Resources
Blog
Security

September 8, 2026

The Stern Report: The Emperor's New Clothes

Written by:

Matt Stern

Edition: The Fable File

The MDM vendor is the tailor. The MDM is the garment. Your data is the emperor.

MDM doesn't protect your data. It doesn't really protect the device either. It reports on how the device protected itself.

First, the story

Two tailors come to court. They tell the emperor they can weave a fabric so fine it is invisible to anyone unfit for their post. The emperor pays. The tailors mime their work at empty looms.

The ministers are sent to inspect. They see nothing. Each one says the cloth is magnificent, because the alternative is admitting he is unfit for his post. The emperor sees nothing. He says the same thing, for the same reason.

Then he walks the procession in front of everyone. A child says the obvious. The emperor keeps walking, because the procession is already underway and stopping is worse than continuing.

That's the story. Here is the part nobody remembers: the tailors were paid in full, and they left town before the procession.

Now drop the metaphor

Let me be direct about something. Mobile device management is not a security product. It is a legacy management app with a reporting surface, and most of what it gets credit for is work somebody else is doing.

Strip it down to what MDM itself performs. It enrolls a device. It pushes a configuration profile. It asserts a policy. It collects state and renders that state in a console. It sends a wipe request. That is the job.

Now look at where the security in that list actually comes from:

  • Encryption: the operating system. MDM sets a flag. Apple and Google do the cryptography, in hardware, whether your console exists or not.
  • Passcode and biometrics: the operating system. MDM states a minimum. The platform enforces it.
  • App isolation: the operating system sandbox, or the Android work profile. Not the management layer.
  • Identity and access: your identity provider. Conditional access is an IdP decision that consumes a posture signal MDM reported.
  • Malware, phishing, and exploit detection: a separate mobile threat defense product, in the deployments that bought one. MDM does not do this and never did.
  • The wipe: a request the platform honors, if the device is powered on, network-reachable, and still cooperating.

Take away the OS, the IdP, and the threat defense product, and what remains is an inventory database and a dashboard.

MDM doesn't secure the device. It reports on how the device secured itself.

That reporting is the reason it survives. A console that renders a fleet as green is an evidence generator, and evidence closes audit findings. It is a compliance instrument that got shelved in the security budget, and it has stayed there through fifteen years of mobile platform evolution largely on inertia and integration cost.

Some vendors answer this by pointing at MAM instead. Application management is a narrower and more honest claim: it governs the app. It does not govern the data once the app has pulled it down and written it to disk.

So the garment isn't fake, exactly. It's stitched entirely from other people's thread, and the tailor is selling you the seam.

What the seam doesn't cover

None of that would matter much if the data stayed somewhere else. It doesn't. Once a work application syncs sensitive data down to a managed phone, that data is at rest on the endpoint, in application storage, in cached attachments, in message history, in local search indexes. The answer to that exposure is retroactive: the platform encrypts it, and you wipe it later if something goes wrong.

So your data's security is inherited. It belongs to the handset, the OS version, the patch level, and whatever else the user installed alongside your app. Your management console is a spectator to all four. It can tell you the patch level is wrong. It cannot make the patch happen, and it cannot make the data leave.

Retroactive isn't protection. It's cleanup with better branding.

Everyone in the procession has a reason to agree

This is the part of the fable that actually maps to how organizations end up exposed, and it isn't the tailors. It's the court.

  • The vendor sold a device-management platform and answered a data-protection question with it. Nobody in that sales cycle was incentivized to name the gap.
  • The IT lead deployed it, wrote the policy, and marked mobile as handled. Reopening that means reopening the budget.
  • The security lead inherited an architecture diagram with a box labeled MDM sitting where a boundary should be. Nobody has re-drawn it in three years.
  • The executive sponsor sees enrollment numbers going up and reads that as risk going down.

None of these people are lying. Every one of them is making a locally rational decision. That is exactly how the emperor ended up naked.

The garment nobody is wearing

Here's where the analogy stops being funny.

MDM only covers a device your organization actually manages. Personal phones, the ones your employees, your subcontractors, and your reservists already carry, are outside the fabric entirely. In most programs, some portion of the workforce is reading work email, pulling drawings, or answering a Teams message on a device the enterprise has never enrolled. That is not a hypothetical risk. It is the default behavior of adults with jobs.

And the standard remedy makes it worse. When you tell an employee that the price of access is full enterprise control of their personal phone, including a wipe that can take their photos with it, a predictable share of them decline to enroll and route around you instead. The policy that was supposed to close the gap widens it. That's Shadow IT, and it's the same mechanism that put unmanaged mobile into the enterprise in the first place.

So the honest inventory is this: a managed fleet where your data lands on the endpoint and gets encrypted, and an unmanaged fleet where your data lands on the endpoint and doesn't. Neither one is a boundary. One of them just has a dashboard attached.

The child in the crowd doesn't work for you

In the fable, the person who says the obvious is a child, someone with no stake in the procession and no reason to play along. In your organization, that person doesn't exist. Everyone has a stake.

So the obvious gets said by an adversary instead, and it gets said in the form of an event.

  • A phone left in a rideshare, still logged in, holding six months of attachments in local app storage.
  • An employee who resigns on Friday with the whole shared drive cached on a personal handset you were never managing.
  • A malicious app with over-broad permissions, sitting on the same device as your data, doing exactly what the user allowed it to do at install.
  • A handset three OS versions behind, running an exploit chain that was patched last spring.

The wipe command is your last control, and it only works if the device is powered on, reachable, and still under your management. An adversary who has the handset controls all three of those conditions. You don't.

Wiping a phone doesn't protect the data that already left it.

And notice what every one of those scenarios has in common. The failure isn't in your network, your identity provider, or your cloud. It's on a piece of consumer hardware you don't own, sitting in someone's pocket, holding your data because an app put it there.

What actually clothes you

The fable's real lesson isn't "vendors lie." It's that an invisible garment and no garment are operationally identical, and the only fix is to put on something real.

For mobile, something real means changing where the data lives, not adding another layer of management on top of a device that is still holding it. If mission data never lands on the endpoint, the endpoint's posture stops being the thing standing between an adversary and your data. Everyone is selling zero trust. Almost nobody is applying it to the phone.

This is the architecture Hypori is built on. The workspace runs in an accredited cloud environment; the phone receives an encrypted stream of the session. Mission application data, messages, and workflows stay off the device. Nothing syncs down to be wiped later, because nothing synced down.

Let me be precise about the boundary, because a CSO who overclaims deserves the skepticism he gets. This model addresses data at rest on the endpoint and the exposure that follows a lost, stolen, or unmanaged device. It does not make the phone trustworthy, and no mobile architecture does, a compromised platform is a platform-level event. What it does is remove your data from the list of things that platform is holding.

It also removes the reason employees refuse to enroll. There is nothing on their personal phone to manage and nothing of theirs to wipe, which is why the BYOD population stops routing around the policy.

The bottom line

Nobody in your organization set out to buy an invisible garment. They asked a data-protection question, got a device-management answer, wrote it down, and moved on, because everyone else in the procession had already nodded.

The gap isn't awareness. It's action. Say the obvious thing yourselves, while it's still your choice who says it.

If the only thing protecting your data on that phone is a wipe command, you don't have a control. You have a costume.

Matt Stern

Chief Security Officer, Hypori

Subscribe to Substack

Recent articles

Security

September 3, 2026

What Flock Cameras Teach Us About Your Phone Privacy at Work

Flock Safety's license plate cameras reveal how easily surveillance creeps in once tracking is technically possible. See why the same risk exists on your work phone, and how Hypori keeps your employer out of your personal life.

CMMC

September 2, 2026

The Stern Report: The Requirement Never Moved. The Model Should.

‍CMMC Phase 2 is suspended. The CMMC Reform Task Force reports to the DoW CIO this month. This is the argument I would make to it.

Security

September 1, 2026

Zero Day Is the New Every Day

Zero-day exploits used to require a nation-state budget. Now they take a laptop and a grudge. Here's why "patch faster" isn't the fix anymore.