Mobile Device Build
Review
Configuration hardening review of corporate mobile device builds, and MDM/UEM policy sets across iOS and Android — focused on device-level security posture and enrolment policy, distinct from mobile application testing.
Corporate mobile fleets carry the same sensitive data as any managed endpoint, but the security review often stops at "is MDM enrolled?". Enrolment alone does not tell you whether encryption is enforced, whether compromised devices are actually blocked from accessing corporate resources, or whether BYOD containerisation is properly isolated.
Our mobile device build reviews assess device-level configuration and MDM/UEM policy sets, across iOS/iPadOS and Android against best security practices such as CIS benchmarks and NCSC/NIST mobile device guidance — covering encryption enforcement, passcode policy, app allow/deny lists, and OS update compliance.
This is a device configuration review, not an application penetration test — we assess the platform and policy surrounding managed devices; app-level testing is covered separately under our Mobile Application Testing service.
Scope & Baseline Selection
Agreement on device ownership model in scope — corporate-owned, BYOD, or COPE — enrolment type, and the applicable benchmarks.
Policy & Configuration Extraction
Review of MDM/UEM policy sets, compliance policies, and configuration profiles exported from the management console.
Automated benchmark Analysis
Comparison against CIS mobile benchmarks across encryption enforcement, passcode policy, application allow/deny lists, and OS update compliance.
Manual Review & Contextualisation
Review of conditional access integration, jailbreak/root detection, containerisation boundary for BYOD devices, and MDM enrolment security.
Risk Prioritisation
Findings ranked by potential to enable data exfiltration from managed applications, bypass compliance-based conditional access, or allow persistence on a compromised device.
Remediation Guidance & Delivery
Custom guidance (including where appropriate, configuration profiles or policy JSON) delivered alongside a prioritised fix list.
We assess whether MDM enrolment actually translates into enforced security posture — the gap between "enrolled" and "compliant" is where most mobile fleet exposure sits.
Findings are delivered with practical MDM/UEM configuration guidance and commands where applicable, so remediation can be implemented without rebuilding profiles from scratch.