Mobile devices: is your favorite app still trustworthy?
We install an app on our phone or tablet. It comes from Apple’s App Store or Google Play, sometimes has millions of users, has excellent ratings and has been around for several years. We use it regularly, it works well, and nothing in its behavior seems particularly worrying. Gradually, its presence becomes so familiar that we practically stop thinking about it.
Yet taking it for granted is a much bigger cybersecurity and privacy issue than it appears. A mobile app is not an immutable object. It receives updates, its code evolves, new features appear, its libraries change, its technology partners can be replaced, its data collection practices can evolve, and the company that owns it can itself be acquired. Meanwhile, the trust we granted it at the time of installation can remain practically intact for years.
Apple and Google impose significant rules on apps distributed on their platforms. Permissions, data declarations, isolation mechanisms, update control and the policies governing developers genuinely reduce several categories of risk. These mechanisms do not, however, constitute a permanent guarantee that an app’s risk profile will remain identical throughout its lifetime.
For executives and cybersecurity leaders, the question should therefore no longer be only whether an app comes from an official source. We must also ask whether the app we judged acceptable yesterday still represents an acceptable risk today. This is precisely where cyber vigilance becomes fundamental.
The smartphone is probably one of the most intimate computers we have ever created. It accompanies us almost continuously and concentrates a considerable amount of information about our personal and professional lives. Depending on the permissions granted and the features used, various apps can access location, photos, contacts, the camera, the microphone and a range of information related to the device and its use. Fortunately, iOS and Android have significant mechanisms for limiting this access. Apps are isolated from one another, and different categories of information require specific permissions. An app therefore generally cannot arbitrarily browse the entire contents of a phone simply because its publisher would like to.
The real problem appears over time. The user grants various permissions because they seem necessary or convenient. One app requests location in order to offer a particular feature, another wants access to photos, a third uses contacts, and others incorporate analytics, advertising or various services from technology partners. Each of these decisions may be perfectly reasonable when it is made. A few years later, however, how many users remember precisely the permissions granted to the dozens of apps on their device? Cyber vigilance therefore begins with a simple idea: a permission granted in the past should not automatically become a forgotten permission for the future.
This consideration becomes even more important when we look at how the apps themselves evolve. An app downloaded today may receive dozens of updates over the coming years. New features are added, SDKs are integrated or replaced, analytics mechanisms evolve, and the publisher’s business practices can change. Declarations concerning the collection and use of data can also be modified as the product evolves. Apple and Google impose obligations on developers regarding the declaration of data collected, its use, its sharing and certain permissions. These requirements establish an important accountability framework and allow the platforms to intervene when an app does not comply with their policies, but they do not replace each organization’s own risk analysis.
An app can thus comply with an app store’s general rules while presenting a data collection model incompatible with the specific requirements of a bank, a government department, a laboratory, a pharmaceutical company, a manufacturer holding strategic intellectual property or an organization in the defense sector. Compliance with a platform’s rules and the acceptability of the risk for an organization are two different assessments. This distinction is particularly important because an app does not need to be malicious to constitute a privacy risk. It may do exactly what it says, use the permissions granted and communicate with legitimate technology partners, while the volume, nature or combination of the information collected goes beyond what an organization considers acceptable for a person who also has access to its sensitive information.
A change in an app’s ownership makes it possible to take this line of thinking even further. A popular app is not just a software product. It has a user community, a reputation, ratings, usage habits and a trust relationship sometimes built over several years. All of that has commercial value. When an app is acquired, the user generally continues to see the same icon and may keep the same habits and the same perception of the product, even though the organization that develops it, its business objectives, its partners and its strategy have changed.
Here we discover a deeply human weakness in digital security: our trust often has an inertia that technology does not. We assess something at a given moment and then go on living with that decision, even when what we assessed has been transformed. It is not even necessary to imagine a malicious scenario. An acquisition can be perfectly legitimate, and the new owner may simply be seeking to develop the product further and better monetize its user base. New features appear, some require new permissions, technology partners are added and privacy policies evolve. At each of these stages, the control mechanisms may have worked exactly as intended, while a few years later the app’s risk profile has become very different from the one that existed when it was installed.
This reality challenges a still very widespread conception of digital trust. We tend to treat it as a binary decision: trustworthy or not trustworthy. In a technology environment that is continuously evolving, trust should instead have a life cycle. This idea connects directly to the principles of Zero Trust. An authenticated identity does not automatically receive access to all resources, a known device is not necessarily considered secure on a permanent basis, and a connection coming from the internal network is not on its own sufficient proof of trust. The same philosophy can progressively be applied to apps.
An organization must therefore be able to know who owns an app today, which permissions it actually uses, which SDKs it contains, which services it communicates with, in which jurisdictions the data is processed and what has changed since its last assessment. It must also be able to determine whether a permission granted three years ago is still necessary and whether current practices still match the level of risk it accepts. Cyber vigilance consists precisely in keeping these questions alive rather than assuming that a trust decision made in the past automatically remains valid.
The problem becomes particularly interesting when personal and professional environments meet on the same device. An executive’s phone may contain weather, travel, social networking, photography, navigation, messaging and entertainment apps. The same device may also provide access to work email, internal documents, collaboration platforms and various corporate cloud services. The phone then becomes the meeting point between two ecosystems governed very differently.
The organization controls its internal systems. It chooses its suppliers, defines its security policies, manages its identities and determines the conditions of access to its resources. It has far less control over the technological and commercial decisions made by the dozens of publishers whose apps may reside on an employee’s personal phone. This obviously does not mean that each of these apps can access corporate data. The isolation mechanisms of iOS and Android, along with mobility management technologies, make it possible to establish significant separations. The real issue for the company consists rather in determining under what conditions a device belonging to this personal ecosystem can access its own assets.
This distinction is essential because it makes it possible to reconcile security and respect for privacy. An organization does not need to needlessly monitor the whole of an employee’s digital life in order to protect its information. It must above all control the conditions of access to its own systems and adapt those conditions to the sensitivity of the resources concerned. Some information may be accessible from a suitably protected personal device, other information may require a managed corporate environment, and certain particularly sensitive functions may warrant using a corporate device whose apps, configurations and access are far more strictly controlled.
This approach brings mobility back into the overall risk architecture rather than treating it as an isolated problem. It also makes it possible to broaden the notion of cyber vigilance, which can no longer be limited to an annual campaign reminding employees to beware of suspicious links. It becomes an organizational capability consisting of knowing the assets, monitoring changes, reassessing permissions, understanding dependencies, verifying behaviors and adapting trust decisions as the environment evolves.
This vigilance becomes even more important when we consider the real value of the data collected. Seemingly innocuous information can acquire great value when combined with other information. Location, travel habits, contacts, hours of activity, devices used, metadata and various behavioral signals can together reveal far more than each of these pieces of information taken individually. Artificial intelligence considerably amplifies this reality, since the ability to correlate and analyze large quantities of data now makes it possible to uncover relationships and produce inferences that would once have required far more time and resources.
The question is therefore no longer solely whether a particular piece of data is secret. We must also consider what becomes possible to infer when that data is combined with thousands of other signals. For an organization, confidentiality then goes beyond protecting documents identified as confidential. It also concerns the behaviors, relationships, metadata and contexts that can indirectly reveal strategic information.
Here we enter territory where Hypersecurity usefully broadens the discussion without distorting the role of cybersecurity. Cybersecurity remains essential for protecting devices, applications, identities, data and communications. Hypersecurity adds a cross-functional view that makes it possible to consider their interactions, their dependencies, their evolution and the way trust must be continuously reassessed. From this perspective, trust is never permanent: it is continuously earned, verified and reassessed.
An app can be considered acceptable today and go on being acceptable for ten years. The objective is not to constantly suspect every supplier, but to have the mechanisms needed to detect the changes that warrant a new analysis. This distinction is important, since cyber vigilance is not based on generalized distrust. It is based on the permanent ability to verify.
This approach also makes it possible to better define the role of internal teams and complementary expertise. IT and cybersecurity professionals know their environments and their users deeply. They must, however, simultaneously manage infrastructure, identities, incidents, updates, vulnerabilities, cloud services, suppliers and a growing number of devices and applications. The permanent evolution of this environment makes a cross-functional view capable of examining the relationships among these different components particularly useful.
Quantum Beyond can work alongside these teams by bringing this additional layer of analysis and cyber vigilance. Devices, applications, identities, permissions, data flows and dependencies can be examined as components of a single architecture. Zero Trust and Continuous Trust make it possible to reduce implicit trust, IAM makes it possible to control access, data governance helps determine which information can be used from which environments, segmentation limits the potential consequences of a compromise, dependency analysis reveals certain less visible paths of exposure, and cyber resilience prepares the organization for the scenario in which one of its trust assumptions turns out to be false.
This approach connects directly to the logic of Hypersecurity: continuously protecting systems, data, identities, knowledge and operations in a distributed digital environment that is permanently evolving. The mobile phone then becomes one element among others in a much larger architecture encompassing the cloud, SaaS services, the Edge, IoT, artificial intelligence, applications, suppliers and human or non-human identities.
A modern organization cannot reasonably control every decision made by every player in this ecosystem. It can, however, design its architecture so that a change at one of them does not automatically transform its own level of risk without its being able to detect it. This is probably one of the most important principles of cyber vigilance: accepting that the environment will change and building the means needed to know when that change calls for a new decision.
Official app stores play an essential role in the mobile ecosystem. Apple and Google impose rules, govern permissions, review apps and their updates, and can remove software that breaches their policies. These mechanisms genuinely reduce several categories of risk and are an important component of mobile security. They cannot, however, offer a company or a government organization a permanent guarantee about the future evolution of each app and each company that owns it.
An app can remain legitimate, popular and widely used for years while evolving considerably. Its owner can change, its business model can be modified, new technology partners can appear, its features can expand, new permissions can be requested and new data flows created. Throughout that time, the user continues to see the same icon on their phone and to grant it trust that was sometimes built several years earlier.
That is why cyber vigilance must become a permanent component of digital security and privacy. The trust granted at the time of installation represents a decision made in a specific context. When the context changes, that decision must be open to reassessment. For companies and government organizations, this responsibility extends well beyond the phone itself. It concerns the information the device provides access to, the identities it carries, the applications it interacts with and the relationships it establishes with the entire digital ecosystem.
Quantum Beyond can support internal teams in this work by bringing together Hypersecurity architecture, Zero Trust and Continuous Trust, IAM, data governance, dependency analysis, segmentation, cyber resilience and continuous risk assessment. This perspective makes it possible to regularly challenge trust assumptions as the environment evolves, while maintaining an approach proportionate to the organization’s real needs.
Cyber vigilance ultimately rests on an extremely simple idea. An app that was trustworthy yesterday may well still be trustworthy today. Maturity consists in making sure that this trust does not depend solely on a decision made several years earlier. What was trustworthy yesterday may therefore still be trustworthy today, but in cybersecurity, above all we must keep the means to verify it.
