Available on Demand | June 27, July 10, July 29, 2025 | 3 Hours | 3 CPE

Today’s phishing attacks target much more than email; they exploit every mobile channel — SMS, Signal, social platforms and QR codes to reach your users. Mobile phishing (“smishing”) and QR based attacks (“quishing”) are engineered to bypass traditional endpoint defenses to exploit human behavior.

As mobile becomes mission-critical in federal agencies — replacing laptops and extending the workspace far beyond office boundaries — cybersecurity has failed to keep pace. Many of these mobile endpoints are employee-owned devices (BYOD), further complicating visibility, control, and enforcement.

Recent attacks underscore the growing risk. For instance, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) released a joint statement in November 2024 that their ongoing investigation into the People’s Republic of China (PRC) targeting of commercial telecommunications infrastructure revealed a broad and significant cyber espionage campaign.

Hosted & Moderated By:

Jane Norris, Moderator & Contributing Editor, FedInsider

Jane Norris
Contributing Editor,
FedInsider

June 27: Mobile Security: The Human Layer is the New Attack Surface

Phishing today isn’t just email. Adversaries are now exploiting SMS, Signal, LinkedIn, QR codes, and more to directly target your people—on the devices they rely on most. These mobile-specific tactics—like smishing and quishing—are designed to exploit human trust, not technical flaws. And they’re working.

Protecting users from falling for such schemes is difficult. Threat researchers have seen malicious smishing campaigns deploy zero-click malware that can hijack verification codes and one time passwords (OTPs), replicating screen interfaces, and stealing application credentials. One report identified why mobile users are more at risk, including:

  • Reduced screen size makes suspicious URLs harder to identify;

  • Touch screens make it harder for a user to inspect URLs;

  • Mobile channels like SMS and QR codes are commonly used as thus often trusted

Join us as thought leaders from government and industry discuss the ways that security professionals can empower users to recognize and protect themselves from social engineering tactics on mobile, and how agencies can close the visibility and control gaps left open by traditional EDR tools.

Learning Objectives:

  • Spot mobile-first phishing techniques: Learn how attackers adapt social engineering for mobile channels like SMS and QR codes

  • Deploy human-centric defenses: Understand how phishing-resistant MFA, clear BYOD policies, and mobile-aware password strategies reduce risk

  • Improve user awareness at the edge: Explore training approaches designed to help mobile users detect and respond to smishing threats in real time

Tim LeMaster, Vice President, Federal Systems Engineering, Lookout

Tim LeMaster
Vice President, Federal Systems
Engineering,
Lookout

July 10: The Modern Endpoint – It’s Personal

Today’s workforce isn’t tethered to laptops – it’s powered by mobile. It’s often a primary way many employees connect to email and other mission-critical resources but not treated that way from a security standpoint.

Traditional Mobile Device Management (MDM) solutions weren’t built to detect advanced threats or align with Zero Trust principles. They offer basic control, but not the telemetry, risk context, or threat detection required by today’s federal cybersecurity standards. Meanwhile, the modern kill chain pathway begins with reconnaissance – attackers learn all they can about the target agency and its employees, primarily via social media, including whether they use a single sign-on page. These malicious actors capitalize on the commoditization of advanced malware and ready availability of Malware-as-a-Service kits that make creating these codes an easy task for attackers. One company reported that 60% of mobile devices run on vulnerable operating systems.

In this session, government and industry leaders will explore why legacy mobile management tools are no longer enough – and how agencies can meet federal requirements by extending modern security to the mobile endpoint.

Learning Objectives:

  • Map your mobile risk surface: Build a methodology to identify all mobile endpoints accessing your network—including unmanaged personal devices

  • Go beyond MDM: Understand where MDMs fall short and how modern mobile threat defense aligns with Zero Trust and federal security baselines

  • Modernize device policy enforcement: Review and revise policies to improve visibility, compliance, and protection across the full mobile fleet

Jonathan Feibus, Acting Director of the IT Services Development &Operations Division, Office of the CIO, Nuclear Regulatory Commission

Jonathan Feibus
Acting Director for the SDOD, OCIO,
Nuclear Regulatory Commission
Dr. Michael Henson, Group Leader, Cyber Resilience Foundations Group & Senior Cyber Security Engineer & Researcher, Pacific Northwest National Laboratory

Dr. Michael Henson
Group Leader, Cyber Resilience Foundations Group, Senior Cyber Security Engineer & Researcher, Pacific Northwest National Laboratory
James Coyle, Chief Technology Officer, U.S. Public Sector, Lookout

James Coyle
Chief Technology Officer,
U.S. Public Sector, Lookout

July 29: Mobile Threat Intelligence: Rethinking What Your Traditional EDR is Missing

There have been several cyber attacks recently that were launched through users’ mobile devices, often targeting high-profile government officials. For instance, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) released a joint statement in November 2024 that their ongoing investigation into the People’s Republic of China (PRC) targeting of commercial telecommunications infrastructure revealed a broad and significant cyber espionage campaign.

These kinds of incursions by bad actors on the part of hostile nation-states led to CISA’s release of a Mobile Communications Best Practices Guide. But the attacks also highlight the need for agencies to treat mobile as a frontline asset in their threat intelligence operations.

Join us as thought leaders from government and industry discuss the current state of the mobile threat horizon, emerging threats and how modern threat intelligence practices can adapt to defend against adversaries who increasingly exploit mobile to bypass traditional controls.

Learning Objectives:

  • Recognize mobile-specific threat signals: Understand the telemetry and behavioral indicators that distinguish mobile threats from traditional endpoints

  • Analyze real-world adversary campaigns: Review documented attacks by nation-state actors leveraging mobile exploits to infiltrate sensitive environments

  • Evolve your threat intelligence program: Explore strategies to continuously gather, enrich, and apply mobile threat intelligence in a Zero Trust world

Faniko Brown, Chief Information Security Officer, TRANSCOM

Faniko Brown
Chief Information Security Officer,
TRANSCOM
James Coyle, Chief Technology Officer, U.S. Public Sector, Lookout

James Coyle
Chief Technology Officer,
U.S. Public Sector, Lookout