Mobile Device Security for UK Businesses
Smartphones and tablets access business email, Teams, cloud files, and corporate applications — often without the security controls applied to managed laptops. Lost or unmanaged mobile devices are a common source of data breaches, and mobile-targeted attacks are growing rapidly.
Overview
Mobile devices access business data with fewer controls than managed PCs. A lost unencrypted device with business email access may constitute a notifiable GDPR breach. MDM tools like Microsoft Intune enforce screen lock, encryption, and remote wipe centrally. Kaspersky blocked approximately 33 million mobile malware incidents in 2024.
Learn about mobile device managementWhat is mobile device security and what does it cover?
Mobile device security protects the phones and tablets reaching your corporate data, enforcing screen locks, encryption, app controls and remote wipe from a single console. It spans company-owned devices under full management and personal BYOD devices under lighter application-only controls, and sits inside your wider endpoint security programme.
A phone with access to Outlook, OneDrive and Teams holds the same sensitive data as a managed laptop — often with weaker controls. Treating mobiles as a first-class endpoint, not an afterthought, is the core idea.
How does mobile device security work?
It works through two layers: Mobile Device Management (MDM) for company-owned hardware and Mobile Application Management (MAM) for personal devices. Both run on Microsoft Intune, included with Microsoft 365 Business Premium (£16.90 per user/month, ex VAT, per Microsoft UK).
- MDM enrols the whole device — controlling apps, OS updates, password complexity and full remote wipe.
- MAM wraps only the business apps (Outlook, Teams, OneDrive), enforcing app PINs and blocking data leaking into personal apps, without touching personal content.
- Conditional access then checks each device is enrolled and compliant before it reaches Microsoft 365.
Without this, you have no visibility into which devices touch your data and no way to remove business data when a phone is lost or a staff member leaves.
What are the most common mobile threats facing UK businesses?
The biggest mobile threats are phishing, malicious apps, lost or stolen devices, and unsecured Wi-Fi. With 85% of breaches involving phishing (DSIT 2025), mobile is especially exposed because small screens hide sender addresses and shortened URLs, making fraudulent links harder to spot before a user taps.
- Phishing and smishing — SMS, WhatsApp and email attacks that are harder to scrutinise on a phone. See our phishing protection service for layered defence.
- Malicious applications — sideloaded Android apps and rogue store listings that harvest credentials. Kaspersky blocked approximately 33 million mobile malware incidents in 2024.
- Lost and stolen devices — an unencrypted phone holding business email can be a reportable breach under UK GDPR.
- Unsecured Wi-Fi — public networks expose credentials and session tokens to interception.
MDM vs MAM — which do you need for company and BYOD devices?
Use MDM for devices the business owns, and MAM for personal devices staff use for work. MDM gives full control and a complete wipe; MAM protects only business apps and respects personal privacy. Most UK SMEs run both side by side across a mixed fleet.
| Capability | MDM (company-owned) | MAM (personal / BYOD) |
|---|---|---|
| Device enrolment | Full device | App-level only |
| Controls OS updates & passcode | Yes | No |
| Manages business apps | Yes | Yes (Outlook, Teams, OneDrive) |
| Sees personal photos/messages | No | No |
| Wipe scope | Full factory reset | Selective — business data only |
| Best for | Corporate phones & tablets | Employee-owned devices |
On a MAM-enrolled BYOD device, Intune can only see the business apps it manages — never personal app data, photos, messages or browsing history. AMVIA provides clear staff privacy documentation so BYOD enrolment is transparent and adopted without friction.
Why do UK SMEs need mobile device security?
Because mobiles are now a primary attack surface and a primary breach route. According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, and unmanaged phones accessing corporate data widen that exposure.
A lost device with unencrypted business email can trigger a notifiable breach. The ICO expects technical controls — encryption and remote wipe — to mitigate this. The average cost of a data breach for UK organisations was £3.58 million in 2024 (IBM 2024), so a preventable loss carries real financial and reputational weight. The NCSC's device security guidance sets the baseline UK businesses are measured against.
How does conditional access protect mobile devices?
Conditional access requires a device to be enrolled in Intune and compliant before it can open Microsoft 365. A phone with no screen lock, an outdated OS, or one that has been jailbroken is blocked until it meets the standard. Pair this with conditional access policies for a consistent baseline.
This is far stronger than trusting any device that presents valid credentials. It guarantees every device touching your data meets a minimum endpoint standard — whether company-owned or personal — and underpins a zero-trust posture across your mobile estate.
How does remote wipe work and when is it used?
Remote wipe removes business data from a lost, stolen or returned device — a full factory reset for company hardware, or a selective wipe of business apps only for BYOD. It is only effective with a documented procedure, so staff know exactly who to call and the wipe runs within hours, not days.
AMVIA's managed service includes a documented remote-wipe procedure with out-of-hours initiation. Selective wipe is also a core part of leaver offboarding: business data is removed from a personal device on the final day of employment, leaving personal content untouched.
How much does mobile device security cost?
Mobile device security cost depends on device count and licensing. The platform itself, Microsoft Intune, is included in Microsoft 365 Business Premium at £16.90 per user/month (ex VAT, annual) per Microsoft UK — so many SMEs already own the licence and only need it configured and managed.
AMVIA prices the managed layer — enrolment, policy design, compliance reporting and remote-wipe handling — on a per-device basis, scoped to your fleet. Request a free security audit for a fixed quote against your actual device numbers.
How do you build a mobile security programme?
Start by finding every device that touches business data, including unsanctioned personal phones. Then deploy MDM for company devices, MAM for BYOD, conditional access to block non-compliant devices, and a documented remote-wipe procedure. Review it regularly inside your wider security programme.
Only 14% of UK businesses have a formal incident response plan (DSIT 2025), so make sure mobile incidents are written into whatever response procedure you run. AMVIA configures and manages Intune MDM and MAM end to end — enrolment, policy, wipe requests and monthly compliance reporting. Call AMVIA on 0333 733 8050 to discuss your fleet.
Mobile device security checklist
- All devices accessing business data identified — including BYOD
- MDM or MAM deployed — Intune enrolled for company devices, MAM for personal
- Screen lock and storage encryption enforced via policy
- Conditional access blocks non-compliant devices from Microsoft 365
- Remote-wipe procedure documented, with staff briefed on who to call
Key Points
What UK businesses need to know about mobile device security.
Growing Mobile Threat
Kaspersky blocked approximately 33 million mobile malware incidents in 2024. Mobile-targeted phishing via SMS (smishing) and messaging apps is increasing.
MDM Provides Centralised Control
Microsoft Intune (included in M365 Business Premium) enforces security policies on iOS, Android, and Windows Mobile devices from a single management console.
BYOD Needs Careful Handling
Personal devices require Mobile Application Management (MAM) policies — controlling business app data without managing the personal device itself.
Lost Device = Potential Breach
A lost mobile device accessing business email without encryption or remote wipe capability may constitute a notifiable GDPR data breach.
Mobile Device Security Checklist
All devices accessing business data identified — including BYOD
MDM or MAM policies deployed — Intune enrolled for company devices, MAM for personal
Screen lock enforced on all enrolled devices
Device storage encrypted — enforced via MDM policy
Conditional Access blocks non-compliant devices from M365
Remote wipe procedure documented and staff know who to call if device is lost
Frequently Asked Questions
Because phones and tablets read the same email and open the same files as laptops — with 85% of breaches involving phishing (DSIT 2025), the message reads identically on a phone, minus the desktop protections. An unmanaged mobile is an unlocked door into managed data.
Encryption and PINs on every enrolled device, work data separated from personal, app and OS-version rules, and remote wipe for the inevitable losses. Enforced through MDM — policy documents without enforcement are wishes.
Yes — modern management containerises: business email and files live in a managed work profile that IT can control and wipe, while photos, messages and personal apps stay invisible to the company. That separation is what makes BYOD workable for both sides.
Inventory, then enrolment: find every device touching business data (there are always more than expected), enrol them into MDM — Microsoft Intune is included in many M365 plans you may already own — and switch on the baseline policies. AMVIA runs this as part of device management.
Secure Your Business Mobile Fleet
AMVIA deploys and manages mobile device security for UK businesses — enforcing screen lock, encryption, and remote wipe across all devices accessing corporate data.
Related Resources
Mobile Device Management (MDM)
AMVIA's managed MDM service using Microsoft Intune for company-owned and BYOD devices.
Managed IT Support
Extend consistent device management to Windows laptops and desktops alongside mobile — from £25/user/month.
The Complete Cybersecurity Guide
How mobile security fits within a complete cybersecurity strategy for UK SMEs.
Endpoint Security for Remote and Hybrid Workers
Remote worker endpoint security protects company laptops, phones and data wherever staff connect — home broadband, public Wi-Fi or a client site.
Protect your business → Get Cybersecurity Assessment