Analyst Spotlight
Kumar Gaurav
Solutions Architect
Jamf
Mobile Is No Longer a Channel. It Is the Workplace.
Why mobile policy has become a CISO’s decision — and why DPDP makes deferring it expensive
For most Indian enterprises, the majority of daily work now happens on a phone: approvals, customer records, messaging, increasingly AI assistants. Adoption ran ahead of governance. Mobile was onboarded as a convenience channel and never reclassified as primary infrastructure, so it inherited neither the control rigour of the laptop estate nor the scrutiny of the data centre.
That gap shows up as a split between management and security. Management answers whether a device is enrolled, configured and patched. Security answers whether it is trustworthy right now — jailbroken, on a hostile network, carrying a malicious profile, phished in the browser. Most organisations invested in the first and assumed it delivered the second. Enrolment is a state; trust is a moment. A compliant device can be actively compromised, and configuration alone will never tell you.
Shadow IT is the visible symptom, not the disease. Staff route work through personal messaging, consumer storage and unsanctioned AI tools because the sanctioned path is slower or absent. Each workaround moves corporate data — often personal data — onto infrastructure with no contract, no retention rule, no audit trail. Restricting harder rarely works on a device the user owns. The durable fix is making the managed path better than the workaround.
Meanwhile, Apple and Android have deliberately narrowed device-wide control, separating work and personal data at the OS layer. The enrolment model chosen for a device now sets a hard ceiling on what can ever be enforced or inspected, and no policy raises it. Ownership architecture, not policy authoring, is the real control decision.
DPDP Act converts this operational debt into legal exposure. Once the Rules bite, an employee’s phone holding customer data is a processing location the organisation must be able to describe: what personal data sits there, on what basis, for what purpose, and how a breach would be scoped and notified. “We are not certain what is on those devices” will not survive an inquiry. Full compliance falls due May 2027.
The question worth putting to the team is not how many devices are enrolled. It is this: where does our regulated data actually live, what could we prove about those devices today, and what would we be unable to do if one were compromised tomorrow?