Identity and access management vendor RSA partnered with mobile security provider Zimperium to roll out a feature for its Authenticator mobile application, which adds extra layers of mobile security into its multi-factor authentication (MFA) and zero-trust security processes.

RSA claims this Mobile Lock feature targets one of the weakest points in every organization’s security stance: their users, especially as users rely heavily on mobile devices with the continued prevalence of hybrid and remote work models.

Recent reports also showed the increasing number of mobile device security issues that pose a threat to enterprise security. Nearly half of the surveyed security professionals noted their enterprises suffered a mobile-related compromise, double from last year, according to Verizon’s recent Mobile Security Index.

Zimperium’s own Global Mobile Threat Report showed zero-day attacks targeting mobile devices increased by 4.66 times in 2021, accounting for one-in-three endpoint attacks.

The Mobile Lock feature embeds the Zimperium z9 mobile threat defense engine into the RSA Authenticator mobile application, which is already deployed on millions of devices, the two companies claim. This additional layer of security helps address those issues by detecting critical threats, preventing users from authenticating into secured corporate environments when found threats, and alerting IT administrators about the threats.

That capability takes another step forward for organizations’ overall zero-trust strategies. “Ensuring that a user’s mobile device is secure before granting access to a secure environment should be a core component of any zero-trust architecture,” Zimperium Chief Strategy Officer Nitin Bhatia wrote in a blog post.

“Given the heightened sensitivity of information on or accessible via remote devices – including critical data, enterprise systems, and customer records – our customers asked us for enhanced mobile protection that wouldn’t burden users,” RSA CEO Rohit Ghai said in a statement. “Mobile Lock addresses that urgent need, moving users’ personal devices and their organization’s overall security postures closer to zero trust.”