Opens in a new tab
vmblog logo 2024 wht (updated)

Black Hat USA 2023 Q&A: Zimperium Will Showcase Its Mobile-First Security Platform, Delivering Unmatched Security Across Both Applications and Devices

Share: 

David Marshall | Published: July 25, 2023

 

Are you getting ready for the upcoming Black Hat USA 2023 event, an internationally recognized cybersecurity event providing the most technical and relevant information security research, now in its 26th year.  The event is quickly approaching, taking place August 5-10, 2023, returning to the Mandalay Bay Convention Center in Las Vegas, NV with a 6-day program. 

Ahead of the show, VMblog received an exclusive interview with JT Keating, SVP Strategic Initiatives at Zimperium, which enables companies to realize the full potential of mobile-powered business by activating a Mobile-First Security Strategy.  You’re going to want to get them on your MUST SEE list.

zimperium-logo
 

VMblog:  Before we get into it, can you give us a quick overview of the company? What should folks know?

JT Keating:  Zimperium enables companies to realize the full potential of mobile-powered business by activating a Mobile-First Security Strategy. We have seen an explosive growth of mobile device and app usage as well as a spike in bring your own device (BYOD) in the workplace over the past few years, resulting in a larger-than-ever attack surface. This rise of the mobile-powered business has fundamental implications for security teams. For example, losses from online payment fraud cost e-commerce businesses $41 billion in 2022 and are expected to grow to $48 billion in 2023.

Built for the demands of mobile business, Zimperium’s Mobile-First Security PlatformTM delivers unmatched security across both applications and devices. We deliver autonomous mobile security that dynamically adapts to changing environments so companies can capitalize on the new world of mobile-powered opportunities, securely.  

VMblog:  You are sponsoring the upcoming Black Hat USA event.  How can attendees find you at the show?  Does your booth have a theme?  How many folks are you sending?

Keating:  Zimperium will also be onsite at Black Hat in Las Vegas from August 8 – 10, and everyone is encouraged to visit our booth #2514. We will have theater presentations throughout the day each day as well as demos highlighting our platform and its new features.

VMblog:  The show is focused on cybersecurity.  What specific problems is your company and technology addressing?

Keating:  We are facing a quiet revolution across global business. The center of gravity for work and commerce has shifted to mobile devices. The pandemic, which led to a distributed, remote workforce almost overnight, pushed this revolution forward even faster. On the one hand, mobile has made it easier for employees to collaborate more tightly with more people while also making it easier to access higher volumes of data to drive productivity. At the same time, mobile experiences have become the consumer norm. Developers are meeting the demand by building more sophisticated apps, creating seamless ecosystems of higher value services, experiences and data.

On the other hand, the result of this revolution is that organizations are now required to protect each one of their mobile endpoints on the edge, rather than solely focusing on a central, on-prem infrastructure. There is an increase in unmanaged devices, mobile threats, explosion of apps, continuous innovation and regulations while resources remain flat, making it difficult for companies to keep up. As a result, companies are operating in uncontrolled environments with blind spots and exposure points.

Apps can be reverse engineered and developers have to account for the apps operating in hostile environments and still comply with regulatory and privacy laws. Developers are also stuck between wanting to secure apps but also meeting release velocity goals. Zimperium’s Mobile-First Security Platform closes the vulnerability gap and eliminates these tradeoffs, by securing a mobile-powered business.

  • Centralized management and access to device and app security through a single interface on any cloud and on-premises.
  • Protection for all devices against critical mobile threats such as phishing, spyware, and rogue networks.
  • Privacy-by-design to protect employee privacy on both corporate and BYOD devices as they work from anywhere, anytime.
  • Pervasive risk management for apps to find risks in apps you develop and third-party apps used by employees.
  • Advanced in-app protection to prevent reverse engineering, protect cryptographic keys, and create self-defending apps.
  • An enhanced mobile ecosystem with enterprise integrations including SIEMS, IAM, XDR, DevOps workflows, ticketing systems, GitHub action and, fraud systems.
  • Deep forensics and enhanced search capabilities to enable advanced threat hunting.

Zimperium is hard at work to continuously meet customers’ mobile security challenges as they implement mobile-powered initiatives.

VMblog:  The market is a crowded space.  What is it about your company and technology that sets you apart from the competition?  What are your differentiators?

Keating:  One of our key differentiators is that Zimperium is born for mobile security. Our unique on-device architecture approach detects and mitigates risks even when a device is not connected to a network, while delivering an optimal experience to users. Since no personal data goes to the cloud, companies can eliminate risk while respecting the personal and professional nature of mobile. Zimperium works with your existing ecosystem by seamlessly integrating with your Mobile Device Management, Security Operations Center and DecSecOps processes.

Zimperium also delivers security across every dimension, with unmatched breadth and depth enabling organizations to secure all mobile devices (managed/unmanaged, online/offline) and all mobile apps (developed by their organization or others). Our Mobile-First Security Platform works across the full app lifecycle, enabling developers to infuse apps with synergistic security capabilities from development to runtime, from within their existing environment, without disrupting existing processes and with the broadest range of cryptography, key signing and encryption.

We are also harnessing the power of machine learning within our engine that uses billions of data points to understand mobile risks and threats, allowing our customers to adapt their security posture dynamically. By continuously correlating data from multiple sources – from malware to data manipulation instances – to understand where risk lies, Zimperium keeps organizations up-to-date and secure from threats. Our ML-powered detection meets the needs of the modern workforce, securing devices against even the most advanced threats and helps customers build resilience so that they can focus on growing their enterprise.

VMblog:  What are some of the security best practices you would deem critical?

Keating:  At Zimperium, our team of researchers and security experts have developed five security principles of a mobile-first strategy, built from over decades of experience. These principles will lead to a complete, scalable, and effective mobile-first security strategy: 

  • Prioritize and assess risk as close to the user or point of entry as possible. Organizations need to prioritize securing mobile-powered business initiatives across all mobile devices and apps.
  • Operate in a known state – visibility and vulnerability assessment for all your entry points. Gain complete visibility of your mobile ecosystem and risk level. Automatically assess vulnerabilities and address them-without throttling productivity. Establish safeguards that are measurable, auditable, and insurable.
  • Enhance your detection and response strategy for mobile. Detect anomalies and prioritize remediations based on contextual intelligence-so the most critical gaps get addressed first. Embed security across the device and application lifecycle, provide risk- based response, and enable zero trust assessment of mobile endpoints.
  • Start the autonomous journey. Dynamically respond to ever-changing threats and mobile ecosystems. Automatically isolate compromised devices and untrusted environments. Establish a proactive, resilient, and scalable security posture.
  • Minimize risk compliance failures. Stay ahead of regulations, data sovereignty and privacy standards, while respecting employees’ work/life boundaries.

VMblog:  What are some of the top priorities you believe attendees at Black Hat should be considering for 2023/2024?

Keating:  Earlier this year, we launched our annual Global Mobile Threat Report, which revealed a continued growth toward mobile-powered business along with the increasingly sophisticated security risks facing it, including spyware, phishing, and ransomware. One of the key findings was that 43% of all compromised devices were fully exploited (not jailbroken or rooted), which is an increase of 187% year-over-year. 

A top-of-mind priority for Black Hat attendees should be how they can capitalize on mobile-powered business without leaving vulnerability gaps dangerously exposed. Security professionals at organizations looking to fully harness the power of mobile devices should build a mobile-first security strategy, prioritizing and assessing risk as close to the user and device as possible.

I would encourage attendees to learn how they can improve risk detection capabilities at their organizations by leveraging zero trust, XDR, 3rd party integrations and by staying on top of global privacy regulations that impact the apps they are developing and using.

##