Editorial

Your MDM Sees Less Than You Think

When managed doesn't necessarily mean it's secure

Tuesday, July 21, 2026 | 5 MINS

Mobile device management gives organisations something security teams naturally value: control. Devices can be enrolled, configured, monitored and wiped remotely. Policies can be applied consistently, operating systems checked and access blocked when a device falls outside the rules.


That can create a dangerous level of confidence.

An enrolled device is not automatically a secure device. It may meet every compliance requirement while an employee uploads sensitive information to a personal cloud account, pastes company data into an unapproved AI tool or conducts business through an application the organisation barely understands.

Green dashboards

The dashboard remains green because the device is doing exactly what the policy permits.

MDM was built around a relatively clear distinction between corporate and personal technology. That boundary is now much harder to identify. Employees work across company laptops, personal phones, browsers, SaaS platforms and messaging applications. The data moves between them more freely than the security controls do.

This makes device management an increasingly incomplete view of risk.

There is also a temptation to respond by applying tighter controls. Organisations block applications, restrict features and expand monitoring in pursuit of greater security. But controls that make legitimate work unnecessarily difficult rarely eliminate the behaviour. They move it somewhere less visible.

Employees find another application, another device or another route to complete the task. Security gains control of the managed device while losing sight of the work itself.

Privacy adds further tension. Bring-your-own-device policies require organisations to protect corporate information without intruding into employees’ personal lives. Technically possible does not always mean culturally acceptable. Poorly explained controls can quickly turn a security programme into an employee surveillance concern.

So what is effective?

Effective MDM therefore depends on more than enrolment numbers and compliance scores. Security teams need to understand where business data is accessed, how it moves and what happens when a device is compromised, lost or no longer trusted. Identity, application security, data protection and user behaviour must all be considered alongside the device.

MDM still provides an essential operational foundation. It can reduce exposure, enforce minimum standards and give teams a practical response when something goes wrong. But it cannot govern every action performed through a managed screen.

The most important question is not how many devices appear compliant. It is whether the organisation can still protect its information when users behave in ways the MDM platform cannot see.

More topics

}());