How Mobile App Security from Guardsquare Addresses Gaps in Framework Compliance
Former AT&T Chief Security Officer and TAG Infosphere founder Dr. Edward Amoroso shares his perspective on the state of mobile application security in a featured guest post for Guardsquare.
Enterprise compliance is evolving as organizations face mounting regulatory pressure and more capable threat actors. Regulators now expect alignment to frameworks such as National Institute of Standards and Technology Cybersecurity Framework (CSF) 2.0 and sector-specific mandates. Yet, while governance has matured around cloud, endpoint, and networks, mobile app risk remains underrepresented in compliance frameworks and control processes.
This is certainly not the first time we’ve seen important aspects of security compliance left out of compliance frameworks. This author spent decades in network security, for example, and was often surprised at how thin the treatment of network protections was in popular compliance frameworks. These omissions were eventually addressed – and, in this note, we will make the case that it is time now to rectify under-treatment of mobile app risk in compliance.
The strategy we will take in our discussion really follows two tracks: First, we make the case that mobile app security already does improve security compliance through its controls around data, credentials, and access. But we also make the case that the compliance frameworks can and should be adjusted to specifically account for mobile app security controls more aggressively and more deliberately.
This TAG analyst report thus examines how mobile app security, with emphasis on the capabilities offered by Guardsquare, can help enterprises close existing compliance gaps. We assess how mobile app threats intersect with modern control frameworks and evaluate how application hardening, runtime protection, and anti-tampering capabilities support demonstrable alignment with prevailing cybersecurity and software assurance expectations.
But, in addition, as referenced above, we provide guidance for the purveyors of our major compliance frameworks such as NIST CSF 2.0 to introduce and augment their requirements to more specifically address mobile app risk. This is perhaps intensified by the downstream effects of good mobile app security on the protection of emerging artificial intelligence (AI) usage, which is often tightly integrated with mobile apps.
Understanding mobile app risk
Mobile apps represent a uniquely exposed attack surface. Unlike server-side systems residing in controlled infrastructure, mobile apps operate in untrusted environments where adversaries can download, reverse engineer, instrument, and modify application binaries. Sensitive logic, embedded credentials, API endpoints, and proprietary algorithms may be extracted if appropriate safeguards are not implemented.
This risk extends beyond data leakage. Attackers can also manipulate application logic to bypass authentication controls, intercept transaction flows, or automate fraudulent behavior. When mobile apps serve as primary digital channels, compromise at the client layer can undermine otherwise robust backend controls. One challenge is that complementary controls are often not present to address these risks if the mobile app ecosystem does not include proper protections.
From a compliance perspective, this creates a disconnect. That is, an organization may demonstrate full policy alignment and strong internal security controls, yet remain vulnerable through inadequately protected mobile code operating outside enterprise boundaries. This undermines the entire purpose of compliance frameworks, and it helps to explain our motivation in making the case for more attention to mobile app controls in our frameworks.
Adding mobile app security to compliance frameworks
All of the major cybersecurity frameworks currently provide broad guidance on software integrity and secure development but rarely prescribe explicit mobile app hardening controls. It is unclear why the omission has been so stark, but compliance development is not perfect. Witness the omission of governance from NIST CSF 1.0 to NIST CSF 2.0. That said, there remain areas – and our attention here is on mobile app risk – that demand more focus.
For example, NIST CSF 2.0 emphasizes functions such as Govern, Identify, Protect, Detect, Respond, and Recover. Within these categories, subcontrols reference secure development practices, code integrity, and protection against unauthorized access, but they do not mandate binary obfuscation, runtime anti-tampering, or mobile-focused protections. As a result, organizations can technically align with CSF while leaving mobile apps insufficiently hardened.
Similarly, standards such as ISO/IEC 27001 and ISO/IEC 27002 address secure coding and application security in principle, yet stop short of prescribing concrete defensive techniques for mobile runtime environments. Sector regulations, including those influenced by U.S. Securities and Exchange Commission cyber disclosure rules or financial supervisory guidance, expect “reasonable security controls” but do not detail mobile-specific measures.
Overview of Guardsquare platform
Guardsquare specializes in protecting Android and iOS applications against reverse engineering, tampering, and runtime exploitation. Its solutions include advanced code obfuscation, string encryption, control flow protection, and runtime application self-protection (RASP) capabilities. These controls are designed to make application binaries resilient against static and dynamic analysis by attackers operating on compromised or jailbroken devices.
The platform integrates into secure software development lifecycles (SDLC), enabling enterprises to incorporate protection during build and release processes. By embedding protections into compiled code, Guardsquare helps extend compliance-oriented controls beyond policies and static testing to active runtime defense. This approach aligns with modern expectations around secure-by-design principles and software supply chain integrity.
How Guardsquare completes emerging compliance
Guardsquare’s capabilities directly support existing framework objectives related to software integrity, data protection, and resilience. Obfuscation and anti-tampering controls reinforce requirements under NIST CSF 2.0 Protect functions concerning application integrity and prevention of unauthorized code modification. Runtime detection mechanisms enhance Detect capabilities by identifying compromised execution environments.
Example of Guardsquare platform
As regulators increasingly emphasize software supply chain assurance, secure development practices, and demonstrable control effectiveness, mobile hardening becomes harder to treat as optional. By implementing protections that materially reduce the risk of reverse engineering and manipulation, enterprises can better substantiate claims of reasonable security under ISO-aligned programs and sector mandates.
They would also recommend that the Guardsquare platform, as well as other commercial vendors in the mobile app security ecosystem, can help compliance framework developers to identify practical controls that can be incorporated into emerging standards. Our observation is that the best frameworks always have an eye to what actual practitioners are buying from vendors and deploying into their production environments.
Ready to close your mobile compliance gaps?
While major regulatory frameworks are still catching up, your organization’s mobile security can’t afford to wait. Dive deeper into the intersection of mobile app risk and enterprise compliance by joining Ed Amoroso and Guardsquare’s Ryan Lloyd for their webinar, "What CISOs Should Know About the Mobile Apps Running Their Business."
Together, they will expand on the insights from this blog, discussing actionable ways to future-proof your compliance strategy and implement the robust runtime protections your mobile applications need.



