Mobility & Endpoint

Mobile Threat Defence

Managed mobile devices are still endpoints, and endpoints get attacked. Powered by Zimperium, CDTS delivers and operates Australia’s only sovereign, IRAP-assessed (PROTECTED) Mobile Threat Defense solution — and manages the assessed Oracle Cloud Infrastructure environment it runs on.

MDM tells you a device is compliant with your policy. It does not tell you the device is being attacked. Mobile Threat Defence closes that gap — detecting malicious networks, hostile apps, device compromise and phishing on the handset itself.

The Zimperium engine runs its detection on-device using machine learning, so it works with no network connection and without shipping user traffic to a cloud analyser. That matters for privacy, and it matters more for people who work where connectivity is not guaranteed.

The platform behind it is hosted onshore in a sovereign Australian data centre and has been IRAP assessed at PROTECTED. It runs on Oracle Cloud Infrastructure — itself IRAP assessed at PROTECTED, including a dedicated Canberra region for government and defence — and CDTS manages that environment.

CDTS delivers the rest as a managed capability: deployment through your MDM, tuned detection policy, triage of what fires, and the integration work that turns a detection into an access decision rather than an email nobody reads.

Sovereign mobile threat defence

Australia’s only IRAP-assessed (PROTECTED) Mobile Threat Defense solution

CDTS is the only company positioned to deliver it — we manage the IRAP-assessed Oracle Cloud Infrastructure environment it runs in, from Canberra.

Zimperium built Australia’s first and only sovereign-hosted Mobile Threat Defense capability: the platform runs onshore in a sovereign Australian data centre, and it has been IRAP assessed at PROTECTED against the Australian Signals Directorate’s standards.

CDTS manages the IRAP-assessed Oracle Cloud Infrastructure environment that capability runs on, and we design, deploy and operate the service on top of it — deployment through your MDM, detection policy, triage of what fires, and the integration work that turns a detection into an access decision.

That combination is why no one else in the country is positioned the same way. The assessment belongs to the solution and to the platform; the operating knowledge belongs to us.

PROTECTED IRAP assessment level
Sovereign Onshore Australian hosting
OCI The assessed environment we manage
On-device Detection runs locally, works offline

The only assessed MTD in Australia

Powered by Zimperium — Australia’s first and only sovereign-hosted Mobile Threat Defense solution, IRAP assessed at PROTECTED.

We manage the assessed environment

It runs on Oracle Cloud Infrastructure, itself IRAP assessed at PROTECTED including a dedicated Canberra region for government and defence. CDTS manages that environment.

And we operate the capability

Deployment, detection tuning, triage and conditional access integration — run by the same Canberra team, with security-cleared resources available.

IRAP assessment at PROTECTED attaches to the Zimperium Mobile Threat Defense solution and to Oracle Cloud Infrastructure. CDTS manages that environment and delivers the capability; CDTS itself holds no IRAP assessment.

Attack surface

Four vectors, detected on the device

Mobile attacks do not look like desktop attacks. The on-device engine watches all four surfaces at once, in real time, with no cloud lookup in the path.

01

Network

Rogue access points, interception and unsafe networks — on devices that roam onto untrusted Wi-Fi constantly and by design.

02

Device

Jailbreak, root and OS-level exploitation, including zero-day chains needing no user interaction — caught by behavioural analysis of OS, memory and CPU deviation rather than by signature.

03

Application

App vetting for permissions, embedded SDK behaviour, data transmission and malware risk — across both enterprise and personal apps.

04

Phishing

Mobile-targeted phishing across SMS, messaging apps, QR codes and in-app links — the vector where a handset is structurally weaker than a desktop.

What’s included

Scope of the service

The components we deliver and operate under this service. Scope is agreed per engagement — this is the standard shape.

01

On-device detection

Machine-learning detection across device, network, application and phishing vectors — operating offline and in real time.

02

Phishing & malicious link protection

Coverage beyond email — SMS, messaging apps, QR codes and in-app links, which is where mobile users are actually targeted.

03

App vetting & scanning

Automated privacy and security analysis of the apps in your catalogue, including what they transmit and where it goes.

04

Conditional access integration

Threat signals fed to Intune and Entra ID Conditional Access so a compromised device is quarantined, not just flagged.

05

SIEM & SOC integration

Detection events exported to your SIEM in a form your analysts can actually use, with agreed severity mapping.

06

Sovereign, assessed hosting

Hosted onshore in a sovereign Australian data centre on Oracle Cloud Infrastructure — IRAP assessed at PROTECTED, and managed by CDTS.

07

On-demand forensics

Forensic scanning a user can run after joining an unknown network or returning from high-risk travel, with the evidence an investigator will ask for.

08

Privacy-preserving deployment

Configurable privacy settings and selective end-user alerting, so device risk reaches your organisation without exposing personal app or browsing data — the reason it holds up on BYO fleets.

09

Managed triage

CDTS reviews what fires, suppresses the noise, and escalates the detections that warrant a human — so the capability stays trusted.

Platforms & vendors we deliver on
  • Zimperium MTD
  • Oracle Cloud Infrastructure
  • Microsoft Intune
  • Entra ID Conditional Access
  • Ivanti Neurons for MDM

Common questions

What exactly is IRAP-assessed here?

Two things: the Zimperium Mobile Threat Defense solution is IRAP assessed at PROTECTED, and the Oracle Cloud Infrastructure environment it runs on is IRAP assessed at PROTECTED. Both assessments attach to those platforms — not to CDTS as a company. We are the partner that manages the environment and operates the capability.

What makes CDTS the only company positioned to deliver this?

We manage the IRAP-assessed Oracle Cloud Infrastructure environment that Australia’s sovereign-hosted MTD capability runs on, from Canberra, and we operate the service on top of it. No other Australian provider holds both halves of that.

Where is the data held?

Onshore. The platform is hosted in a sovereign Australian data centre, and detection itself happens on the device rather than in the cloud, so there is very little to hold in the first place.

Does it read user traffic?

No. Detection is performed on the device by the local engine. Content is not proxied to a cloud service for inspection, which is the reason it holds up in privacy-sensitive environments.

Will it work on BYO devices?

Yes, and the privacy model is a large part of why. We can deploy in a mode that reports device risk to your organisation without exposing personal app or browsing data.

Next step

Talk to us about Mobile Threat Defence

Tell us what the environment looks like today. We will tell you honestly whether this is the right place to start.