
Smart sensors in factories. Mobile devices in field operations. Connected equipment in hospitals and government offices. These tools are essential to how modern organizations operate. But their growing presence comes with a major tradeoff: Many of these devices connect to enterprise networks without the visibility, control, or protections applied to traditional endpoints.
Mobile and IoT devices are often unmanaged, unmonitored, and undersecured, making them attractive targets for attackers. As these endpoints multiply across industries, they expand the attack surface in ways that are difficult to detect and even harder to defend.
According to the Zscaler ThreatLabz Mobile, IoT, and OT Threat Report, IoT malware attacks increased by 45% last year, and mobile spyware incidents more than doubled. Attackers are capitalizing on the fact that many of these devices run outdated operating systems, use default credentials, or communicate over unencrypted channels. These devices are even more at-risk than laptops because they don’t have the same level of protection.
Legacy perimeter-based security is not designed to manage this new reality. Agent-based controls often fail on headless devices, and mobile endpoints introduce data security risks when used for both personal and professional purposes. Unmanaged devices also pose unique challenges, such as smishing (SMS phishing) attacks and ThreatLabz found that healthcare and government were among the most targeted sectors in 2024. These industries depend heavily on connected devices for operational continuity, but many endpoints lack the protections needed to repel modern threats. Threat actors are using encrypted tunnels to maintain persistence, execute lateral movement, and exfiltrate sensitive data undetected.
On mobile devices, spyware tools have become more advanced. Some can bypass multifactor authentication and remain hidden while intercepting data and communications. Combined with the vulnerabilities endemic to IoT—like open ports or hardcoded credentials—these threats are difficult to manage without a new approach.
How zero trust can help
Zero trust operates on the principle that no user or device is trusted by default. It evaluates every access request based on identity, device posture, behavior, and context.
This approach is particularly effective for environments where traditional endpoint agents are not feasible. With zero trust, organizations can:
- Continuously discover IoT devices
- Enforce least-privilege access based on granular policies
- Apply microsegmentation to isolate and contain threats
- Monitor traffic and device behavior for anomalies
- Extend secure application access to unmanaged mobile devices
- Limit communication paths to reduce lateral movement and block command and control attacks
- Avoid requiring intrusive agents by routing traffic through secure gateways
This model supports dynamic access decisions, which are essential when dealing with transient and diverse device populations.
Overcoming common challenges
Security for mobile and IoT devices requires balance. Applying uniform controls can be difficult when devices vary widely in capability and ownership. Instead, organizations should start by mapping the entire device landscape, categorizing devices based on use case and risk profile.
Security policies can then be tailored based on function and sensitivity. For instance, an employee’s personal phone may be allowed access to work email through a zero trust browser, but denied access to certain internal applications. Meanwhile, an IoT device with no user interface might only be permitted to communicate with a single destination.
Cross-functional collaboration is key. Security teams must work with operational stakeholders to ensure policies are feasible and aligned with productivity goals.
Balancing usability and security
Zero trust must be transparent and adaptive. If enforcement disrupts workflows or burdens users with constant authentication prompts, adoption will suffer. Security should be enforced in ways that respect user experience, such as through a Zero Trust browser or risk-based authentication.
Minimizing endpoint requirements can also improve usability. Agentless options and lightweight access controls can protect devices without requiring full control or visibility. For example, enforcing application access through a browser-based interface allows users to stay productive on personal devices without exposing the enterprise.
Regular audits and policy reviews ensure controls stay current as device populations change. Security is not static, and neither are the environments it protects.
Learn how Zscaler can help you build a resilient Zero Trust strategy for securing mobile and IoT devices by visiting Zscaler today.
