How to Keep Mobile Devices Secure and Device Data Private

Jared Shepard talks about mobile device security and privacy.

Technology keeps evolving. More and more, we need our phones just to participate in the world. And mobile device security and privacy keep getting murkier, especially when it comes to business. Employers want to protect company data from whatever their employees might be doing on their devices outside of work. And employees don’t want their employers to have access to everything they do on their phones. Solutions and options are out there – it’s just a matter of being proactive.


See Mobile Device Threats with Jared Shepard for a complete transcript of the Easy Prey podcast episode.

Jared Shepard is the CEO of Hypori and a U.S. Army veteran with over twenty years of experience in information technology. His first company, Intelligent Waves, does cyber defense, and Hypori is a spinoff company from that. He’s also the founder and chair of Warriors Ethos, a nonprofit organization that helps veterans transition out of the military and into their next career.

Jared didn’t intend to go into IT. He was planning to become a Green Beret when one of his friends suggested IT. His friend said that he could get one certification and make $70,000 a year. Jared thought that sounded pretty good. So he re-enlisted in the army and became an IT guy, which taught him the basics. On 9/11, a 3-star general picked him to be a communications NCO, and his time in rooms with the top leaders in the U.S. Army made him realize how much bigger the world was than he thought and drove his desire to have a bigger impact. After leaving the army, he was a consultant and contractor for a while before starting Intelligent Waves. He’s been running his own companies ever since.

Anyone Can Be a Victim

Jared has been a victim of multiple frauds and security incidents. He was in Iraq when the USB exploit happened and had to do backflips to protect networks. And between his two companies, he probably gets a message every other day from an employee asking if he really wanted them to buy gift cards. It happens all the time, and the need to be diligent never stops.

The requirement for diligence is just never-ending. Before you click, know what you’re doing.

Jared Shepard

On a personal level, Jared’s first 401(k) was stolen with identity theft. It was very advanced. The bank sent him a picture of “his” passport, which had all the right information but a photo of an African man. The thief started by just calling in and changing the phone number. Then a few weeks later, he called and said he needed to update the email address. Finally, he said he’d like to move the 401(k) to a different bank. A withdrawal would have been suspicious, but consolidating retirement accounts is normal. At the last minute, the thief said he’d like to look at gold or Bitcoin. Once the money was in Bitcoin, it was gone instantly. That’s when the bank figured it out.

Luckily, the bank recognized that they hadn’t successfully validated the person’s ID before allowing the move, so they protected Jared. He even got to work with the FBI to investigate what happened. He also learned that the FBI has a threshold of something like $300,000 lost before they investigate. That’s more than many people’s life savings. And the actual cost to execute 9/11 wasn’t a huge multiplier more than that – someone could pull that off a few times and fund terrorist activities. There’s real potential impact.

Crimes are Getting More Complicated

This incident happened to Jared a while ago, and crimes have only gotten more sophisticated and complex since. We now have all sorts of new devices and equipment, from the need for mobile device security to generative AI mechanisms. If you’re on the internet or have done public things, it takes AI hardly anything to produce something with your likeness, whether that’s a fake passport or literally meeting someone on live video with a deepfake. The old advice of getting someone on a video call isn’t true anymore.

Some of Jared’s friends in security talk about companies unknowingly hiring North Korean operatives into their business. They have laptop farms in the US to remote into, so even if IT is checking where someone’s calling from, it looks domestic. When they tell a company that they have an employee who is potentially a foreign operative and say who it is, the company almost always says that’s their best employee. Of course they are – it’s five people doing one job because they want to outperform. Sometimes they want to get at your code or compromise your environment, or they want to be able to recommend someone else to get at even more sensitive things. That’s why lots of big firms require in-person interviews for senior-level jobs. The cost of a plane ticket is trivial compared to an annual salary – or an incident.

Think of any company that runs a large portion of infrastructure. Or just look at the Cloudflare, CrowdStrike, or AWS outages recently. An internal threat could be crippling. Jared would argue that we haven’t seen a peer like China really target our infrastructure yet. These have all been human errors so far. A targeted nation-state attack could be even more devastating.

Mobile Device Security and Privacy

In the past, companies managed mobile device security with multiple devices. Employees who needed phones got company-provided phones, with strict warnings not to do anything personal on their work phones and vice versa. But the days of carrying multiple devices are mostly over. Young people want to be able to do everything on one device. And even big producers like Microsoft, Apple, and Google are trending towards mobile operating systems – they know the world is going to go mobile. But it makes mobile device security more murky. Companies want to leverage 24/7 employee remote access, but also not compromise corporate information, infrastructure, and data. And employees want to work and play on one device without compromising their privacy.

Doing work and personal things on one device means an increased need for mobile device security.

An additional concern that makes the problem even more complex is AI. How many operating systems have AI built into them organically? And the most-downloaded free AI in the world is DeepSeek. It’s a great, high-performing AI. But if you use it, you have to be comfortable with the fact that it’s exporting tons of data to China.

Europe is struggling with GDPR from a privacy standpoint. In the US, corporate rules have taken over more than individual privacy rules, though we’re starting to see more individual privacy rules emerge. And AI needs a combination of personal and corporate data to train. ChatGPT used to only store prompts for 30 days, then they got sued and have to store prompts indefinitely. In Europe, you can’t move data across national borders without written consent from individuals – which is great until you try to create any kind of collaborative platform. As a user, it’s hard to keep track of all the legal statuses, privacy options, and what lawsuits are going on.

How Hypori Addresses Mobile Device Security and Privacy

Jared’s company Hypori works to address some aspects of mobile device security and privacy concerns. They’ve gone against the grain in many ways in their solutions. They’re not Chevy competing against Ford to make a better truck – they’re doing something entirely different.

Hypori got its start in the military side of things. The military does hard stuff in hard places – it’s difficult from a nation-state standpoint and a data standpoint, and it’s also dangerous. The idea was to let people use a device knowing that the device or network was compromised, but still be able to use it without jeopardizing the mission or data. This was before zero trust was a big concepts, but it built the platform that assumes your device is already compromised. Which, if you have social media on it, it has been.

Our platform assumes that your devices is already compromised – which, by the way, if you have social media on it, it is.

Jared Shepard

Hypori’s application doesn’t trust or interact with anything on your phone. As a side effect of that, you get to keep your privacy. What you do on your time on your phone with your apps is your business and never exposed to the company. And the company will never be exposed to anything that happens to be on your phone. Your phone can receive pixels from the cloud-based OS and you can view and interact with it in real time, but none of it is never actually on your phone. So technically, the data never left the company. It provides separation between personal and corporate, which benefits both your privacy and the company’s security.

Taking Computing Away from the Edge

The idea behind what Hypori does is taking computing away from edge devices – devices that people interact with on the “edge” of networks. This not only enhances mobile device security, but also empowers more computing capability. All devices need to do under this model is display pixels and collect touches, swipes, and typing. Processing and storage happens in the cloud. One of Jared’s favorite parlor tricks when demoing Hypori is to show an old phone with two bars of 4G and ask what kind of speeds people think he can get. Then he does a speed test and shows he’s running on data center speeds.

With this setup, everything runs faster, companies can dynamically allocate processors, memory, and bandwidth, people can access it from any device, and it’s cheaper than a brand-new computer. The downside is that if you don’t have internet connectivity, you’ve got nothing. But with services like Starlink and municipal wifi, the idea that you ever won’t have a connection is starting to go away

Assume Everything is Compromised

Whether it’s general cybersecurity or mobile device security specifically, Jared’s top rule is to just assume everything is compromised. If you operate with that assumption, you can figure out whether or not the data you need to put there is sensitive and if so, apply appropriate protections to keep it protected.

My #1 rule to cybersecurity is everything is compromised.

Jared Shepard

On mobile devices specifically, there are even things you can do to stop things like screen recording. There’s a setting on many phones to disable it – if the device detects screen recording, it will feed black pixels instead. The only other workaround for that would be someone watching your phone over your shoulder. Jared does some work for the Department of Defense, and they sometimes ask about scenarios where someone takes a photo of a phone screen. His response is that then you have an insider threat problem, and that’s a different problem. Tech can only solve for that so much.

There are some things tech can solve really well. Jared has even played around with mobile device security programs that detect whether you’re looking at the screen and blacks it out if you aren’t or if someone else is looking at it over your shoulder. The problem is that users hate the inconvenience. Wherever the tech goes is going to be obnoxious. It’s just a question of whether or not users are willing to adapt. Jared’s biggest enemy as a cybersecurity guy isn’t an enemy force, it’s just laziness. Marketing is all about reducing friction, but friction is the friend of security.

The number one enemy for [cybersecurity] in the world is not China. It’s just laziness. That’s always our number one enemy.

Jared Shepard
Friction is a benefit for security on any device.

A Parallel Product for Consumers

Hypori’s product is specifically to provide better mobile device security for businesses. But they have a consumer product in the works, too. The inspiration for it came from Jared’s wife. One day, as he was getting ready for work, she asked when she could have Hypori. He wasn’t sure why she’d want that. But she explained that the worst thing in the world was when she had to replace her phone. She was always worried about losing contacts and photos. And it would be convenient to take the big phone with a great camera to kids’ events and a smaller, simpler one to dinner with friends. Why couldn’t see change out her phone like she did her purse?

Jared immediately realized the opportunity for making devices into an accessory. It would be faster and cheaper. If you’re just checking email and getting on apps, you don’t need a $1,800 device. Maybe we could build devices around an $1,800 device having $1,800 worth of cameras. There’s a level of flexibility and empowering users that comes with that.

The tradeoff is that you’re handing your privacy to the company managing that digital device. It’s a valid concern, but realistically you’ve always been doing that. Today, who’s protecting your privacy? Microsoft, Apple, or name your security vendor, VPN vendor, or endpoint management vendor. Any time you use a product and you’re not paying for it, you and your data is the product. If you buy something specialized, there’s a higher likelihood of getting what you actually want. If you’re buying for convenience, ease, or features, privacy is probably secondary.

Any time you use a product .. and you’re not paying for it, you are the product. Your data is the product.

Jared Shepard

Data and AI

The big search engines make money off data. Data is today’s currency, and it’s worth more than money in many cases. Jared finds it funny to see people complaining about privacy in TikTok videos. If you have TikTok on your phone and care about mobile device security, go to their website and read their privacy declaration. They openly tell you that they’re going to go through every other message on your phone and pull every piece of data they can. If that’s what they’re open about, imagine how much more they’re not telling you.

Data is the currency of today. … Data is worth more money than money.

Jared Shepard

Look at the new AI models producing videos. If not today, then within the next two years, AI videos will be so accurate that you won’t be able to trust videos anymore. Jared has friends who are cybersecurity pros who get tricked by AI videos. AI is our generation’s version of splitting the atom – but where splitting the atom was only available to a few countries, AI is available to every sixteen-year-old on the planet.

Within the next 24 months we’ll be at a point where there is no such thing as video content that you can believe anymore.

Jared Shepard

How Consumers Can Improve Mobile Device Security

If you’re a person with your own device concerned about mobile device security, while you wait for Hypori’s personal option, go back to the golden rule of everything being compromised. Every time you do something, take that into consideration. Just because it’s compromised doesn’t mean you don’t do it. It means you consider what the risks are and special considerations. Pay special attention to things like if you’re using your credit card online, you need to be looking at your credit card statement to catch suspicious activity.

Be diligent with your passwords and protecting them. Don’t use your birthday, dog, or kid – you might as well post it on the internet at that point. There are lots of systems out there. Use a password manager. Consider a VPN. Don’t ever not have some kind of endpoint security, whether it’s something like Bitlocker or Microsoft Defender. Something is better than nothing, but nothing is as good as everything. You have to have layered defense.

Even with all that in place, you could still be a victim. Cybersecurity isn’t just about telling you how to protect yourself from being compromised, it’s about telling you what to do if you have been. If you got an indication that you’ve been compromised, you have to know what to do. Know where to change all your passwords. Keep a record. Think about it, have a plan, document it, put it somewhere safe but accessible. And make sure someone else knows how to access it in case something happens. Think about things beyond passwords, too, like kids’ healthcare info or bank information. Jared takes care of all the bills, but if he gets hit by a bus tomorrow, his wife needs to know how to pay the bills at the end of the month.

Plan for Privacy

Prevention is important. Take steps to protect your privacy and improve your mobile device security in advance. But also recognize that nobody gets out of life undefeated. Everybody is eventually compromised in some way, no matter who you are or how good you are at security. You have to assume it’s going to happen. And you have to plan for it.

Jared argues that privacy isn’t isolating all of your information to just you. Privacy is giving you control. It’s letting you choose who gets access, to what, when, and for how long. Privacy means what happens with your information is your choice. You don’t have to lock everyone and everything out. You just need to have controls set and be aware.

The idea of privacy is not the isolation of all your information to just you. The idea of privacy is you get to choose who gets access to what.

Jared Shepard

Learn more about Hypori at hypori.com. You can find and contact Jared Shepard and his team there. If the idea of isolating devices to protect the enterprise without impacting employee privacy intrigues you, reach out – they would love to show it to you. You can also find Jared on LinkedIn, where he is all the time, and on other social media.