Verizon surveyed 762 people responsible for mobile security in April 2025. The Mobile Security Index 2025 that came out of it has one finding IT teams should pin to the wall: 70% of the devices hit by an attack were personal phones, not company ones.
The report runs to 39 pages. This is the short version for someone who manages a fleet: the numbers that matter, what they mean for your policy, and where the report's own first recommendation, mobile device management, fits in.
The Verizon Mobile Security Index 2025 in five numbers
The survey covers small businesses, large enterprises and the public sector, mostly in the US (74%), with the UK (14%) and Australia (12%). It's the eighth edition, so the year-over-year comparisons mean something.
| 85% | of organizations say attacks on mobile devices are increasing. |
| 80% | have seen mobile phishing attempts aimed at their employees. |
| 70% | of devices affected by an attack were personal devices. |
| 50% | had a mobile or IoT incident that led to data loss. 46% had one that caused downtime. |
| 17% | have specific controls against AI-assisted attacks, while 77% think those attacks are likely to succeed. |
None of these is a surprise on its own. Together they describe a gap: everyone sees the threat growing, and few have changed how phones are managed.
Personal phones are where attacks land
Start with the 70%. Only a quarter of the organizations surveyed let employees work entirely on their own phone, and 19% run a mix of corporate and personal devices. Personal phones are a minority of the fleet and the large majority of the victims.
The reason isn't mysterious. A personal phone that reads work email is usually a phone nobody patches on a schedule, nobody checks for a passcode, and nobody can wipe when it's left in a taxi. The company has the exposure and none of the controls.
Banning personal devices doesn't work, people route around it. What works is giving the personal phone a managed work space: a work profile on Android, a managed set of apps and accounts on iPhone, with company data encrypted and removable without touching the photos. We've covered the mechanics in our BYOD glossary entry. The point here is simpler. If 70% of incidents start on devices you don't manage, managing them is the first job.
The people who said no to MDM lost more data
This is the comparison I'd show a CFO. Verizon isolated the organizations that considered an MDM and decided against it. 63% of them lost data in a mobile incident, against 50% across the whole sample. And 31% of them rate their own mobile risk as extreme, twice the average of 15%. They know.
The other direction holds too. Organizations that run an MDM do better on every AI-related control the survey measured:
- Full employee training on generative AI risks: 55% with MDM, 39% without.
- AI usage policies that are defined and enforced: 59% against 45%.
- Auditing of AI-generated content: 63% against 48%.
- Automatic access revocation on a risk signal: 71% against 57%.
An MDM doesn't train anyone. But a team that has inventoried its devices and written a policy for them tends to be the team that does the rest. Device management is the base layer the other controls sit on.
Verizon says as much. The first recommendation in the report is to implement an MDM on all devices, managed and BYOD, for three reasons it names: patch management, control over installed apps, and a handle on generative AI tools. That last one matters more than it did a year ago. 93% of organizations report employees using generative AI on their phones, and 64% rank sensitive data typed into those tools as their top mobile risk.
Book a demo
See Appaloosa run on your fleet
A 20-minute call on your real setup. Enrollment, private apps, security.
Book a demo →Phishing moved to the phone
80% of organizations saw mobile phishing attempts. More telling: when companies run their own smishing tests, 39% of them watch between a quarter and half of their employees tap the link.
That click rate would be alarming on a laptop. On a phone it's predictable. The URL is truncated, the message arrives next to texts from family, and there's no mail gateway in front of SMS or WhatsApp. User behavior is the top cause of breaches cited in the survey (44%), ahead of app, network and web threats at 43% each. Verizon's own 2025 Data Breach Investigations Report puts a human element in about 60% of confirmed breaches.
Training helps a little. Reducing what a bad click can reach helps more: no corporate credentials stored outside managed apps, conditional access that refuses a non-compliant phone, OS updates enforced within days rather than whenever. All of that is policy you push from a console, which brings you back to having one. It's what mobile device management is for.
Incidents cost more than they did last year
Among organizations that were hit, 47% suffered downtime, 45% lost data, 40% paid financial penalties, 28% took reputational damage and 22% faced regulatory action.
The trend line is the worrying part. Of those that had downtime, 63% describe the repercussions as major. Last year it was 47%. Phones run more of the business than they did, so a phone incident stops more of it.
There's also a new line on the bill: 36% were penalized by their cyber insurer afterwards, through a higher premium, reduced coverage or a denied claim. And 84% have had to demonstrate their mobile security maturity to a customer, partner, regulator or insurer. "We have an MDM, here's the compliance report" is a much shorter conversation than the alternative.
One number deserves a raised eyebrow. 96% of respondents are confident they could recover quickly from a mobile attack. Among the very confident, 32% still suffered major repercussions when it happened. Confidence isn't a control.
If you want to put a figure on your own exposure, our mobile risk calculator estimates it from your fleet size, your share of personal devices and the type of data on them.
Small businesses are the least protected
33% of small and medium businesses use an MDM, against 43% of large enterprises. They run fewer smishing tests too (65% against 78%). Yet 57% say they're at a resource disadvantage against attackers and 54% think they have more to lose than a big company.
They're right on both counts, and the objection is usually cost and time. It's an outdated one. Cloud MDM is priced per device per month (ours starts at 3.49 EUR), and a first configuration takes an afternoon, not a project. For a 60-person company the annual bill is smaller than one day of downtime.
Some sector figures, for context. In energy, 72% see themselves as a prime target and only 35% use an MDM. In healthcare, 89% fear a mobile breach would affect patient care. In the public sector, 79% think one could put lives at risk.
What separates the top 4%
Verizon lists eight practices: MDM or UEM, mobile threat defense, zero trust, SASE, a secure enterprise browser, EDR, MDR and cyber risk quantification. Only 4% of organizations do all eight. That group has half the downtime (24% against 46%) and a fifth of the major repercussions (12% against 63%).
Nobody goes from zero to eight in a quarter. The order matters, and the report's own recommendations put device management first because the rest depends on it. You can't run threat defense on devices you haven't enrolled, and zero trust needs a device posture to evaluate.
What to do with all this on Monday
Four things, in this order.
- Count the phones that touch company data, personal ones included. The list is usually longer than expected.
- Enroll them. Corporate devices through zero-touch enrollment so they arrive managed, personal devices through a work profile or a managed account that leaves private data alone.
- Enforce the basics everywhere: passcode, encryption, OS updates with a deadline, remote wipe of company data.
- Decide which generative AI apps are allowed on managed devices, and say so in writing. 93% of your peers already have employees using them.
75% of the organizations surveyed raised their mobile security budget in the past year and 76% plan to keep going. The ones who got the most for that money started with the unglamorous part.
The full report is on Verizon's Mobile Security Index page. If you'd like to see what managing a mixed fleet of corporate and personal phones looks like in practice, book a demo and bring your device count.
FAQ
What is the Verizon Mobile Security Index?
The Verizon Mobile Security Index (MSI) is an annual report on mobile and IoT security in organizations. The 2025 edition is the eighth. It's based on a survey of 762 professionals responsible for mobile security, conducted in April 2025 across small businesses, large enterprises and the public sector in the US, the UK and Australia.
What share of mobile attacks hit personal devices?
According to the Verizon Mobile Security Index 2025, 70% of devices affected by an attack were personal devices rather than company-issued ones, even though only 25% of organizations rely fully on personal phones and 19% mix both.
Does an MDM reduce mobile security incidents?
The 2025 survey points that way. Organizations that rejected an MDM lost data in 63% of cases against 50% on average, and organizations with an MDM score 14 to 16 points higher on every AI-related control measured. Verizon lists MDM on all managed and BYOD devices as its first recommendation.
How often do mobile incidents cause downtime or data loss?
50% of surveyed organizations had a mobile or IoT incident involving data loss and 46% had one involving downtime. Among those with downtime, 63% called the repercussions major, up from 47% in the 2024 edition.
Ready to try Appaloosa? Start free