Managed Mobility Services
What ISEC7 Managed Mobility Services cover
We take over the complete lifecycle of mobile devices and security components, from commissioning to 24×7 operations. That takes the load off your IT so you can concentrate on your core tasks.
24×7 monitoring
Continuous monitoring of all mobile devices, MDM/UEM platforms and security-relevant services around the clock.
Operations
Operation of ISEC7 SPHERE, UEM, secure voice communication and email security, including patch, update and configuration management. The SOC is operated by our partner Arctic Wolf.
Onboarding
Structured transition of your existing mobility landscape into the managed service, including discovery, migration and cutover plan.
Support
Multi-level user and administrator support in German and English.
Compliance reporting
Regular reports on security posture, patch status, incidents and compliance requirements (NIS2, KRITIS, GDPR, ISO 27001).
The six building blocks of ISEC7 Managed Mobility Services
Each building block can be obtained individually or in combination. ISEC7 integrates the selected building blocks into your existing environment.
ISEC7 SPHERE
Unified endpoint monitoring: real-time visibility and compliance reporting for UEM/MDM platforms (BlackBerry UEM, Microsoft Intune, Ivanti, Omnissa Workspace ONE).
Arctic Wolf Managed SOC by ISEC7
ISEC7 delivers managed detection and response with a 24/7/365 SOC through its partner Arctic Wolf. Arctic Wolf operates the SOC in Frankfurt, and ISEC7 remediates the vulnerabilities found in your system.
ISEC7 MANAGED SECURE VOICE
Tap-proof voice communication for iOS and Samsung Knox. The SecuVOICE app from Secusmart used for the service holds a BSI deployment authorization up to VS-NfD, BSI-VSA-11057, valid until August 31, 2027. ISEC7 operates the service.
ISEC7 MAIL
Secure mobile email with S/MIME encryption and signing, for Exchange and Microsoft 365, including hybrid environments.
ISEC7 CLASSIFY
Data classification for Outlook, Office apps and ISEC7 MAIL: labeling is enforced, and several schemes run in parallel, for example corporate, German federal government and NATO.
Sovereign Cloud for BlackBerry UEM
BlackBerry UEM from a cloud that ISEC7 hosts and operates in Germany, in the Enterprise and Regulated packages.
What ISEC7 contributes to NIS2 and KRITIS evidence
The obligations under NIS2 and for KRITIS operators apply to your organization, not to the service provider. ISEC7 documents operations, patch status and incidents so that you can use the reports in your own compliance evidence.
NIS2
The German NIS2 Implementation Act entered into force on December 6, 2025. The Managed Mobility Services reports show you the status of devices, patches and incidents that you need for your risk management measures and reports.
KRITIS
Operations and reporting are designed for the evidence requirements of KRITIS operators and NIS2-regulated companies.
Certification and operations
ISEC7 Group AG, ISEC7 GmbH, ISEC7 Software GmbH and ISEC7 Inc. are certified to DIN EN ISO 27001:2022, ISO 9001:2015 and ISO 14001:2015, valid until September 2, 2027. The Sovereign Cloud for BlackBerry UEM and hosted instances of ISEC7 SPHERE run in German data centers. In the market since 2003.
Who are ISEC7 Managed Mobility Services for?
Public authorities & public administration
Federal, state and municipal administrations with requirements for VS-NfD-compliant communication and sovereign IT structures.
KRITIS operators
Energy, water, health, transport, finance: sectors with KRITIS obligations and around-the-clock availability requirements.
Regulated companies
Industry, pharma, mid-sized companies and corporations with NIS2, DORA or industry-specific security requirements.
Frequently asked questions about Managed Mobility Services
What is the difference between Managed Mobility Services and traditional MDM?
Traditional mobile device management is a software platform that you operate yourself. With Managed Mobility Services, a service provider operates this platform for you and also takes on adjacent building blocks, such as SOC, secure voice communication, email, classification and cloud operations. At ISEC7, this includes monitoring, operations, onboarding, support and compliance reporting around the clock.
What does around-the-clock operation of mobile devices involve?
Around the clock means that monitoring, incident response and support continue at night and on weekends, not just during business hours. With ISEC7 Managed Mobility Services, this covers monitoring, incident response, patch and update management, and user and administrator support. Security events are detected by the SOC of our partner Arctic Wolf; ISEC7 remediates the vulnerabilities found in your system. ISEC7 reports regularly on security posture, patch status and incidents.
Can I outsource NIS2 obligations to a managed service provider?
No, the obligations under NIS2 and for KRITIS operators apply to your organization and remain there; a service provider can, however, deliver the operations and reports that your compliance evidence draws on. The German NIS2 Implementation Act entered into force on December 6, 2025. Operations and reporting of ISEC7 Managed Mobility Services are designed for the evidence requirements of KRITIS operators and NIS2-regulated companies. ISEC7 Group AG, ISEC7 GmbH, ISEC7 Software GmbH and ISEC7 Inc. are certified to DIN EN ISO 27001:2022, valid until September 2, 2027.
How do I prove the patch status of my mobile devices?
You need regular reports from the UEM, or from a monitoring layer on top of it, that show the device inventory, operating system versions and patch status. Within ISEC7 Managed Mobility Services, ISEC7 SPHERE monitors the connected UEM and MDM platforms from a single console, and ISEC7 reports regularly on security posture, patch status and incidents. The reports are structured so that you can use them in your compliance evidence.
How does the switch to a managed service for mobile devices work, and how long does it take?
It starts with an inventory of devices, platforms and requirements; how long the switch takes depends on the size of the fleet and the number of source systems. At ISEC7, onboarding runs in four steps: inventory, connection of the UEM and mail systems, parallel operation, handover. In the first step, a discovery workshop captures your mobility landscape, your compliance requirements and the target architecture; this produces the migration and cutover plan.
How do I make tap-proof calls on a smartphone up to VS-NfD?
The products that the BSI has approved, or granted a deployment authorization, for classified information up to VS-NfD are listed with number and validity in BSI publication 7164. The SecuVOICE app from Secusmart holds a BSI deployment authorization up to VS-NfD, BSI-VSA-11057, valid until August 31, 2027. On this basis, ISEC7 operates the ISEC7 MANAGED SECURE VOICE service, as a subscription from 25 users; because German federal government key material is used, the service is available exclusively to German public authorities and companies. Details on the Secure Voice page.
Who operates the SOC for ISEC7 Managed Mobility Services?
The security operations center is operated by our partner Arctic Wolf in Frankfurt. According to Arctic Wolf, more than 150 German-speaking employees work there, the data is stored in Germany, and Arctic Wolf holds SOC 2 Type 2 (webinar by ISEC7 and Arctic Wolf, July 10, 2025). ISEC7 connects your mobility landscape, supports the service and remediates the vulnerabilities found in your system. You can also obtain the managed SOC service alongside existing security software.
Do all building blocks of ISEC7 Managed Mobility Services run in Germany?
Not every building block in the same way. ISEC7 hosts and operates the Sovereign Cloud for BlackBerry UEM in Germany; ISEC7 SPHERE runs in your data center or in German data centers. Arctic Wolf operates the SOC in Frankfurt with data storage in Germany; ISEC7 MAIL connects directly to your Exchange or Microsoft 365, with no ISEC7 servers in between. For ISEC7 MANAGED SECURE VOICE, part of the infrastructure is located in the German federal government networks, according to the manufacturer Secusmart.
Which UEM platforms does ISEC7 support?
ISEC7 SPHERE monitors BlackBerry UEM, Microsoft Intune, Ivanti and Omnissa Workspace ONE from a single console. ISEC7 offers consulting, integration and managed services for UEM solutions from BlackBerry, Ivanti, Microsoft, Samsung, Omnissa, Jamf and Google. More on the Endpoint Management page.
As of: September 28, 2026 · Approval details according to BSI publication 7164 · SOC details according to Arctic Wolf
Request Managed Mobility Services now
Would you like to hand over the operation of your mobile infrastructure? We will discuss your starting point individually and without obligation.