[seopress_breadcrumbs]

The Mobile Security Imperative for Regulated Industries

This interview analysis is sponsored by Appdome and was written, edited, and published in alignment with our Emerj sponsored content guidelines. Learn more about our thought leadership and content creation services on our Emerj Media Services page.

Mobile applications have become the primary interface between enterprises and their customers, and increasingly one of the most exposed fronts in a broader enterprise threat landscape that is accelerating at machine speed.

Release cadence has risen from 10 to 13 apps per organization annually since 2023, and 71% of firms admit that pace has come at security’s expense. Attackers have industrialized just as fast across the enterprise attack surface as a whole. The EU’s cybersecurity agency reports that 70% of vulnerability-based incidents now result in successful intrusions, and CISA’s Known Exploited Vulnerabilities catalog grew 20% in 2025 alone, forcing federal remediation windows as tight as 15 days for critical flaws.

These figures span the full enterprise threat landscape, not mobile alone. Mobile carries that risk directly: it is a release surface shipping dozens of updates a year, each one a fresh opportunity for exploitation, with direct exposure to customer trust and revenue.

Stanford HAI found AI-related incidents jumped 56.4% year-over-year to a record 233 in 2024, with cybersecurity ranked among enterprise leaders’ top concerns tied to that growth. The damage already shows up on the balance sheet. The FTC recorded $12.5 billion in consumer fraud losses in 2024, a 25% jump driven by more victims actually losing money, not just more attempts — losses that increasingly route through the mobile channels enterprises depend on most.

Manual, developer-paced patching cannot close a gap this wide. This is a revenue and trust problem, not a technical one.

Yolandi de Weerdt recently sat down with Tom Tovar, CEO of Appdome, on the Emerj AI in Business podcast to crystallize how AI is reshaping mobile security strategy in an era where attacker automation now sets the pace.

This article distills the core strategic shifts shaping modern mobile security and highlights the AI‑driven principles executives can apply to stay ahead of attacker automation:

  • Agentic in‑app security for developer‑independent protection delivery: Embed protections directly into the application, independent of the engineering queue, so security ships continuously without relying on developer sprints.
  • Release‑synced defense for closing the post‑deployment exploit window:  Automate protection updates with every release so defenses adjust to what actually shipped, eliminating the gap attackers target between deployment and detection.
  • User‑specific protection for individualized risk reduction:  Tune safeguards to each user’s real‑time risk profile instead of applying one blanket policy, concentrating defense where threats actually emerge.

Listen to the full episode below:

Episode:  The Mobile Security Imperative for Regulated Industries – with Tom Tovar of Appdome

Guest: Tom Tovar, CEO of Appdome

Expertise: Mobile Application Security, DevSecOps, Cybersecurity, Product Strategy

Brief Recognition: Tom Tovar is CEO of Appdome, where he leads the development of mobile application security and DevSecOps platforms. Previously, he served as CEO of Nominum, scaling the company into a leading provider of DNS security software and services, and has held board, advisory, and investor roles across multiple cybersecurity and enterprise software companies. He earned a JD from Stanford Law School and a BBA in Finance and Accounting from the University of Houston.

Agentic In‑App Security for Continuous Protection Delivery

Tom Tovar speaks from direct experience when he describes how quickly the ground has shifted beneath cyber teams. He argues that the core challenge is no longer discovering issues but producing protection at the same speed attackers now operate.

He describes the pressure cyber teams now face:

“The barrier to creating fast exploits has effectively dropped to zero, so both the internal operating model and the external threat model are accelerating at once. Cyber sits between those two gravitational poles, getting pulled apart by a kind of black‑hole effect it can’t escape if it stays manual. On both sides — engineering and attackers — the work itself is becoming agentic.”

— Tom Tovar, CEO of Appdome

For Tovar, the problem isn’t simply speed. It’s structural. Cyber’s traditional model — policy, compliance, scanning, advisory guidance — leaves the function intermediated by the engineering organization. When protections must route through developer sprints, cyber becomes an evaluator rather than a contributor. In an SDLC where code, engagement, and threats are all agentic, that role has no future.

A practical way of understanding the shift, as he explains it, is recognizing the difference between agentic evaluation and agentic work. Frontier models help teams find issues faster, but finding is no longer enough. What matters is producing protection outcomes at machine speed:

Agentic Work Over Agentic Evaluation: Discovery has limits; protection requires producing fixes, not just identifying problems.

And this is where Tovar makes the role change explicit: cyber becomes a producer when it embeds protections directly into the app, independent of the engineering queue. In his framing, that is what gives cyber a seat in an agentic SDLC — contributing protection outcomes the same way engineering contributes code.

To make that shift real, Tovar outlines the operating model cyber needs:

  • Protection pipeline — a release‑cycle workflow where protections are deployed, measured, analyzed, and iterated the same way engineering ships code. This includes deploying protections in a test environment first to validate behavior before production.
  • Context capture — a system that records the what/why/when of every protection decision, giving cyber the same decision‑tracking discipline engineering gets from tools like Jira.
  • Feedback loop — data from real‑world implementation flows back into the system so agentic reasoning can improve over time, enabling staged autonomy as confidence grows.

Release‑Synced Defense To Close the Exploit Window

One of the most destabilizing shifts in mobile security is the widening gap between how fast attackers operate and how slowly enterprise release cycles can respond. Tovar describes a landscape where exploit propagation happens at machine speed while enterprise defenses remain tied to human approvals, gates, and segregation‑of‑duties checks. In his view, this timing mismatch is no longer a tactical inconvenience; it is the structural opening attackers exploit.

Tom Explains the gap:

“Attackers move in milliseconds while developers, even at their best, move in days. Every release has to cross approvals, gates, and segregation‑of‑duties checks, while exploits can propagate region by region, brand by brand, release by release. Vulnerabilities themselves are being replaced by secure coding performed by agents, which means cyber has to shift its function and layer active protections on top of the code base to defend users and revenue.”

– Tom Tovar, CEO of Appdome

Tovar’s argument rests on three related shifts:

  • Fewer traditional vulnerabilities: As secure coding agents take on more responsibility for identifying and remediating flaws, vulnerability discovery moves earlier in the development process.
  • A shifted attack surface: Exploits increasingly bypass code-level vulnerabilities altogether, concentrating risk in the window between releases where protections haven’t yet caught up.
  • A new cyber mandate: Security teams focus on delivering protections at the pace threats evolve.

Release‑synced defense addresses that timing gap directly. In Tovar’s framing, cyber must deliver protections at the same cadence engineering uses to ship the app. Each release becomes an opportunity to update defenses based on the latest threat data, not a moment to wait for developer implementation. Protection becomes a release‑aligned activity rather than a trailing one.

This reframes the SDLC: protection updates move in lockstep with every build, closing the exploit window that currently favors attackers. By aligning defense with release timing, cyber ensures protections evolve as quickly as the app itself, and as quickly as the threats targeting it.

Personalized Protection for User‑Level Risk Control

As organizations adopt agentic workflows, Tom Tovar argues that the most profound change won’t be speed or automation — it will be scope.

Cyber teams have long defined protection policy at the level of the application: a payments app gets one posture, a loyalty app gets another, and features, not users, drive the differences. In an agentic environment, that framing becomes too coarse. Tovar describes a progression where protection becomes increasingly granular as the system gains context and feedback.

He describes the starting point:

“Cyber people will say, well, this application does these three features, and this other application does five features. Therefore, the application with currencies needs higher protection, the application with no currencies needs lower protection.”

— Tom Tovar, CEO of Appdome

This is the traditional model, policy defined by what the app does. Once protection is already adapting release by release as discussed before, Tom argues the scope tightens one step further: from release to user.

With enough context and feedback, protection can be defined by each user’s individual threat circumstance rather than by the app or its latest build. Tom describes a future where every user’s defense posture is tuned to their behavior, environment, and risk profile, not a global policy applied uniformly across the entire audience.

He frames it as the natural endpoint of agentic reasoning:

“Imagine we personalize protection based on each of our unique threat circumstances. All of a sudden we all don’t get the same defense posture. My defense posture looks differently than the other person’s defense posture, across billions and billions of users.”

— Tom Tovar, CEO of Appdome

A user‑level model, as Tom describes, only matters if it translates into operational behavior, not just a conceptual endpoint. In practice, individualized protection looks like:

  • Adaptive posture — agentic systems adjust defenses per user instance, tightening controls automatically when threat signals rise and relaxing them when risk is low.
  • Risk‑tiering — high‑risk users receive stronger, more intrusive protections; low‑risk users avoid unnecessary friction, improving usability without compromising safety.
  • Continuous monitoring — layers of agents observe each user’s app behavior in real time, updating protection decisions as context changes to maintain stability and performance.

Personalized protection is not a marketing idea; it is the structural outcome of agentic context, agentic feedback, and agentic decision‑making. As Tovar puts it, it has always been the “holy grail” of cyber, and agentic systems finally make it achievable. The shift from application‑level policy to user‑level policy marks the point where cyber stops defending software and starts defending people.

Share article

Subscribe to updates

Subscribe to weekly email with our best articles Financial Services updates that have happened in the last week.

Recommended from Emerj