurr / May 8, 2019 / Comments Off on Peering Inside the Mobile Attack Surface

With most online traffic shifting to mobile, organizations are at risk of data loss due to risky mobile apps that have security and privacy vulnerabilities. Consult this infographic to see potential threats in mobile app code functionality, data at rest and data in motion and how to identify them with mobile appsec testing.

How to Protect Mobile Apps from MiTM Attacks

By Amy Schurr / May 3, 2019 / Comments Off on How to Protect Mobile Apps from MiTM Attacks

Nearly all mobile apps interact with backend systems and require secure communications. One best practice for developers to safeguard network communications is to implement certificate pinning in their apps. Certificate pinning protects against attackers intercepting sensitive data via man-in-the-middle (MiTM) attacks. Learn more here.

MTD Myths Vs. Reality: What Leaders Need to Know About Mobile App Risk

By NowSecure Marketing / May 1, 2019 / Comments Off on MTD Myths Vs. Reality: What Leaders Need to Know About Mobile App Risk

Although Mobile Threat Defense (MTD) has captured attention from regulated industries and government, it doesn’t provide the price/performance value to justify investment. Here’s why mobile app vetting offers a stronger, cost-effective approach to managing mobile risk.

Q&A: What Is It Like to Be a Mobile App Pen Tester?

By Amy Schurr / April 17, 2019 / Comments Off on Q&A: What Is It Like to Be a Mobile App Pen Tester?

Because NowSecure was founded as a mobile application forensics company a decade ago, penetration testing is built into our DNA. We’ve tested thousands of Android and iOS apps on behalf of our customers, uncovered some scary vulnerabilities and helped customers improve the security of their mobile apps. The following is the third installment of an […]

Deep Link Security: How to Guard Against Mobile App Deep Link Abuse

By Amy Schurr / April 5, 2019 / Comments Off on Deep Link Security: How to Guard Against Mobile App Deep Link Abuse

Mobile app developers often use deep links to improve the user experience and engagement by helping users navigate from the web to their app. However, our security testing has found an easily exploitable vulnerability when deep links are used incorrectly for authorization purposes. This blog will explain how this vulnerability can be exploited and how to safeguard your app by using the more secure version of deep links, App Links.

Detecting Mobile AppSec Testing Vendor Bullsh#t (BS)

By Amy Schurr / January 9, 2019 / Comments Off on Detecting Mobile AppSec Testing Vendor Bullsh#t (BS)

While mobile app security testing is fairly new, we still see a considerable share of BS from vendors. Inspired by a similar DoD document for Agile, we created our own list of crucial capabilities and key questions to ask prospective tool vendors.

DevSecOps Best Practices: Integrating Mobile AppSec Testing Into the Dev Pipeline

By Amy Schurr / December 12, 2018 / Comments Off on DevSecOps Best Practices: Integrating Mobile AppSec Testing Into the Dev Pipeline

As DevSecOps teams incorporate mobile application security testing into the build pipeline, they need the process to be painless. Follow these smart strategies for selecting and implementing an automated testing tool that keeps pace with the mobile app release cycle and helps ensure security, compliance and privacy.

Recognize the Security Risks of Low and No-Code Mobile Apps

By Amy Schurr / December 5, 2018 / Comments Off on Recognize the Security Risks of Low and No-Code Mobile Apps

Popular low or no-code mobile application development platforms empower new ranks of citizen developers. However, the tools can also shortchange application security and must be properly tested before the apps are rolled out. Learn some best practices for safely incorporating these app dev platforms into your organization.