APAC CIOOutlook
About UsConferencePartner With Us
  • Technologies
    • Blockchain
      Data Intelligence and Management
      Digital Transformation
      FinTech
      Generative and Agentic AI
      Low Code No Code
      Mobile Application
      Networking
      Robotics
      Storage
      Wireless
  • Industries
    • Automotive
      Aviation
      Banking
      Construction
      E-Commerce
      Food and Beverages
      Healthcare
      Insurance
      Logistics
      Manufacturing
      Retail
      Supply Chain
      Travel and Hospitality
  • Platforms
    • Microsoft
      Salesforce
      SAP
  • Strategic Solutions
    • Business Intelligence
      Contact Center
      Corporate Finance
      CRM
      Cyber Security
      Data Center
      Enterprise Asset Management
      Enterprise Performance Management
      IT Infrastructure and Services
      Managed Services
      Procurement
      Unified Communication
      Workflow
  • Home
  • CXO Insights
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • Whitepapers
  • CXO Awards
#

Apac CIOOutlook Weekly Brief

×

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

Subscribe

loading

THANK YOU FOR SUBSCRIBING

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Zephyr

Sanjay Zalavadia, VP of Client Services

Mobile Application Security Testing: The Unique Characteristics of Device Security Models

Sanjay Zalavadia

Sanjay Zalavadia

Smartphones, tablets, and wearables have all led to changes in how businesses operate and how consum­ers are kept connected to their favourite organizations. How­ever, workers cannot simply use just any application; software often must undergo stringent evaluations to en­sure that it meets employee needs and has the protections to keep com­pany data safe. As more businesses approve of bring-your-own-device policies, quality assurance teams must leverage mobile app development se­curity testing techniques while under­standing the unique needs of device security models.

Security Importance on the Rise

Although computers are still a main target for hackers, mobile devices are increasingly experiencing their share of attacks. Application security has become such a priority for orga­nizations that the market is expected to grow to $6.77 billion by 2021, tri­pling its current estimate, according to predictions from MarketsandMar­kets. The report noted that the surge of breaches aimed at applications is a primary driver for the market's rapid development. This makes sense, es­pecially since malicious programs are already in app stores just waiting to be downloaded.

Google Play, in particular, has been a victim of numerous apps tar­geted to release malware and access user data. TechTarget contributor Eric Beehler noted that Google's open for­mat and lack of safety oversight has caused many problems for users and can mean trouble when exposing busi­ness information. Although improve­ments are constantly being made to avoid these incidents, companies must test applications themselves to ensure that they are safe for employees to work with.

“All it takes to access the data stored on an unlocked smartphone running a poorly written app is a sim­ple extraction of the file attached to the mobile application, then a query,” Beehler wrote. “This action can tell you anything you want to know about the data stored in that app, which is especially troublesome if the data­base connects to a back end system. Because of these mobile application vulnerabilities, sensitive data should be encrypted at the device level, and external connections should be en­crypted as well.”

Taking Stock of Device Security Capabilities

Rather than relying on providers to en­sure that apps are safe, organizations have to test out the programs them­selves as well as make use of security testing tools to protect employees and business data. TechTarget contribu­tor Dan Cornell noted that there are a few testing types that these solutions should address: static, dynamic, and forensic. These approaches will ex­amine code at rest, the behaviour of running systems and what's been left behind after a program has been run, respectively. Using these methods together will give QA teams a fuller picture of the app's security and help make decisions regarding how to bet­ter protect employees.

While security testing tools will be a major asset to evaluating appli­cations themselves, the solutions can also gauge the protection capabilities of the device. It's important to note that as new devices and operating systems are released, support is dis­continued for older versions. IT and QA staff must determine if employees are using any legacy systems that no longer receive patches and manufac­turer updates, as this will leave a huge vulnerability if it's not addressed ap­propriately. Newer hardware may also have better features like encryption and passcodes, whereas legacy de­vices may not have things like remote wipe to reset to factory defaults or re­move encryption keys. Taking stock of what devices and operating systems are being used will help teams make a security map of their infrastructure. This way, teams can create a solid pro­tection strategy and provide employ­ees with capable applications.

Incorporated in 2007, Zephyr is a company based in Bangalore, India, providing on-demand Test Management solutions designed to meet the needs of today's dynamic and global Test and Quality Assurance departments.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Just Group [GBX: JUST.L]

    Empowering Retail through Customer-First Technology Adoption Strategy

    Frank De Sa, Chief Information Officer

  • Willis Towers Watson

    ISS Facility Services Australia & New Zealand

    The Right Technology And Reliable Partners; The Business Next Frontier

    Luke O'Brien, CIO

  • Willis Towers Watson

    BPAY Group

    Building BPAY Group's New Digital Foundation

    Angela Donohoe, Chief Information Officer

  • Willis Towers Watson

    Bvn Architecture

    How Have Recent Advancements in Big Data Been Impacting Businesses?

    Marc Solomon, CIO

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

APAC CIOOutlook
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@apacciooutlook.com
  • sales@apacciooutlook.com
  • marketing@apacciooutlook.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 APAC CIOOutlook. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://cyber-security.apacciooutlook.com/leadership-perspective/mobile-application-security-testing-the-unique-characteristics-of-device-security-models-nwid-4177.html