Jamf Mobile Forensics: for the small number of people whose phone is genuinely a target.
Formerly Jamf Executive Threat Protection. Ordinary mobile security assumes an attacker who needs you to tap something. Mercenary spyware such as Pegasus, Predator and Graphite does not: it can arrive with no interaction at all, leave almost nothing visible, and sit on a phone that looks entirely normal. This product exists to detect that class of compromise and produce evidence of it. Most organisations do not need it, and we will tell you if you are one of them.

- iOS and AndroidBoth mobile platforms covered
- Zero-clickDetects no-interaction compromise
- Remote DFIRNo need to take the phone away
- Honest gateWe say no more often than yes
Seven capabilities, all pointed at one hard problem.
Detection of advanced mobile attacks, including zero-click
The threats this addresses are the ones that do not require a user mistake. A zero-click attack reaches the device through a message or a call that the target never has to open, which means every piece of user awareness training you have run is irrelevant to it. Detection has to happen through artefacts on the device rather than through anything the user could notice or report.
Automated collection and analysis of device artefacts
The product collects the diagnostic and forensic data a mobile device retains and analyses it for indicators associated with known spyware families and attack techniques. Doing this manually is specialist work that takes an experienced analyst a long time per device. Automating the collection is what makes it viable to check a group of people routinely rather than only after somebody already suspects something.
Remote DFIR, so the phone stays with its owner
Digital forensics and incident response performed remotely rather than by taking custody of the handset. This matters more than it sounds. The people most likely to need this check are the least able to hand their phone over for a week, and a control that requires them to do so is a control that will not be used. Remote collection removes the excuse.
AI-assisted analysis of the collected evidence
Jamf has added AI analysis to help interpret the collected data and prioritise what an analyst should look at first. Treat this as triage rather than as a verdict: it narrows a very large volume of artefacts down to what deserves human attention, which is genuinely useful, and it is not a substitute for the human judgement that follows.
Incident management built for a security operations team
Detections arrive as managed incidents with a rules engine behind them rather than as isolated alerts, so an operations team can work them in a defined process. If you do not have a security operations function, this is a signal worth reading: the product assumes somebody is going to act on what it finds, and buying detection with nobody to respond is the same mistake organisations make with endpoint security generally.
Coverage across iOS, iPadOS and Android
The high-risk individuals in most UAE organisations do not all carry the same platform, and executives frequently carry two devices. Coverage across both major platforms means the assessment is of the person rather than of one handset, which is the only way it is meaningful. Analyst work is done from macOS or Windows.
Evidence you can act on and hand over
The output is a documented forensic finding rather than a pop-up. That is what allows a legal team, a regulator, a board or an external investigator to do something with it. A suspicion that a phone is compromised is nearly useless. A documented artefact-level finding is the difference between a difficult conversation and a defensible one.
Most organisations do not need this, and the basics beat it every time.
This is a specialist product for a narrow problem, and it is easy to sell badly by frightening people. We would rather lose the enquiry than sell advanced mobile forensics to an organisation whose actual exposure is an unpatched laptop and shared passwords.
- The realistic threat for almost every UAE business is not mercenary spyware. It is business email compromise, an invoice redirected because somebody read a mailbox, ransomware through an exposed remote access service, and credentials reused from a public breach. If those are open, spend there first. The return per dirham is not close.
- Apple Lockdown Mode is free, built in, and for a genuinely high-risk individual it is a far bigger reduction in attack surface than any product you can buy. It restricts the message and web features that this class of attack tends to use. It is inconvenient, which is exactly why people avoid enabling it, and that inconvenience is the trade being made.
- Detection is not prevention. This product finds and evidences a compromise. It does not stop one. If the objective is to reduce the chance of being compromised in the first place, the work is device hardening, disciplined patching, restricting who can reach the individual by message, and reducing what is on the device at all.
- Buying detection without a plan for the answer is the common failure. Decide in advance who is told if a device is found compromised, who makes the call to isolate or replace it, what happens to the data that may already have gone, and whether a legal or regulatory notification follows. That plan is harder than the purchase and more valuable.
Four commitments on a subject that is easy to sell dishonestly.
We will tell you if you do not need it
The first output of any conversation about this is an assessment of whether anyone in your organisation is plausibly a target for this class of attack. For most UAE businesses the answer is no, and we will say so directly and point you at the work that would actually reduce your risk instead. We would rather have that reputation than the revenue.
Free hardening comes before paid detection, always
Lockdown Mode, current operating system versions, removing unused message-receiving apps and restricting who can reach an individual are all free and all more valuable than detection for reducing the chance of compromise. We implement those first and quantify what is left before recommending a product on top.
We plan the response before we deploy the detection
Before anything is switched on we agree who is notified, who decides, how quickly a device can be replaced, when counsel is engaged and what a regulatory notification would look like. Detection without a decided response produces a crisis at the worst possible moment, and that plan is genuinely harder to write than the deployment is to run.
Discretion, and a named contact rather than a queue
Work of this kind involves individuals rather than systems, and it is handled by named people on our side with the confidentiality that implies. Findings are reported to whoever you nominate and to nobody else. Our response tiers apply, P1 within 5 minutes, but for this work the more relevant commitment is that you always speak to somebody who already knows the context.
Six situations where the conversation is warranted.
A family office or private investment vehicle
Small teams, very high value information, and principals whose movements and intentions are commercially valuable to others. The attack surface is a handful of phones belonging to people who travel constantly and cannot be told to stop using their devices normally. This is close to the archetype the product was designed for.
A board or executive committee of a listed or regulated entity
Advance knowledge of a transaction, a result or a regulatory outcome has direct financial value, and board members are often the least managed devices in the organisation because nobody wants to impose policy on them. That combination is the problem. This is one of the few controls that can be applied to a small named group without a wider policy fight.
A law firm handling sensitive or contested matters
Privileged material, adversarial parties with resources, and a professional obligation of confidentiality that a compromise would breach directly. For firms in DIFC or ADGM the professional consequences of an undetected compromise are not only commercial, which changes how proportionate a specialist control looks.
Media, publishing and civil society organisations
People who publish on contested subjects are a documented target group for mercenary spyware globally. The individuals concerned frequently have no IT support at all, which means the practical work is often as much about basic hardening and sensible habits as about any product, and we approach it that way.
Executives who travel to higher-risk jurisdictions
Exposure attaches to the person and to where they go rather than to the head office. The usual pattern we recommend here is a hardened travel device carrying the minimum necessary, checked before and after travel, rather than continuous monitoring of the everyday phone. It is cheaper, less intrusive, and addresses the actual window of risk.
Organisations that already suspect something
Sometimes the enquiry follows an incident: an unexplained leak, a negotiation where the other side clearly knew too much, a device behaving oddly. Here the requirement is investigative rather than preventive, it is usually urgent, and it needs handling in a way that preserves evidence rather than destroying it. Do not factory reset the device before speaking to somebody.
What high-risk mobile exposure looks like in practice.
| Feature | Assessed and monitored | Aware but unaddressed | Not considered |
|---|---|---|---|
High-risk individuals formally identified | Informally | ||
Lockdown Mode enabled where warranted | Rarely | ||
Devices patched without exception | Mostly | Unknown | |
Device artefacts ever examined | Routinely | Never | Never |
Compromise would be detected | Likely | Only by chance | No |
Evidence available if it were | |||
Response plan agreed in advance | |||
Legal counsel briefed | |||
Replacement device available same day | Sometimes | ||
Typical position in the UAE market | Uncommon | Common | The default |
Mobile management, mobile security and mobile forensics do different jobs.
| Mobile device management | Mobile threat defence | Mobile forensics | |
|---|---|---|---|
| Enforces passcode, encryption, updates | Yes | No | No |
| Blocks phishing and malicious sites | Limited | Yes | No |
| Detects ordinary mobile malware | No | Yes | Not its purpose |
| Detects zero-click and mercenary spyware | No | Rarely | Yes, this is the point |
| Collects deep on-device artefacts | No | No | Yes |
| Produces documented forensic evidence | No | No | Yes |
| Needed by most organisations | Yes | Usually yes | Rarely |
| Applies to the whole workforce | Yes | Yes | A named few |
| Requires somebody to respond to findings | Some | Yes | Absolutely |
| Where to spend first | First | Second | Only when justified |
Five stages, and the first two are free of any product.
- 1
Establish whether a genuine target exists
A short structured conversation about roles, travel, public profile, the value of what individuals know and who might want it. The output is a written position on whether anyone in the organisation plausibly falls into this risk category. For most organisations this stage ends the engagement, which is the correct outcome.
- 2
Harden what is free before buying anything
For the individuals identified: Lockdown Mode where they will accept it, operating system currency enforced without exception, removal of unused message-receiving applications, tightening of who can reach them directly, and a review of what data is on the device at all. This reduces exposure measurably and costs nothing but attention.
- 3
Agree the response before deploying the detection
Who is told, who decides, how fast a device can be replaced, when counsel is engaged, what notification obligations may follow, and how findings are recorded. This is written down and agreed by the people who would actually be involved, not drafted by IT and filed.
- 4
Deploy and baseline
The product is deployed to the named individuals, artefacts are collected and analysed, and a baseline position is established for each device. A clean baseline is itself a useful result: it converts an open question into a documented finding at a point in time, which is what makes any later change meaningful.
- 5
Run it, review it, and stop it when it is no longer warranted
Periodic collection and analysis, with findings reported to your nominated contact. We also review annually whether the risk profile still justifies it, because roles change and a control that was proportionate two years ago may not be now. Recommending you stop paying for something is part of the job.
“We came in expecting to be sold a product and were told in the first meeting that only two people in the business plausibly needed it, and that we should fix our patching before we spent anything at all. They were right, and it is why we now use them for everything else.”
The questions people actually ask about this.
Twelve questions that decide whether this conversation is worth having.
Is there a real target
- Does anyone hold a government, diplomatic or public office role?The clearest indicator, and the one this product was built around.
- Does anyone negotiate transactions where advance knowledge is worth a great deal?Deal teams, boards and family offices are commercially attractive targets.
- Does anyone work in or travel regularly to a high-risk jurisdiction?Exposure follows the person, not the office.
- Does anyone publish, report or campaign publicly on contested subjects?Journalists and civil society are a documented target group for this class of tooling.
Has the free hardening been done
- Is Lockdown Mode enabled on the devices of the people identified above?Free, built in, and the largest single reduction available.
- Are devices on the current operating system version, without exception?This class of attack chases unpatched flaws. Patch latency is the exposure.
- Have unused messaging apps been removed from those devices?Every message-receiving app is an inbound surface.
- Can strangers reach those individuals directly by message or call?Restricting who can reach someone is an underrated control.
Could you act on a finding
- Is there a named person who would be told first?Findings of this kind cannot go through a general helpdesk queue.
- Do you have legal counsel briefed in advance?The response is a legal question as much as a technical one.
- Could you replace a compromised device the same day?A finding you cannot act on for a week is a finding of limited value.
- Do you know what regulatory notification would apply?UAE data protection obligations may follow depending on what was exposed.
The layers underneath this one.
Jamf Protect for UAE Mac estates
Everyday endpoint security for Macs, and an honest comparison against what Microsoft Defender already covers if you are licensed for it.
Mobile device management in Dubai
The layer every organisation should have first: enrolment, encryption, passcode policy, update compliance and what happens when a device is lost.
Cybersecurity companies in Dubai
The wider security practice, and how to judge whether a provider is selling you controls that match your actual threat profile.
Start with whether anyone here is actually a target.
That question is free to answer and it decides everything after it. If the answer is no, we will tell you plainly and point you at the work that would genuinely reduce your risk. If it is yes, we will start with the hardening that costs nothing before recommending anything you have to buy.
Related Services
Explore more solutions that work great with this service
Jamf Protect UAE
macOS endpoint security, honestly compared with Defender
Apple Device Management
Mac and iPhone fleets, encryption, patching and the September cycle
MDM Solutions Dubai
Device management across Windows, Apple and Android
Endpoint Security
Defender for Endpoint and Intune managed
Cybersecurity Companies Dubai
Cyber buyer's guide, 7 services to evaluate
Managed Security Services
MSS on Microsoft Defender XDR and Sentinel
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations