**Lookout’s Mobile Security Exposure Center: Shifting from Reactive to Proactive Risk Management**
In today’s distributed work environment, mobile devices have become the new edge—and securing that edge is more challenging than ever. Unlike traditional corporate endpoints, mobile devices operate outside the established security perimeter. Security teams often have visibility into which applications are installed but lack the capability to analyze the intricate components and dependencies within those apps. This gap creates significant risk, as hidden vulnerabilities can lurk in seemingly harmless software.
Jim Dolce, CEO of Lookout, highlighted a critical example involving WolfSSL, a lightweight SSL/TLS library used in billions of devices. Many banking applications rely on this library, and a serious vulnerability within it could allow attackers to impersonate financial institutions and steal user credentials. While such vulnerabilities may be discovered and publicized— as seen with the Mythos Glasswing project—security teams often remain unaware that the very apps used by their employees contain these risks.
“The name and version of an app only tell part of the story,” Lookout explains. “True security requires visibility into the software components, dependencies, and vulnerabilities hidden beneath the surface.”
To address this challenge, Lookout introduced the **Mobile Security Exposure Center (MSEC)**, a solution designed to provide complete transparency into an organization’s mobile fleet. MSEC works by scanning every device in the network, identifying installed applications, and generating a proprietary Software Bill of Materials (SBOM) from each app’s binary data. This SBOM breaks down the app into its individual components, which are then cross-referenced with vulnerability databases like the CISA Known Exploited Vulnerabilities (KEV) catalog. The findings are integrated into the organization’s CTEM (Continuous Threat Exposure Management) framework, enabling security teams to take timely remediation actions.
“The system will identify which apps use WolfSSL, the version of that app, the user and the device that is using that app, and all of that information can then be used to remediate the exposure,” Dolce explains. MSEC applies this analysis to all software components across all mobile devices, offering a comprehensive view of application risk.
MSEC also complements Lookout’s existing AI Visibility & Governance product. While AI Visibility & Governance focuses on understanding AI adoption and usage across the enterprise, MSEC reveals the software composition and exposure profile of those applications. Together, they provide a more complete picture of application risk, security, and governance—shifting the focus from reactive management to proactive exposure management.
However, even with robust known-vulnerability scanning, new threats can emerge. Not all vulnerabilities are known at the time of scanning, and emerging threats—such as those potentially uncovered by advanced AI models—can expose new attack surfaces.
Lookout acknowledges this challenge and is already addressing it. “Bad actors can use frontier AI models, like Mythos, to find and exploit vulnerabilities,” Dolce notes. “But we can use the same technology defensively.” The next iteration of MSEC will leverage frontier AI models to identify unknown vulnerabilities within SBOMs, staying one step ahead of malicious actors.
In essence, MSEC’s roadmap starts with inventory awareness—knowing which apps are present across the mobile fleet. It then moves to SBOM creation, correlation with known vulnerability databases, and finally, the use of defensive AI to uncover previously unknown risks.
**Related Readings**
– Mobile Attack Surface Expands as Enterprises Lose Control
– FBI Warns of Data Security Risks From China-Made Mobile Apps
– Mobile Security: Verizon Says Attacks Soar, AI-Powered Threats Raise Alarm
– Chinese Hackers Turn Smartphones Into a ‘Mobile Security Crisis’
### FAQ
**What is the Mobile Security Exposure Center (MSEC)?**
MSEC is Lookout’s solution for providing full visibility into an organization’s mobile fleet. It scans mobile devices to identify installed applications, generates a Software Bill of Materials (SBOM) for each app, and cross-references component data with known vulnerability databases to help security teams detect and remediate risks.
**Why is app component visibility important?**
Knowing only the app name and version is insufficient to assess risk. Security teams need insight into underlying components and dependencies, as hidden vulnerabilities in third-party libraries—like WolfSSL—can introduce significant security threats.
**How does MSEC help with known vulnerabilities?**
MSEC correlates discovered components with vulnerability databases such as the CISA KEV catalog, enabling organizations to address known security flaws promptly.
**Can MSEC detect unknown vulnerabilities?**
Currently, MSEC focuses on known vulnerabilities. However, Lookout plans to integrate frontier AI models to identify previously unknown vulnerabilities within SBOMs, enhancing proactive risk detection.
**How does MSEC integrate with existing security tools?**
MSEC complements Lookout’s AI Visibility & Governance product by providing detailed software composition analysis. Together, they offer a comprehensive view of application risk, security, and governance.
**What devices does MSEC support?**
MSEC is designed for mobile fleets, scanning devices to assess application compositions and vulnerabilities across the organization’s mobile environment.
### Conclusion
Lookout’s Mobile Security Exposure Center represents a significant advancement in mobile risk management. By moving beyond surface-level app visibility and diving deep into software composition, MSEC empowers security teams to proactively manage vulnerabilities before they can be exploited. As threat landscapes evolve—alongside emerging AI-driven attack techniques—MSEC’s integration of defensive AI models will be crucial in uncovering unknown vulnerabilities. For organizations seeking to secure their mobile fleets effectively, MSEC offers a robust foundation for transforming mobile security from reactive to proactive defense.



