Mobile SOC: experts watching over the security of your smartphones and computers
A protection agent on every device, alerts reviewed by a Cyber Praxis analyst, a spyware check at regular intervals and a monthly report. If an alert is confirmed, we step in using the method of our expert examinations.
In short. A SOC — Security Operations Centre — receives the security alerts of an IT environment and decides what to do about them. The Mobile SOC of Cyber Praxis SRL applies that principle to the devices you carry everywhere: smartphones, tablets and laptops. An agent on each device reports anything abnormal, an analyst reviews the alerts, a periodic forensic check looks for spyware, and a monthly report takes stock. The service is run from Lasne, in Walloon Brabant, for clients in Belgium and France.
Why a SOC for smartphones?
Because that is where your messages, your accounts, your banking codes and access to your work email now live — and so that is where attacks concentrate: phishing links sent by text message or messaging apps, malicious apps, monitoring software installed without the user's knowledge, account takeovers. Many organisations monitor their servers and workstations, but not their staff's phones. And an individual usually has no way of knowing whether their device has been compromised.
The Mobile SOC closes that gap: protection installed on the device, and people who look at what it reports. An alert nobody reads protects against nothing.
Who it is for
For individuals, especially after a hack or covert monitoring: once the device has been examined and cleaned, the Mobile SOC helps check that the problem does not come back. For companies and organisations, on their staff's smartphones, tablets and computers — devices provided by the employer, or personal devices used for work, within a framework agreed in advance. For executives and high-risk profiles — lawyers, elected officials, journalists, people involved in a dispute —, who may be targeted by more discreet spyware than most, and for whom a regular forensic check makes the most sense.
What the service includes
A protection agent on every device
A security app is installed on each covered smartphone, tablet or computer. It reports malicious or risky apps, phishing links, suspicious Wi-Fi networks, an operating system that is out of date, a jailbroken or rooted device, or security features switched off. Alerts go to Cyber Praxis: an analyst reviews them during the hours set by the agreed level of service, rules out false alarms and tells you, in plain words, what to do. Before any deployment, we tell you in writing which tool is used, what data it collects, where that data is hosted and how long it is kept.
A regular spyware check
At an interval agreed with you — every quarter, for example — the device undergoes a forensic check: a search for known indicators of compromise, monitoring software, unexpected configuration profiles or remote access, and unexplained changes. It is the necessary complement to the agent, because some spyware is designed to evade the protection installed on the device. Each check produces a dated account of what was examined and what was found.
Monitoring and a monthly report
Every month, a report takes stock of your devices: alerts received and how they were handled, devices whose system or apps are out of date, newly published vulnerabilities affecting your models and versions, settings to correct, email addresses appearing in documented data breaches. It is a filter: you receive what concerns your devices, not a news feed. The report is written to be read by a management team, a DPO or an individual, with no technical background needed.
Stepping in when an alert is confirmed
If an alert reveals a real compromise, we guide you through containing it — isolating the device, securing accounts, changing what needs to be changed — without destroying anything that could serve as evidence. Where useful, material is preserved using the method of our expert examinations: copy, cryptographic hash, documented chain of custody. The material then remains usable if you file a complaint or assert your rights; its evidential weight is for the court to assess. An in-depth examination of a device then falls under smartphone forensics or cyber investigation.
What we do not do
The Mobile SOC protects a device for the person who uses it. It is never a tool for monitoring a person. We do not look at the content of messages, photos or emails, unless a suspicious trace found during a check requires it. We do not track anyone's location. And we never install anything on someone's device without their knowledge — partner, child, employee or third party: that is exactly what the spyware we look for does.
In a company, deployment is prepared with the DPO: informing staff beforehand, a purpose limited to security, proportionality and, for a personal device, the employee's agreement and a written description of what the agent sees on it. In Belgium, the GDPR applies and, for private-sector employers, so does Collective Labour Agreement No. 81 on the monitoring of electronic online communications data, which requires prior information in particular. In France, the rules are comparable: staff must be informed beforehand and, from 50 employees, the CSE (works council) consulted. No tool detects everything: the Mobile SOC reduces the risk but does not remove it, and the report states clearly what was checked and what was not.
Getting started
Four stages, from the first conversation to monthly follow-up
-
1
Scoping
We go through it with you: how many devices, which ones, who uses them, and what worries you. For a company, the framework is prepared with your DPO.
-
2
Initial baseline
A forensic check at the outset records the state of each device before monitoring begins. Anything found at this stage is dealt with first.
-
3
Deployment and monitoring
The agent is installed, then alerts are reviewed by an analyst at the agreed level of service. You know whom to contact, and how.
-
4
Reports and reviews
A report every month, a spyware check at the agreed interval, and a review of the set-up whenever your devices or your use change.
Frequently asked questions
Can the Mobile SOC read my messages or photos?
No. The agent handles security information: installed apps, operating system version, protection settings, flagged networks and links, detected threats. The periodic forensic check may require a copy of the device: it is searched for traces of compromise, its content is only looked at if a suspicious trace requires it, and the copy is deleted under terms agreed in writing. Before deployment, we give you in writing the list of data collected, where it is hosted and how long it is kept.
Can an employer install the Mobile SOC agent on staff phones?
Yes, on work devices, provided staff are informed beforehand and the purpose remains security. On a personal device, installation requires the employee's agreement, and what the agent sees of the private side is set out in writing. In Belgium, the framework includes the GDPR and, for private-sector employers, Collective Labour Agreement No. 81; in France, the GDPR and employment law. We prepare it with your DPO. The Mobile SOC is never installed without the user's knowledge.
Does the Mobile SOC detect all spyware?
No tool can promise that. Some spyware is designed to evade the protection installed on the device. That is why the service combines an agent, which reports what it detects, with a periodic forensic check, which looks for traces the agent cannot see. If there is serious doubt between two checks, a full examination of the device can be carried out.
What happens when an alert is triggered?
A Cyber Praxis analyst reviews it, during the hours set by the agreed level of service. If it is a false alarm, it is closed and listed in the monthly report. If it is confirmed, we contact you, guide you through containing the incident and, where useful, preserve the material using a documented method so that it remains usable; its evidential weight is for the court to assess.
How much does the Mobile SOC cost?
The fee depends on the number of devices, their operating systems, how often the forensic checks take place and the level of service. It is set out in a quote, after a free and confidential first conversation. No fees are charged before you accept the quote.
Tell us about your devices and what worries you
The first conversation is free and confidential. Tell us how many devices are involved, of which types, and why you are considering monitoring: we will propose a level of service and a quote.