Mobile devices and insider threat investigations: Why access keeps getting harder
Brief
Key takeaways
- Data exfiltration and IP theft and departing employee cases are common enterprise investigations, and mobile devices are increasingly central to how they get resolved.
- Sixty-six percent of DFIR teams report growing mobile device volume, yet 53% can only extract limited data, the top mobile challenge for the third year in a row.
- Consent-based, category-scoped extraction is how DFIR teams get defensible mobile evidence without over-collecting an employee’s personal data.
When a company suspects an employee of taking a trade secret, client list, or product plans to a competitor, that’s an insider threat. These internal investigations often start with laptops and corporate email. Increasingly, the evidence that proves intent lives somewhere else: a bring your own device (BYOD) phone, in a messaging app the company has no visibility into.
