We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Apple
  2. Jamf Mobile Forensics
Jamf Mobile Forensics, UAE

Jamf Mobile Forensics: for the small number of people whose phone is genuinely a target.

Formerly Jamf Executive Threat Protection. Ordinary mobile security assumes an attacker who needs you to tap something. Mercenary spyware such as Pegasus, Predator and Graphite does not: it can arrive with no interaction at all, leave almost nothing visible, and sit on a phone that looks entirely normal. This product exists to detect that class of compromise and produce evidence of it. Most organisations do not need it, and we will tell you if you are one of them.

Request a high-risk user assessmentSee whether it applies to you
Advanced mobile threat detection and forensics in the UAE
  • iOS and AndroidBoth mobile platforms covered
  • Zero-clickDetects no-interaction compromise
  • Remote DFIRNo need to take the phone away
  • Honest gateWe say no more often than yes
What the product does

Seven capabilities, all pointed at one hard problem.

The hard problem is that a sophisticated mobile compromise leaves very little for a user or an administrator to see. Detecting it needs deep artefacts off the device and somebody qualified to read them, and both halves are what this covers.

Detection of advanced mobile attacks, including zero-click

The threats this addresses are the ones that do not require a user mistake. A zero-click attack reaches the device through a message or a call that the target never has to open, which means every piece of user awareness training you have run is irrelevant to it. Detection has to happen through artefacts on the device rather than through anything the user could notice or report.

Automated collection and analysis of device artefacts

The product collects the diagnostic and forensic data a mobile device retains and analyses it for indicators associated with known spyware families and attack techniques. Doing this manually is specialist work that takes an experienced analyst a long time per device. Automating the collection is what makes it viable to check a group of people routinely rather than only after somebody already suspects something.

Remote DFIR, so the phone stays with its owner

Digital forensics and incident response performed remotely rather than by taking custody of the handset. This matters more than it sounds. The people most likely to need this check are the least able to hand their phone over for a week, and a control that requires them to do so is a control that will not be used. Remote collection removes the excuse.

AI-assisted analysis of the collected evidence

Jamf has added AI analysis to help interpret the collected data and prioritise what an analyst should look at first. Treat this as triage rather than as a verdict: it narrows a very large volume of artefacts down to what deserves human attention, which is genuinely useful, and it is not a substitute for the human judgement that follows.

Incident management built for a security operations team

Detections arrive as managed incidents with a rules engine behind them rather than as isolated alerts, so an operations team can work them in a defined process. If you do not have a security operations function, this is a signal worth reading: the product assumes somebody is going to act on what it finds, and buying detection with nobody to respond is the same mistake organisations make with endpoint security generally.

Coverage across iOS, iPadOS and Android

The high-risk individuals in most UAE organisations do not all carry the same platform, and executives frequently carry two devices. Coverage across both major platforms means the assessment is of the person rather than of one handset, which is the only way it is meaningful. Analyst work is done from macOS or Windows.

Evidence you can act on and hand over

The output is a documented forensic finding rather than a pop-up. That is what allows a legal team, a regulator, a board or an external investigator to do something with it. A suspicion that a phone is compromised is nearly useless. A documented artefact-level finding is the difference between a difficult conversation and a defensible one.

Read this before enquiring

Most organisations do not need this, and the basics beat it every time.

This is a specialist product for a narrow problem, and it is easy to sell badly by frightening people. We would rather lose the enquiry than sell advanced mobile forensics to an organisation whose actual exposure is an unpatched laptop and shared passwords.

  • The realistic threat for almost every UAE business is not mercenary spyware. It is business email compromise, an invoice redirected because somebody read a mailbox, ransomware through an exposed remote access service, and credentials reused from a public breach. If those are open, spend there first. The return per dirham is not close.
  • Apple Lockdown Mode is free, built in, and for a genuinely high-risk individual it is a far bigger reduction in attack surface than any product you can buy. It restricts the message and web features that this class of attack tends to use. It is inconvenient, which is exactly why people avoid enabling it, and that inconvenience is the trade being made.
  • Detection is not prevention. This product finds and evidences a compromise. It does not stop one. If the objective is to reduce the chance of being compromised in the first place, the work is device hardening, disciplined patching, restricting who can reach the individual by message, and reducing what is on the device at all.
  • Buying detection without a plan for the answer is the common failure. Decide in advance who is told if a device is found compromised, who makes the call to isolate or replace it, what happens to the data that may already have gone, and whether a legal or regulatory notification follows. That plan is harder than the purchase and more valuable.
Ask us to review your actual exposure first
How we approach it

Four commitments on a subject that is easy to sell dishonestly.

Advanced mobile threats are the easiest thing in security to sell with fear and the hardest to sell honestly. These are the rules we hold ourselves to on this topic.

We will tell you if you do not need it

The first output of any conversation about this is an assessment of whether anyone in your organisation is plausibly a target for this class of attack. For most UAE businesses the answer is no, and we will say so directly and point you at the work that would actually reduce your risk instead. We would rather have that reputation than the revenue.

Free hardening comes before paid detection, always

Lockdown Mode, current operating system versions, removing unused message-receiving apps and restricting who can reach an individual are all free and all more valuable than detection for reducing the chance of compromise. We implement those first and quantify what is left before recommending a product on top.

We plan the response before we deploy the detection

Before anything is switched on we agree who is notified, who decides, how quickly a device can be replaced, when counsel is engaged and what a regulatory notification would look like. Detection without a decided response produces a crisis at the worst possible moment, and that plan is genuinely harder to write than the deployment is to run.

Discretion, and a named contact rather than a queue

Work of this kind involves individuals rather than systems, and it is handled by named people on our side with the confidentiality that implies. Findings are reported to whoever you nominate and to nobody else. Our response tiers apply, P1 within 5 minutes, but for this work the more relevant commitment is that you always speak to somebody who already knows the context.

Who this is actually for

Six situations where the conversation is warranted.

These are the profiles where we would consider this proportionate. If your organisation does not resemble one of these, the honest answer is that your money goes further elsewhere, and we will say so.

A family office or private investment vehicle

Small teams, very high value information, and principals whose movements and intentions are commercially valuable to others. The attack surface is a handful of phones belonging to people who travel constantly and cannot be told to stop using their devices normally. This is close to the archetype the product was designed for.

A board or executive committee of a listed or regulated entity

Advance knowledge of a transaction, a result or a regulatory outcome has direct financial value, and board members are often the least managed devices in the organisation because nobody wants to impose policy on them. That combination is the problem. This is one of the few controls that can be applied to a small named group without a wider policy fight.

A law firm handling sensitive or contested matters

Privileged material, adversarial parties with resources, and a professional obligation of confidentiality that a compromise would breach directly. For firms in DIFC or ADGM the professional consequences of an undetected compromise are not only commercial, which changes how proportionate a specialist control looks.

Media, publishing and civil society organisations

People who publish on contested subjects are a documented target group for mercenary spyware globally. The individuals concerned frequently have no IT support at all, which means the practical work is often as much about basic hardening and sensible habits as about any product, and we approach it that way.

Executives who travel to higher-risk jurisdictions

Exposure attaches to the person and to where they go rather than to the head office. The usual pattern we recommend here is a hardened travel device carrying the minimum necessary, checked before and after travel, rather than continuous monitoring of the everyday phone. It is cheaper, less intrusive, and addresses the actual window of risk.

Organisations that already suspect something

Sometimes the enquiry follows an incident: an unexplained leak, a negotiation where the other side clearly knew too much, a device behaving oddly. Here the requirement is investigative rather than preventive, it is usually urgent, and it needs handling in a way that preserves evidence rather than destroying it. Do not factory reset the device before speaking to somebody.

Three positions organisations take

What high-risk mobile exposure looks like in practice.

The middle column is where most organisations that have thought about this at all end up. They have identified the risk, done nothing structural about it, and rely on the individual noticing something. That reliance is misplaced, because this class of compromise is specifically designed to be unnoticeable.
High-risk individuals formally identified
Assessed and monitored
Aware but unaddressedInformally
Not considered
Lockdown Mode enabled where warranted
Assessed and monitored
Aware but unaddressedRarely
Not considered
Devices patched without exception
Assessed and monitored
Aware but unaddressedMostly
Not consideredUnknown
Device artefacts ever examined
Assessed and monitoredRoutinely
Aware but unaddressedNever
Not consideredNever
Compromise would be detected
Assessed and monitoredLikely
Aware but unaddressedOnly by chance
Not consideredNo
Evidence available if it were
Assessed and monitored
Aware but unaddressed
Not considered
Response plan agreed in advance
Assessed and monitored
Aware but unaddressed
Not considered
Legal counsel briefed
Assessed and monitored
Aware but unaddressed
Not considered
Replacement device available same day
Assessed and monitored
Aware but unaddressedSometimes
Not considered
Typical position in the UAE market
Assessed and monitoredUncommon
Aware but unaddressedCommon
Not consideredThe default
Feature
Assessed and monitored
Aware but unaddressed
Not considered
High-risk individuals formally identified
Informally
Lockdown Mode enabled where warranted
Rarely
Devices patched without exception
MostlyUnknown
Device artefacts ever examined
RoutinelyNeverNever
Compromise would be detected
LikelyOnly by chanceNo
Evidence available if it were
Response plan agreed in advance
Legal counsel briefed
Replacement device available same day
Sometimes
Typical position in the UAE market
UncommonCommonThe default
Where each control fits

Mobile management, mobile security and mobile forensics do different jobs.

These are frequently confused, and the confusion leads organisations to believe they are covered when they are not. Management controls the device. Security defends against ordinary threats. Forensics investigates the extraordinary ones. Owning one does not give you the others.
Mobile device managementMobile threat defenceMobile forensics
Enforces passcode, encryption, updatesYesNoNo
Blocks phishing and malicious sitesLimitedYesNo
Detects ordinary mobile malwareNoYesNot its purpose
Detects zero-click and mercenary spywareNoRarelyYes, this is the point
Collects deep on-device artefactsNoNoYes
Produces documented forensic evidenceNoNoYes
Needed by most organisationsYesUsually yesRarely
Applies to the whole workforceYesYesA named few
Requires somebody to respond to findingsSomeYesAbsolutely
Where to spend firstFirstSecondOnly when justified
How an engagement runs

Five stages, and the first two are free of any product.

We do not start with a deployment. We start by establishing whether there is a target, because that determines whether anything after it is justified.
  1. 1

    Establish whether a genuine target exists

    A short structured conversation about roles, travel, public profile, the value of what individuals know and who might want it. The output is a written position on whether anyone in the organisation plausibly falls into this risk category. For most organisations this stage ends the engagement, which is the correct outcome.

  2. 2

    Harden what is free before buying anything

    For the individuals identified: Lockdown Mode where they will accept it, operating system currency enforced without exception, removal of unused message-receiving applications, tightening of who can reach them directly, and a review of what data is on the device at all. This reduces exposure measurably and costs nothing but attention.

  3. 3

    Agree the response before deploying the detection

    Who is told, who decides, how fast a device can be replaced, when counsel is engaged, what notification obligations may follow, and how findings are recorded. This is written down and agreed by the people who would actually be involved, not drafted by IT and filed.

  4. 4

    Deploy and baseline

    The product is deployed to the named individuals, artefacts are collected and analysed, and a baseline position is established for each device. A clean baseline is itself a useful result: it converts an open question into a documented finding at a point in time, which is what makes any later change meaningful.

  5. 5

    Run it, review it, and stop it when it is no longer warranted

    Periodic collection and analysis, with findings reported to your nominated contact. We also review annually whether the risk profile still justifies it, because roles change and a control that was proportionate two years ago may not be now. Recommending you stop paying for something is part of the job.

“We came in expecting to be sold a product and were told in the first meeting that only two people in the business plausibly needed it, and that we should fix our patching before we spent anything at all. They were right, and it is why we now use them for everything else.”
Chief Operating Officer
Private investment firm, DIFC · Client reference available on request
Direct answers

The questions people actually ask about this.

Yes. Jamf Mobile Forensics is the current name for what was previously called Jamf Executive Threat Protection, often shortened to JETP, and Jamf states the former name explicitly in its own product documentation. The rename came alongside an expansion of the forensic analysis capability, including AI-assisted analysis and incident management for security operations teams. If you were given a proposal referring to JETP, it is this product. We mention the old name throughout because it is still what most people search for and what most existing documentation calls it.

It is a compromise that requires the target to do nothing at all. Conventional attacks need you to tap a link, open an attachment or enter credentials on a fake page, which is why user awareness training is worth running. A zero-click attack exploits a flaw in software that processes incoming data automatically, a message, an image preview, a call setup, so the device is compromised by receiving something rather than by the user acting on it. That is why it defeats awareness training completely and why detection has to happen at the device artefact level.

Almost certainly not, and this is the uncomfortable part. Commercial spyware of this class is engineered to be invisible in normal use. It does not slow the phone noticeably, it does not appear in the app list, and in many documented cases it leaves no visible trace at all. Battery drain and heat are sometimes mentioned as indicators and they are extremely unreliable, because they have a hundred ordinary explanations. Assuming you would notice is the single most common misconception on this subject.

It finds one, and it is important to be clear about that before buying. This is a detection and forensics product, not a preventive control. If your objective is to reduce the chance of compromise, the effective measures are hardening rather than detection: Lockdown Mode, immediate patching, reducing the number of applications that can receive inbound content, and limiting who can contact the individual directly. Detection has real value, because an undetected compromise continues indefinitely, but it is the second thing to buy rather than the first.

It is a built-in Apple setting that sharply restricts the features most often used to deliver this class of attack: certain message attachment types, some web technologies, incoming invitations from unknown contacts and connections from accessories. It is free, it takes a minute to enable, and for a genuinely high-risk individual it removes a substantial part of the attack surface. The catch is that it is inconvenient, some websites and attachments stop working, which is precisely why people do not enable it. For somebody who is actually a target that is a good trade, and we would rather have that argument with you than sell you a product instead of having it.

A small minority, and we would be misleading you to suggest otherwise. The great majority of UAE organisations, including many large and profitable ones, face threats that are entirely ordinary: business email compromise, ransomware through exposed remote access, credential reuse, invoice fraud. Those are the risks that materialise, and money spent closing them returns far more than money spent on advanced mobile forensics. We run this assessment as a gate, not as a funnel, and most conversations end with a recommendation to spend elsewhere.

Yes, and the most important thing is what you do before contacting us. Do not factory reset the device, do not restore it from a backup and do not attempt to clean it, because all three destroy the evidence needed to establish what happened. Keep the device powered on if you safely can, restrict what is done on it, and get in touch. Investigative work of this kind is time-sensitive because some device artefacts age out, so the sooner the collection happens the better the answer will be.

On a corporate-owned device issued for work, with a clear written policy and informed consent, this is normal security practice and we implement it that way. On a personally owned device it is a different question and needs explicit, informed and genuinely voluntary consent from the individual, documented properly. UAE data protection obligations apply to what is collected and how it is handled either way. We insist on the consent position being clear before deployment, and we will not implement this covertly on someone device on an employer instruction.

A documented forensic report identifying the artefacts observed, what they indicate, what confidence attaches to that conclusion, and what the recommended immediate actions are. It is written to be usable by people who are not forensic analysts, because the audience is typically a general counsel, a chief executive or a board rather than a security team. Where the result is clean, that is stated as clearly as an adverse finding, along with what the analysis did and did not cover, since a clean result with unstated limits is misleading.

The agreed response plan runs, which is why we insist on writing it first. Typically that means the individual is contacted directly rather than through a general channel, the device is isolated and replaced rather than cleaned, an assessment is made of what may have been exposed during the period concerned, counsel is engaged, and the question of regulatory or contractual notification is considered. The technical part is the smallest part. The difficult work is deciding what to tell whom, and doing that under time pressure without a plan goes badly.

Yes, the product covers iOS, iPadOS and Android, with the analyst-side work done from macOS or Windows. This matters practically because high-risk individuals in the UAE do not all carry the same platform and many carry two devices, a personal one and a work one, often on different platforms. Assessing only one of them gives a false result, because an attacker will go at whichever device is more reachable rather than the one you chose to monitor.

You need somebody who will act on what it produces, and that does not have to be an in-house team. The product includes incident management designed for security operations, which tells you something about the intended buyer. Where an organisation has no such function, which is most of the ones asking about this, the practical answer is that we or another provider carry that role under an agreed process. What does not work is buying detection with no named responder, because alerts nobody owns are alerts nobody reads.

They occupy different layers and none of them replaces another. Your MDM enforces device configuration, encryption, passcode policy and update compliance across the whole workforce. Jamf Protect defends Macs against ordinary endpoint threats. Mobile forensics investigates advanced mobile compromise for a named few. An organisation should generally have the first, usually wants the second, and rarely needs the third. Owning an MDM does not give you detection of this class of attack, and we correct that assumption regularly.

For a lot of situations it is the better answer, and it is cheaper. A device carrying only what a trip requires, with no historical message archive, no long-lived credentials and nothing that matters if it is lost, limits the damage of a compromise instead of trying to detect one. It also confines the risk to a defined window rather than treating the everyday phone as permanently exposed. Where somebody travels frequently to higher-risk jurisdictions, we would generally recommend this before continuous monitoring, and sometimes instead of it.

It depends on what was on the device and which regimes you sit under, and this needs answering before an incident rather than during one. The UAE Personal Data Protection Law applies to personal data generally. Firms regulated in DIFC or ADGM have their own data protection regimes and their own regulator expectations. Entities in scope of critical information infrastructure requirements may have further obligations. Professional confidentiality duties, for a law firm or an audit practice, can bite regardless of data protection law. We map which of these apply to you as part of the response planning stage.

We quote per engagement rather than publishing a figure, and for this product more than most that is a deliberate position rather than a sales tactic. The number depends on how many individuals are in scope, whether the requirement is an investigation now or ongoing monitoring, and whether you need us to carry the response role. What we will commit to is that the first conversation is an assessment of whether you need it at all, that assessment does not obligate you to anything, and if the answer is that you do not need it we will say so and tell you where the money is better spent.
Is anyone in your organisation actually high risk

Twelve questions that decide whether this conversation is worth having.

The first group establishes whether a genuine target exists. The second is the hardening that should happen regardless and usually has not. The third is what you need in place before detection is worth buying.

Is there a real target

  • Does anyone hold a government, diplomatic or public office role?
    The clearest indicator, and the one this product was built around.
  • Does anyone negotiate transactions where advance knowledge is worth a great deal?
    Deal teams, boards and family offices are commercially attractive targets.
  • Does anyone work in or travel regularly to a high-risk jurisdiction?
    Exposure follows the person, not the office.
  • Does anyone publish, report or campaign publicly on contested subjects?
    Journalists and civil society are a documented target group for this class of tooling.

Has the free hardening been done

  • Is Lockdown Mode enabled on the devices of the people identified above?
    Free, built in, and the largest single reduction available.
  • Are devices on the current operating system version, without exception?
    This class of attack chases unpatched flaws. Patch latency is the exposure.
  • Have unused messaging apps been removed from those devices?
    Every message-receiving app is an inbound surface.
  • Can strangers reach those individuals directly by message or call?
    Restricting who can reach someone is an underrated control.

Could you act on a finding

  • Is there a named person who would be told first?
    Findings of this kind cannot go through a general helpdesk queue.
  • Do you have legal counsel briefed in advance?
    The response is a legal question as much as a technical one.
  • Could you replace a compromised device the same day?
    A finding you cannot act on for a week is a finding of limited value.
  • Do you know what regulatory notification would apply?
    UAE data protection obligations may follow depending on what was exposed.
Related reading

The layers underneath this one.

Jamf Protect for UAE Mac estates

Everyday endpoint security for Macs, and an honest comparison against what Microsoft Defender already covers if you are licensed for it.

Learn more

Mobile device management in Dubai

The layer every organisation should have first: enrolment, encryption, passcode policy, update compliance and what happens when a device is lost.

Learn more

Cybersecurity companies in Dubai

The wider security practice, and how to judge whether a provider is selling you controls that match your actual threat profile.

Learn more
Next step

Start with whether anyone here is actually a target.

That question is free to answer and it decides everything after it. If the answer is no, we will tell you plainly and point you at the work that would genuinely reduce your risk. If it is yes, we will start with the hardening that costs nothing before recommending anything you have to buy.

Request a high-risk user assessmentCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Jamf Protect UAE

macOS endpoint security, honestly compared with Defender

Learn more

Apple Device Management

Mac and iPhone fleets, encryption, patching and the September cycle

Learn more

MDM Solutions Dubai

Device management across Windows, Apple and Android

Learn more

Endpoint Security

Defender for Endpoint and Intune managed

Learn more

Cybersecurity Companies Dubai

Cyber buyer's guide, 7 services to evaluate

Learn more

Managed Security Services

MSS on Microsoft Defender XDR and Sentinel

Learn more

UAE PDPL Compliance

Federal Decree-Law 45 of 2021 readiness and operations

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy