Mobile Threat Defence
Managed mobile devices are still endpoints, and endpoints get attacked. Powered by Zimperium, CDTS delivers and operates Australia’s only sovereign, IRAP-assessed (PROTECTED) Mobile Threat Defense solution — and manages the assessed Oracle Cloud Infrastructure environment it runs on.
MDM tells you a device is compliant with your policy. It does not tell you the device is being attacked. Mobile Threat Defence closes that gap — detecting malicious networks, hostile apps, device compromise and phishing on the handset itself.
The Zimperium engine runs its detection on-device using machine learning, so it works with no network connection and without shipping user traffic to a cloud analyser. That matters for privacy, and it matters more for people who work where connectivity is not guaranteed.
The platform behind it is hosted onshore in a sovereign Australian data centre and has been IRAP assessed at PROTECTED. It runs on Oracle Cloud Infrastructure — itself IRAP assessed at PROTECTED, including a dedicated Canberra region for government and defence — and CDTS manages that environment.
CDTS delivers the rest as a managed capability: deployment through your MDM, tuned detection policy, triage of what fires, and the integration work that turns a detection into an access decision rather than an email nobody reads.
Australia’s only IRAP-assessed (PROTECTED) Mobile Threat Defense solution
CDTS is the only company positioned to deliver it — we manage the IRAP-assessed Oracle Cloud Infrastructure environment it runs in, from Canberra.
Zimperium built Australia’s first and only sovereign-hosted Mobile Threat Defense capability: the platform runs onshore in a sovereign Australian data centre, and it has been IRAP assessed at PROTECTED against the Australian Signals Directorate’s standards.
CDTS manages the IRAP-assessed Oracle Cloud Infrastructure environment that capability runs on, and we design, deploy and operate the service on top of it — deployment through your MDM, detection policy, triage of what fires, and the integration work that turns a detection into an access decision.
That combination is why no one else in the country is positioned the same way. The assessment belongs to the solution and to the platform; the operating knowledge belongs to us.
The only assessed MTD in Australia
Powered by Zimperium — Australia’s first and only sovereign-hosted Mobile Threat Defense solution, IRAP assessed at PROTECTED.
We manage the assessed environment
It runs on Oracle Cloud Infrastructure, itself IRAP assessed at PROTECTED including a dedicated Canberra region for government and defence. CDTS manages that environment.
And we operate the capability
Deployment, detection tuning, triage and conditional access integration — run by the same Canberra team, with security-cleared resources available.
IRAP assessment at PROTECTED attaches to the Zimperium Mobile Threat Defense solution and to Oracle Cloud Infrastructure. CDTS manages that environment and delivers the capability; CDTS itself holds no IRAP assessment.
Four vectors, detected on the device
Mobile attacks do not look like desktop attacks. The on-device engine watches all four surfaces at once, in real time, with no cloud lookup in the path.
Network
Rogue access points, interception and unsafe networks — on devices that roam onto untrusted Wi-Fi constantly and by design.
Device
Jailbreak, root and OS-level exploitation, including zero-day chains needing no user interaction — caught by behavioural analysis of OS, memory and CPU deviation rather than by signature.
Application
App vetting for permissions, embedded SDK behaviour, data transmission and malware risk — across both enterprise and personal apps.
Phishing
Mobile-targeted phishing across SMS, messaging apps, QR codes and in-app links — the vector where a handset is structurally weaker than a desktop.
Scope of the service
The components we deliver and operate under this service. Scope is agreed per engagement — this is the standard shape.
On-device detection
Machine-learning detection across device, network, application and phishing vectors — operating offline and in real time.
Phishing & malicious link protection
Coverage beyond email — SMS, messaging apps, QR codes and in-app links, which is where mobile users are actually targeted.
App vetting & scanning
Automated privacy and security analysis of the apps in your catalogue, including what they transmit and where it goes.
Conditional access integration
Threat signals fed to Intune and Entra ID Conditional Access so a compromised device is quarantined, not just flagged.
SIEM & SOC integration
Detection events exported to your SIEM in a form your analysts can actually use, with agreed severity mapping.
Sovereign, assessed hosting
Hosted onshore in a sovereign Australian data centre on Oracle Cloud Infrastructure — IRAP assessed at PROTECTED, and managed by CDTS.
On-demand forensics
Forensic scanning a user can run after joining an unknown network or returning from high-risk travel, with the evidence an investigator will ask for.
Privacy-preserving deployment
Configurable privacy settings and selective end-user alerting, so device risk reaches your organisation without exposing personal app or browsing data — the reason it holds up on BYO fleets.
Managed triage
CDTS reviews what fires, suppresses the noise, and escalates the detections that warrant a human — so the capability stays trusted.
- Zimperium MTD
- Oracle Cloud Infrastructure
- Microsoft Intune
- Entra ID Conditional Access
- Ivanti Neurons for MDM
Common questions
What exactly is IRAP-assessed here?
Two things: the Zimperium Mobile Threat Defense solution is IRAP assessed at PROTECTED, and the Oracle Cloud Infrastructure environment it runs on is IRAP assessed at PROTECTED. Both assessments attach to those platforms — not to CDTS as a company. We are the partner that manages the environment and operates the capability.
What makes CDTS the only company positioned to deliver this?
We manage the IRAP-assessed Oracle Cloud Infrastructure environment that Australia’s sovereign-hosted MTD capability runs on, from Canberra, and we operate the service on top of it. No other Australian provider holds both halves of that.
Where is the data held?
Onshore. The platform is hosted in a sovereign Australian data centre, and detection itself happens on the device rather than in the cloud, so there is very little to hold in the first place.
Does it read user traffic?
No. Detection is performed on the device by the local engine. Content is not proxied to a cloud service for inspection, which is the reason it holds up in privacy-sensitive environments.
Will it work on BYO devices?
Yes, and the privacy model is a large part of why. We can deploy in a mode that reports device risk to your organisation without exposing personal app or browsing data.
What we have written about this
Services that usually go with this
Managed MDM & UEM
Design, migration and day-to-day operation of Ivanti, Intune, Jamf and SOTI fleets — run as a managed service.
ExploreCyber Security & Essential Eight
Assessment, uplift and controls designed to help you meet the ACSC Essential Eight, the ISM and the PSPF.
ExploreManaged IT & Service Desk
Your IT department, or the half of it you are missing. 24×7 service desk, proactive monitoring, patching and vendor management under one agreement.
ExploreTalk to us about Mobile Threat Defence
Tell us what the environment looks like today. We will tell you honestly whether this is the right place to start.