Forrester's framing of why this category exists rests on an analogy worth taking seriously.
Like early desktop PCs, the security of mobile devices was left to the operating system manufacturers, and just as with desktops, that is no longer an adequate line of defence. The idea that mobile operating systems are inherently secure and that applications from the official stores are perfectly safe has been debunked, with documented compromises on both platforms and malicious applications appearing in both stores.
That is the same arc desktop security ran through in the 1990s. Security was assumed to be Microsoft's problem until it obviously was not, and an entire endpoint security industry emerged from the correction.
Mobile is running that arc twenty years later, and the reason it lagged is more interesting than the threat comparison.
The endpoint nobody controls
Enterprise endpoint security assumes the enterprise owns the endpoint. It can install what it likes, see what it wants, and remove what it disapproves of, because the laptop belongs to the company.
Mobile broke that assumption, and Forrester notes that half of organisations operate bring-your-own-device smartphone policies.
A personal phone contains the employee's messages, photographs, location history, health data, banking applications, and their family's information. The organisation has a legitimate interest in the corporate data on it and very limited standing over everything else.
That is why mobile security lagged, and it was never primarily about the threat being smaller. It was that the control model that works for laptops does not transfer to a device the enterprise does not own.
Every difficulty in this category descends from that. Agent deployment is negotiated rather than mandated. Visibility is constrained by what the employee will accept. Enforcement actions that would be routine on a corporate laptop, wiping the device, blocking an application, restricting a network, are considerably more fraught on a personal phone.
Inside The Forrester Wave: Mobile Threat Defense Solutions, Q3 2024
Published on 16 July 2024 and authored by senior analyst Paddy Harrington with Merritt Maxim, Angela Lozada, and Christine Turley, this was Forrester's first ever evaluation of the market, scoring eleven providers against twenty two criteria: BlackBerry, Broadcom, Check Point, ESET, IBM, Jamf, Lookout, Pradeo, Sophos, Trend Micro, and Zimperium.
Four were named Leaders.
Zimperium placed as a Leader with the highest possible score in seventeen criteria and the highest marks in both the strategy and current offering categories.
Check Point placed as a Leader, with Forrester crediting Harmony Mobile for mobile application protection, network defence, and vulnerability mitigation.
Pradeo's assessment is the one most relevant to a European reader. Forrester described its offering as allowing the deepest configuration seen in the evaluation, and positioned it specifically for European-based customers looking for a very flexible mobile threat detection solution.
Configuration depth being singled out alongside a European recommendation is not a coincidence, and the reason connects directly to the privacy question below.
Forrester's preceding Landscape report, published in Q1 2024, contained a forward-looking observation worth carrying: the regulatory environment is ready to force transformations on the mobile security market.
Two platforms, two levels of visibility
The asymmetry between the mobile operating systems is the most consequential technical fact in this category and it is underexplained in vendor material.
Forrester touches it directly, referring to Apple's approach as security through obscurity, and noting that whatever the operating system vendors do, attackers will find ways in.
The practical consequence is that a security agent on Android can see substantially more than the same vendor's agent on iOS. Android permits deeper inspection of applications, processes, and system state. iOS restricts what any third-party application can observe about the rest of the device, including security software, on the reasoning that an application capable of inspecting everything is itself an attack surface.
That is a defensible design decision and it means iOS mobile threat defence works differently. It leans more heavily on network-level detection, on analysing applications before installation rather than watching them at runtime, on device attestation and configuration checks, and on what the management framework exposes.
For a buyer this matters in a specific way. A vendor's demonstration on Android may not represent what you get on iOS, and in most enterprises the executive population runs iPhones. Asking for the capability matrix split by platform is a reasonable request and a revealing one.
The privacy problem is the deployment problem
An agent on a personal phone that inspects applications, monitors network connections, and reports device state is, described neutrally, monitoring software on private property.
That framing is not hostile. It is how the employee will understand it, and it is how a works council will understand it.
In several European jurisdictions, including the Netherlands and Germany, deploying monitoring capability to employee devices brings formal consultation obligations. Under GDPR, processing personal data from an employee's own device requires a lawful basis, and the balancing test for legitimate interest is harder when the device is not the employer's and the data includes the employee's private life.
That explains why configuration depth matters enough for Forrester to single it out. A platform that lets an organisation precisely define what is inspected, what is reported, what is retained, and what is explicitly never collected can be deployed under a policy the workforce and their representatives will accept. One with a single monitoring posture cannot.
The technical mechanism most vendors use is separation: the agent evaluates threats locally on the device and reports only security verdicts rather than the underlying data. An application is scanned on the phone and the server learns that a risky application was found, not the full inventory of what the employee has installed.
Whether that separation is real, and demonstrable, is worth verifying rather than accepting. It is the difference between a deployable programme and one that stalls in consultation.
There is a second-order effect that follows. Where enrolment is voluntary in practice, an intrusive deployment produces low adoption, and low adoption means the population most likely to be targeted is the population least likely to be protected. A less capable agent on every device usually beats a comprehensive agent on forty percent of them.
What these platforms actually detect
Forrester's own framing is that mobile threat defence goes far beyond mobile antivirus, bringing endpoint-grade protection and analytics to mobile devices, and analysing application components and actions against organisational standards.
Four detection categories cover most of it.
Application risk, meaning analysing what an application actually does rather than whether it is known malware. Excessive permissions, undisclosed data transmission, embedded advertising libraries, and communication with servers in unexpected jurisdictions are all risks without being malicious in the traditional sense.
Network threats, including hostile wireless networks, interception attempts, and certificate manipulation. Mobile devices connect to networks nobody vetted, constantly.
Device integrity, covering jailbreaking and rooting, whether deliberate or the result of a compromise, and configuration weakness including outdated operating system versions.
And phishing, which is where the actual volume is.
Mobile is where the phishing lands
The strategic case for this category is less about malware than about the device being the primary target for social engineering.
Several factors make mobile the preferred delivery vector. The screen is small, so inspecting a link or a sender address requires deliberate effort. Messages arrive across channels the enterprise does not filter, including text, messaging applications, and social platforms, rather than only through corporate email where the security stack sits. Users act faster on phones, frequently while doing something else. And the device is where multi-factor authentication approvals happen.
That last point is the one that matters most. A phone that can be manipulated into approving an authentication prompt is a phone that defeats the control most organisations rely on to protect everything else.
Which reframes what mobile threat defence protects. It is not primarily protecting the phone. It is protecting the identity that the phone authenticates, and through it the systems that identity can reach.
That connects this category to workforce identity security and to the broader argument that identity became the primary attack surface. The mobile device is where a substantial share of identity compromise now begins.
Where this leaves a buyer
The first Forrester Wave in a market usually indicates the category has become a standard purchase rather than a specialist one, and eleven providers with four Leaders describes a competitive field rather than a settled one.
Three questions decide more than the tier.
What proportion of your mobile estate is personally owned, because that determines whether you are running a deployment programme or a negotiation. If it is majority BYOD, weight configurability and privacy separation heavily, and expect the works council conversation to shape the specification.
What the platform actually sees on iOS specifically, since that is where the visibility constraint bites and where your most-targeted users probably are.
And what happens when a threat is detected on a personal device. Blocking a malicious application is uncontroversial. Restricting access to corporate resources is defensible. Anything approaching device-level enforcement on property the organisation does not own needs a policy position established before the first incident rather than during it.
The category has taken an unusually long time to become a standard control, and the reason was never that the threat was unclear. It was that the obvious security response ran into a legitimate objection, and the vendors that solved for the objection rather than around it are the ones with deployments that actually cover the estate.
Analyst Source
Forrester Research
Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of mobile threat defense. The Q3 2024 Wave, authored by senior analyst Paddy Harrington with Merritt Maxim, Angela Lozada, and Christine Turley, was Forrester's first evaluation of this market, scoring 11 providers against 22 criteria and drawing on customer reference interviews, executive briefings, and vendor demonstrations. It followed The Mobile Threat Defense Solutions Landscape, Q1 2024.
Source research
- The Forrester Wave: Mobile Threat Defense Solutions, Q3 2024
- Announcing The Forrester Wave: Mobile Threat Defense Solutions, Q3 2024
- The Mobile Threat Defense Solutions Landscape, Q1 2024
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.