Michael Mattis

In the interview with Benjamin Richter - CEO of cyber complete GmbH

In the interview with Benjamin Richter - CEO of cyber complete GmbH

The digital world is becoming increasingly mobile – and with it, the attack surface for companies is growing. Today, smartphones are the central tool for professional communication, data access, and everyday organization. This is exactly where the upcoming interview with Benjamin Richter, Managing Director of Cyber Complete GmbH, comes in.

For over 16 years, Benjamin Richter has been focusing on information security and, together with his eight-person team, develops practical solutions for current NIS2 requirements as well as modern ISMS management concepts. A particular focus is on Mobile Security – because in times of digitalization, secure mobile devices increasingly determine a company’s resilience against cyberattacks.

In the interview with Silicon Valley Europe, the question arises as to why classic security approaches alone are no longer sufficient. Today, companies face the challenge of not only managing mobile devices but also actively protecting them against complex threats.

We will examine why the combination of Mobile Device Management (MDM) and modern Mobile Threat Defense (MTD) solutions represents the current security standard. MDM ensures centralized management, compliance with regulatory requirements, and policy control. The additional security technology of MTD also protects against threats such as phishing, malware, zero-day attacks, and network manipulations – even offline.

Another exciting aspect of the discussion will be the future of the Zero Trust approach for mobile enterprise environments. Here, context-based access controls, automated threat responses, and integration into modern identity management systems play a crucial role.

So, look forward to practical insights into current cybersecurity trends, concrete recommendations for action for companies, and a clear assessment of the risks in the mobile work environment.

Silicon Valley Europe: Mr. Richter, how has the threat landscape in the field of Mobile Security changed in recent years, and why is it so important to talk about it today?

Benjamin Richter: When I look at the past few years, one thing has clearly changed: the threat landscape in the mobile sector has dramatically intensified in recent years. In the past, smartphones were more of an additional device – today, they are the primary work tool for many employees. At the same time, mobile operating systems are becoming increasingly complex, and cybercriminals are now using methods that were previously only seen in classic IT environments.

We are observing targeted phishing attacks via messengers, manipulated Wi-Fi networks, zero-day exploits, or malware specifically developed for Android and iOS. In short: the attack surface is growing rapidly, but many companies are still implementing mobile security measures at the level of five years ago.

That’s why it’s so important to talk about this now: mobile security is no longer a “nice-to-have,” but a central component of corporate resilience.

Silicon Valley Europe: Why is classic mobile device management no longer sufficient on its own to effectively protect companies?

Benjamin Richter: A mobile device management – MDM for short – primarily sets rules: encrypt devices, activate screen locks, control apps. That’s important, but it doesn’t prevent an attack. An MDM neither detects phishing nor zero-day attacks, nor does it protect against manipulated networks.

You can compare it to a burglar alarm in a house that only checks whether doors and windows are closed – but doesn’t notice when someone tries to break in.

That’s why you need Mobile Threat Defense (MTD) as a supplement. MTD solutions analyze the actual behavior of the device, detect dangerous activities, and block attacks in real time – even offline. Only the combination of MDM and MTD creates a modern security standard.

Silicon Valley Europe: What role does artificial intelligence play in detecting modern cyberattacks on mobile devices?

Benjamin Richter: AI plays an enormously important role in cyber defense. The development of new attack methods is so dynamic that conventional, purely signature-based detection is no longer sufficient. Artificial intelligence can identify anomalies that are barely visible to human analysts and respond in seconds—a speed that is crucial given the pace of mobile attacks. Examples of such anomalies include suspicious behavior of an application (app), unusual network traffic, changes at the operating system level, or manipulated login processes.

Silicon Valley Europe: What risks do you particularly warn companies about when employees use smartphones for work purposes?

Benjamin Richter: On the one hand, there is a clear shift toward phishing attacks outside of classic email communication. Cybercriminals are increasingly using messaging services like WhatsApp or even traditional SMS messages to deceive their victims. These channels pose a particular challenge because established email security systems do not apply here, and employees find it more difficult to recognize such subtle fraud attempts.

A second critical area is the threat posed by insecure networks. In particular, manipulated or inadequately secured public hotspots, such as those in hotels or cafés, are deliberately used for so-called man-in-the-middle attacks. Users who access sensitive corporate data via these networks typically do not notice such attacks, which poses a significant security risk.

Third, mobile applications (apps) represent a growing threat. Seemingly harmless or useful applications secretly extract sensitive data in the background. This includes not only personal information such as location or contact lists but also confidential corporate data stored on the device. Often, this data exfiltration occurs without the user’s clear and conscious consent, underscoring the scale of the problem. These three threat scenarios require companies to implement a comprehensive security strategy that goes beyond protecting classic IT infrastructure.

Silicon Valley Europe: How can the zero-trust approach be implemented specifically in the mobile work environment?

Benjamin Richter: The principle of continuous distrust, known as Zero Trust, essentially states: “Trust nothing and no one – continuously verify everything and everyone.” For dealing with mobile devices, this results in an automated and ongoing security posture. This manifests in context-dependent access control, where access to corporate data is dynamically verified based on factors such as location, device status, app integrity, and network. In addition, risk-based decisions are made: if a device exhibits suspicious behavior, access is automatically restricted, with Mobile Device Management (MDM) and Mobile Threat Defense (MTD) solutions providing the necessary real-time data. Another core element is continuous verification, where identities are not only confirmed at initial login but continuously thereafter. Zero Trust is thus not a single product, but an automated, ongoing security process.

Silicon Valley Europe: What should SMEs do as a first step to future-proof their mobile security strategy?

Benjamin Richter: Before companies take concrete action, an honest inventory is required first, because many companies actually underestimate the prevalence of shadow IT in the mobile environment. They should clarify how many mobile devices are actually in use, which apps are being used on them, and who is responsible for management and security. Based on this, I recommend the following measures: First, implement MDM (Mobile Device Management) as a foundation to meet basic compliance requirements. This must be supplemented by MTD (Mobile Threat Defense), which is essential for actively detecting and defending against mobile attacks. At the same time, you need to define roles and responsibilities – mobile security must not be an afterthought, but requires clear ownership. And don’t forget to train and sensitize your employees, because the best technology is useless if user behavior creates security risks.

Silicon Valley Europe: What role does Mobile Threat Defense play in remote and hybrid work?

Benjamin Richter: The widespread adoption of remote work – employees now work from anywhere, whether in the home office, on the train, or in a hotel – means that companies lose control over the networks their devices are connected to.

This is exactly where MTD (Mobile Threat Defense) comes in and demonstrates its strength: MTD protects the device regardless of location or network. This ensures a level of security that was previously only possible within the corporate network.

Without MTD, remote work essentially represents an open security gap.

Silicon Valley Europe: How will mobile cyber security develop over the next five years – and what should companies be prepared for?

Benjamin Richter: Companies should prepare for IT security to become increasingly dynamic and respond in real time. Static rules are no longer sufficient. Companies need to adapt to flexible systems that detect attacks before any damage occurs. Absolutely. The crucial question we need to ask ourselves is: Which developments will significantly shape IT security in the coming years, and what does this mean for companies?

The coming years will be marked by enormous dynamism in IT security, with several key areas standing out: First, the use of artificial intelligence (AI) will intensify – this applies to both attack and defense strategies. Second, the automation of security processes will be absolutely necessary to relieve IT departments. Third, there will be a greater need for convergent protection, meaning identity and device protection must be more deeply integrated. Fourth, the increasing regulation through new EU directives such as NIS2 and DORA will significantly raise requirements. And fifth, behavior-based detection of attacks, which relies on pattern analysis, will gain significant importance.

The implication for companies is clear: Static security concepts are outdated. IT security will become highly dynamic and require real-time responses. The focus must be on flexible systems capable of preventively detecting and repelling attacks before any damage can occur.

Silicon Valley Europe: Thank you for this truly insightful discussion on the topic of mobile cyber security.