ege.

Check availability
and order 24/7

Trade Portal access

Don’t have an account?

You need to have one to place orders via our trade portal. Please contact your Account Manager or B2B sales team using the details below:

Call us

+44 (0)1782 565 555

need support

b2b@ege.co.uk

Managed doesn’t mean secure: Understanding EMM and Mobile Threat Defence

Mobile devices have changed the way businesses work.

A smartphone might be used to answer emails on the train, access a CRM system from a customer site, approve a document from home or give a field engineer access to the information they need to do their job.

For employees, that flexibility is now expected. For businesses, it creates a different challenge.

Every device accessing business systems needs to be managed, protected and kept under control. And with employees working across offices, homes, customer sites and public spaces, the traditional idea of a secure corporate network is becoming less relevant.

The mobile device is now part of the security perimeter.

So, how do you protect it?

Two technologies regularly come into the conversation: Enterprise Mobility Management (EMM) and Mobile Threat Defence (MTD).

They are closely related, but they aren’t the same thing.

EMM manages the device, applications and corporate data. MTD focuses on detecting threats and assessing the security risk of the device.

Understanding the difference, and how the two can work together, is increasingly important for businesses managing a mobile workforce.

What is Enterprise Mobility Management?


Enterprise Mobility Management (EMM) is the technology and policies businesses use to manage mobile devices, applications and corporate data.

It has evolved from Mobile Device Management (MDM). While MDM traditionally focused on managing the device itself, modern EMM can extend into application management, data protection, compliance and access control.

Think about what happens when a business gives an employee a smartphone.

Someone needs to make sure it is configured correctly. The right applications need to be installed. Security policies need to be applied. Corporate data needs to be protected. If the employee changes role or leaves the business, access needs to be removed.

Doing this manually becomes impractical, whether an organisation manages thousands of devices or just 10–20 that are regularly used in the field.

EMM provides a central way to manage those requirements.

Depending on the platform, an EMM solution can help with:

  • Device enrolment and configuration
  • Security policies
  • Application deployment
  • Corporate data protection
  • Device compliance
  • User access
  • Remote device management
  • Device lifecycle management

Platforms such as SOTI can give organisations centralised visibility and control across their mobile estate, while Samsung Knox provides additional security and management capabilities for compatible Samsung devices.

EMM Blog Demo


Why does EMM matter?


The obvious benefit is control.

If an organisation has 500 smartphones in the field, IT shouldn’t have to wonder whether each one has the right settings or applications installed.

EMM can provide a consistent framework for managing those devices at scale.

A business can establish policies around operating system versions, passwords, encryption, approved applications and other security requirements. Devices can then be managed against those policies.

It also gives IT teams greater visibility into the estate, helping them understand what devices are in use, who is using them and whether they meet the organisation’s requirements.

But there is an important distinction:

A managed device isn’t automatically a secure device.

That is where Mobile Threat Defence adds another layer.

What is Mobile Threat Defence?


Mobile Threat Defence (MTD) focuses on identifying security threats and assessing risks affecting mobile devices.

If EMM is concerned with whether a device is managed correctly, MTD is concerned with whether it is safe to use right now.

That distinction matters because mobile threats don’t necessarily change a device’s management status.

A smartphone could be fully managed, have the correct settings and meet every compliance requirement, and still be targeted by a phishing attack moments later.

MTD solutions can help identify threats such as malicious applications, phishing attempts, unsafe network connections and certain vulnerabilities. The precise capabilities depend on the MTD provider and operating system.

What can Mobile Threat Defence detect?


Phishing and malicious websites
Mobile phishing is a significant risk because employees regularly receive links through email, SMS and messaging platforms.

A convincing message can take just one click to send a user to a fraudulent website designed to steal credentials or other sensitive information.

MTD can provide web and anti-phishing protection to help identify potentially unsafe connections.

Malicious applications
Applications are another potential attack surface.

An employee might download a malicious application, or an application could contain a vulnerability that creates a security concern.

MTD can assess applications and provide information about potential threats and device risk.

Unsafe networks
Mobile employees don’t always connect from the office.

They might be working from a hotel, airport, coffee shop or customer site.

MTD can help identify certain network-related threats and potentially unsafe connections, giving organisations greater visibility into the conditions surrounding their mobile devices.

Vulnerabilities
Not every mobile threat involves malware or phishing.

Outdated operating systems and vulnerable applications can also create opportunities for attackers.

Depending on the platform, MTD can provide information about vulnerabilities and help organisations identify devices that may require attention.

The important difference is that MTD provides a more dynamic view of security risk.

A device doesn’t simply pass a security check once and remain trusted forever. Its risk can change as it is used.


EMM vs MTD: What’s the difference?


The simplest way to think about the two technologies is this:

  • EMM manages the mobile environment.
  • MTD monitors that environment for threats.

EMM is concerned with things like device enrolment, configuration, applications, security policies, compliance and corporate data. It gives IT teams control over how devices are managed and what they are allowed to do.

MTD takes a different approach. It looks at the security risks affecting those devices, helping identify threats such as phishing, malicious applications, unsafe networks and vulnerabilities.

So, while EMM might tell you that a device is correctly configured and meets your organisation’s requirements, MTD can help tell you whether that same device is currently presenting a security risk.

That’s an important distinction.

A device can be managed without necessarily being secure, and a device can become a security risk even though its configuration hasn’t changed.

This is why EMM and MTD work best as complementary technologies rather than alternatives.

EMM provides the control. MTD provides the security insight. Together, they give businesses a more complete view of their mobile estate.

Of course, not every deployment works that way.

If your customer is setting up devices themselves, we can support them through the process of getting new or existing devices enrolled onto their chosen EMM platform. The important thing is that your customer isn’t left wondering what happens next.

And your sales team isn’t suddenly expected to become the deployment team.

Why isn’t EMM enough on its own?


Imagine an employee receives a company smartphone.

  1. It is enrolled into the organisation’s EMM platform.
  2. The correct operating system is installed.
  3. A strong passcode is enforced.
  4. Encryption is enabled.
  5. Approved business applications are installed.
  6. The device is fully compliant.

From an EMM perspective, everything looks good.

Then the employee receives a convincing phishing message and clicks a malicious link. The device hasn’t suddenly become unmanaged. Its configuration may still meet every EMM requirement.

But the security risk has changed. That’s the gap MTD can help address.

Rather than simply asking whether a device meets a predefined configuration, MTD can provide information about threats that may be affecting it.

This is increasingly important as smartphones become a gateway to corporate email, cloud applications, customer information and other business systems.

How do EMM and MTD work together?


The relationship is straightforward.

EMM manages the device. MTD assesses the device’s security risk.

Together, they give businesses a clearer picture of whether a device should have access to corporate systems and data.

For example, an organisation can use an EMM platform such as SOTI to enrol devices, apply security policies, manage applications and monitor the mobile estate.

MTD can then provide additional information about the device’s current security condition.

If a threat is detected, that information can be used alongside the organisation’s existing device management and security policies to determine the appropriate response.

That could mean restricting access, prompting the user to resolve an issue or taking another action based on the organisation’s risk policies.

The important point is that the device isn’t simply considered secure because it was configured correctly when it was deployed.

EMM provides ongoing management. MTD provides ongoing insight into risk.

Together, they support a more responsive approach to mobile security.

What do EMM and MTD look like in practice?


Let’s take a simple example.

An employee is using a company smartphone to access business email and other corporate applications.

The device has been configured through EMM and meets the organisation’s security requirements. The employee then connects to an unsafe network while working remotely.

MTD identifies a potential security concern and reports an elevated risk level.

The organisation’s security policies determine that devices above a certain risk threshold shouldn’t access sensitive corporate resources.

Access is restricted while the issue is addressed. The employee follows the required remediation steps. Once the threat is resolved and the device returns to an acceptable risk level, access can be restored.

The value isn’t simply in detecting the threat. It’s in connecting threat detection with the policies and controls that determine what happens next.

That creates a more dynamic approach to mobile security than relying solely on a device’s management or compliance status.



EMM, MTD and BYOD


The combination can be particularly useful for businesses operating Bring Your Own Device (BYOD) policies.

BYOD can make sense for employees. They already know their own smartphones, carry them everywhere and may prefer not to carry a separate corporate device.

For businesses, however, it raises an important question:

How do you protect corporate information on a device the business doesn’t own?


EMM and mobile application management can help organisations protect corporate information within approved applications without necessarily taking complete control of an employee’s personal device.

MTD can add another layer by assessing the security condition of that device.

If a personal device becomes high risk, the organisation can use that information to determine whether access to corporate applications or data should continue.

This creates a balance between flexibility and control.

Employees can use the devices that work for them, while businesses can put appropriate controls around the information those devices can access.

Why combine EMM and MTD?


For businesses managing a significant mobile estate, bringing the two together can provide several practical benefits.

Greater visibility
IT teams can gain a clearer view of devices, applications, compliance and security risk.

Stronger mobile security
MTD can identify threats that may not be visible through traditional device management alone.

Faster response
Security information can feed into predefined policies, reducing the need for IT teams to respond manually to every issue.

Better protection for corporate data
Access and application policies can help prevent sensitive information from being accessed when a device presents an unacceptable level of risk.

More secure remote working
Employees can work across different locations while businesses retain greater visibility over the devices accessing their systems.

A more proactive approach
Rather than reacting only after an incident has occurred, businesses can use current device risk information to make more informed access and security decisions.

Mobile Security is part of the technology lifecycle


There is another part of this conversation that is easy to overlook.

Mobile security doesn’t begin when a device is handed to an employee.

It starts much earlier.

  • How is the device sourced?
  • How is it configured?
  • How are applications and security policies deployed?
  • How is it delivered?
  • What happens when it is returned?
  • How is corporate data removed?
  • Can the device be securely reused or redeployed?

These questions connect mobile security with the wider technology lifecycle.

For businesses managing large mobile estates, having the right security technology is important. But so is having the right process around it.

A secure device that is poorly configured or incorrectly deployed can still create problems. Equally, a well-managed device needs a secure process when it reaches the end of its operational life.

That’s why mobile security should be considered alongside the wider way an organisation manages its technology.

How we can help


At EGE, we believe technology works best when products and services work together.

As a UK-based Technology Solutions Provider, we help businesses look beyond the device itself and consider what is needed to make technology work throughout its lifecycle.

That includes the devices themselves, as well as services around deployment, mobile security, fulfilment, returns and technology lifecycle management.

Our approach brings together technologies such as SOTI, Samsung Knox, 42-Gears and Novus to help businesses build a more connected approach to managing and protecting their mobile estate.

Whether your customers are reviewing their Enterprise Mobility Management strategy, exploring Mobile Threat Defence, managing a growing BYOD estate or looking at how to improve device deployment, the starting point is understanding their environment.

  • What devices are being used?
  • Who is using them?
  • What can those devices access?
  • How are they currently managed?
  • What threats could they face?
  • And what happens when that risk changes?


The answers help determine the right combination of technology, policies and services for any organisation.

And for resellers, that creates an opportunity to do more with every customer.

By bringing together the right products and supporting services, resellers can build higher-value technology solutions, create additional revenue streams and increase margin beyond the initial device sale.

Just as importantly, EGE can provide the expertise, technology and support behind those services, helping you expand your own offering without adding unnecessary workload to your own teams.

From device management and mobile security to deployment, fulfilment and lifecycle services, we help resellers offer more while EGE handles the complexity behind the scenes.

Because effective mobile security isn’t about adding technology for the sake of it.

It’s about giving people the freedom to work while giving businesses greater confidence that their technology is being managed, protected and supported throughout its lifecycle.

And for resellers, it’s about turning that support into greater value, stronger customer relationships and more opportunity.

EMM and MTD: The simple difference


Enterprise Mobility Management manages your mobile estate.

Mobile Threat Defence helps identify whether those devices are currently at risk.

Together, they provide a more complete approach to managing and protecting the mobile technology your business relies on.