Case Study: Schibsted
Case Study: Schibsted
Case Study: Schibsted
How Schibsted Media expanded mobile EDR coverage from 50 to 500 devices to better protect journalists working in the field and traveling abroad.
How Schibsted Media expanded mobile EDR coverage from 50 to 500 devices to better protect journalists working in the field and traveling abroad.
Industry:
Industry:
Industry:
Media / digital publishing
Media / digital publishing
Headquarters
Headquarters
Headquarters
Oslo, Norway
Oslo, Norway
Every Source a Journalist Protects
starts with the device in their pocket.
starts with the device in their pocket.
500
500
Devices Protected
Devices Protected
2
Week Deployment
Week Deployment
Schibsted Media publishes some of the Nordics’ most influential news brands, including VG, Aftonbladet, Aftenposten, and Svenska Dagbladet. Its journalists rely heavily on mobile devices to communicate, access information, and report from the field, making the security of those devices an important part of protecting both employees and the integrity of their work.
For Bernard Helou, Head of Cyber Security at Schibsted Media, this created a clear security priority: gaining better visibility into mobile endpoints and greater confidence that journalists and their sensitive information remained protected, particularly when traveling outside the Nordics.
Challenge: Protecting Critical Mobile Devices Wherever Journalism Happens
For a media organization, mobile security has implications beyond protecting corporate data. Journalists routinely use their phones for communication, research, authentication, and access to sensitive information. Depending on their work, those devices may also provide access to confidential source information and privileged journalistic material.
Schibsted Media wanted greater assurance that these devices remained secure, particularly when employees were working in the field or traveling outside the Nordics. The organization needed better visibility into the security posture of mobile endpoints and the ability to understand when a device required further investigation.
The challenge was not simply managing mobile devices. Schibsted Media already had mobile device management capabilities in place. The security team wanted to add a deeper layer of security visibility and protection that could help them understand the risks affecting devices that, in many cases, were among the organization’s most important endpoints.
Solution: Mobile EDR Built Around Visibility, Privacy, and Trust
Schibsted Media evaluated several solutions as part of its search for a mobile security platform. iVerify Enterprise stood out because of its focus on privacy and the transparency of the technical evaluation process.
From the beginning, Schibsted Media was able to have detailed technical conversations with the iVerify team about the platform’s capabilities and limitations. Questions were answered directly, and the communication remained transparent throughout the evaluation.
That approach was particularly important for a media organization handling sensitive journalistic information. The combination of privacy-conscious mobile security, technical transparency, and collaborative support helped establish confidence in iVerify as a long-term security partner.
With iVerify Enterprise, Schibsted Media gained visibility into the security of mobile devices used by journalists and other employees. Its security and SOC teams can better understand risks affecting those endpoints, investigate issues that require additional attention, and access iVerify’s incident response expertise when deeper investigation or response support is needed.
Implementation: From 50 Devices to 500 Ahead of the World Cup
iVerify was Schibsted Media’s first mobile EDR deployment, so the organization was building its mobile endpoint security program without the complexity of migrating from a previous solution.
The initial implementation through Schibsted Media’s MDM was straightforward, despite zero-touch enrollment not being available at the time. The initial deployment was completed in approximately two weeks and covered a small group of 50 devices.
As the platform evolved, Schibsted Media remained informed about new capabilities and product developments. This allowed the security team to adapt its internal processes and create a smoother enrollment experience for new users over time.
The deployment expanded significantly ahead of the 2026 FIFA World Cup. With journalists preparing to travel to North America to cover the event, Schibsted Media wanted greater confidence that their mobile devices would remain protected while working abroad. The organization expanded its iVerify Enterprise deployment from 50 devices to approximately 500, increasing coverage tenfold.
Results: Greater Visibility Into the Endpoints That Matter Most
Since deploying iVerify Enterprise, Schibsted Media’s security and SOC teams have gained greater visibility into mobile devices that play a critical role in journalists’ daily work.
Because journalists frequently work in the field, mobile devices are central to how they communicate and access information. iVerify gives the security team better insight into the risks affecting those devices and helps them identify when an issue requires further investigation. If a security incident does occur, Schibsted Media can also draw on iVerify’s incident response team for additional investigative and response support.
The deployment has also had a broader impact on security awareness. Mobile security has become a more visible part of the organization’s overall security conversation, while end users have become more conscious of keeping devices updated and considering the sensitivity of the information they store and access on them.
For journalists, that awareness is particularly important. Mobile devices can contain or provide access to information about confidential sources and privileged journalistic material. Strengthening awareness of mobile risk alongside technical visibility has therefore been an important outcome of the deployment.
The experience has also helped Schibsted Media identify a security gap it had not previously fully recognized: the need to go beyond mobile device management and gain deeper visibility into and protection of mobile endpoints.
Looking ahead, Schibsted Media’s goal is to continue expanding iVerify across its device fleet. As the organization sees increasing value in mobile security that extends beyond device management alone, broader deployment would provide another layer of protection across the devices employees rely on every day.
Figma's commitment to being people-first extends beyond its collaborative design tools and into the heart of its company culture. At the center of this culture are "Figmates" – Figma's term for its employees. This people-centric approach shapes every technology decision, especially when it comes to security.
Dave Vega, Figma's Director of IT, brings 25 years of experience and a unique philosophy to his role. "What I love about Figma is that we are a people-centric company with a people-centric culture," says Vega. "This allows me to work on finding innovative tools that help people do their jobs in a way that isn't 'big brother,' but something our employees will truly enjoy."
Leading the Platform Security team, Brad Girardeau shares this vision. His team oversees corporate and infrastructure security with a deep commitment to protecting sensitive data while respecting individual privacy.
"Technology is such a big part of our lives. I enjoy creating a world where people can do things with technology and be safe."
— Brad Girardeau, Security Manager, Platform Security
Challenge
As Figma grew, its traditional approach to mobile security needed evolution. While the company had robust security for corporate laptops, mobile devices presented a unique challenge. Figmates aren't required to use phones for work full stop, but for those that choose to work using a mobile phone, they have the option to use a corporate device or use a stipend for a personal device for work. Initially, the built-in isolation features of mobile operating systems seemed sufficient, but as the company expanded, particularly into the EU automotive industry, new requirements emerged.
The security team faced a complex balancing act: they needed better visibility and control over their BYOD environment while maintaining their commitment to employee privacy and choice. Adding to this challenge was a requirement for TISAX certification, which mandated MDM implementation.
"We hear stories about adversaries using zero days to compromise mobile phones or someone's phone gets lost or stolen with access to corporate data," Girardeau explains. "So, a lot of CISOs are asking, 'How do we remove sensitive data from those devices?'"
"We wanted a privacy-protective mode different from traditional, full-control modes of MDM. That distinction is meaningful and important to our employees."
— Brad Girardeau, Security Manager, Platform Security
Solution
The answer came in combining MDM deployment with iVerify's unique security capabilities. For Girardeau, the ability to scan for indicators of compromise, not just known threats, was crucial. iVerify's expertise in uncovering spyware and zero-day attacks made it stand out from traditional solutions.
"iVerify Mobile EDR offers MDM capabilities, but it's not just managing the device by locking and unlocking the phone. It also detects and remediates malware, spyware, and smishing."
— Dave Vega, Director of IT
The solution gave Figma's security team precise control over access management. They could now trace every device connecting to Figma's systems and reliably cut off access if a phone was lost, stolen, or compromised – all without touching personal data.
Implementation
Knowing that asking employees to install security software on personal phones could be sensitive, Figma took a thoughtful approach to implementation. A cross-functional team including legal, security, compliance, IT, communications, and people teams carefully planned the rollout.
They created a comprehensive internal mobile security hub with detailed resources explaining the why and how of the new system. Importantly, they made it clear that employees could opt out and use only company-managed laptops for accessing Figma data.
"iVerify is different from the MDM and security tools of the past... There's a very clean delineation that we could communicate to all Figmates. You can keep your photos and your home videos. We don't see it, and we don't have access."
— Dave Vega, Director of IT
The careful planning paid off. The implementation was completed in less than two weeks, with fewer than a dozen support messages for over 1,300 devices. Vega attributes this success to both the cross-functional collaboration and iVerify's clean, user-friendly design.
Results
The smooth deployment demonstrated that security and privacy aren't mutually exclusive. For IT, the detailed investigation capabilities transformed their ability to handle unusual activity. The security team gained the ability to effectively manage unmanaged devices' access to SaaS applications, while maintaining employee trust.
iVerify remains engaged with Figma’s security team to develop new capabilities, including enhanced enforcement in Okta which is now available.
"As a result of how we rolled this out, we now have huge credibility with the company."
— Dave Vega, Director of IT
Girardeau's final thought captures the essence of the project's success: "I'm proud that we now have a solution that protects privacy and that even I feel comfortable running on my phone."
Schibsted Media publishes some of the Nordics’ most influential news brands, including VG, Aftonbladet, Aftenposten, and Svenska Dagbladet. Its journalists rely heavily on mobile devices to communicate, access information, and report from the field, making the security of those devices an important part of protecting both employees and the integrity of their work.
For Bernard Helou, Head of Cyber Security at Schibsted Media, this created a clear security priority: gaining better visibility into mobile endpoints and greater confidence that journalists and their sensitive information remained protected, particularly when traveling outside the Nordics.
Challenge: Protecting Critical Mobile Devices Wherever Journalism Happens
For a media organization, mobile security has implications beyond protecting corporate data. Journalists routinely use their phones for communication, research, authentication, and access to sensitive information. Depending on their work, those devices may also provide access to confidential source information and privileged journalistic material.
Schibsted Media wanted greater assurance that these devices remained secure, particularly when employees were working in the field or traveling outside the Nordics. The organization needed better visibility into the security posture of mobile endpoints and the ability to understand when a device required further investigation.
The challenge was not simply managing mobile devices. Schibsted Media already had mobile device management capabilities in place. The security team wanted to add a deeper layer of security visibility and protection that could help them understand the risks affecting devices that, in many cases, were among the organization’s most important endpoints.
Solution: Mobile EDR Built Around Visibility, Privacy, and Trust
Schibsted Media evaluated several solutions as part of its search for a mobile security platform. iVerify Enterprise stood out because of its focus on privacy and the transparency of the technical evaluation process.
From the beginning, Schibsted Media was able to have detailed technical conversations with the iVerify team about the platform’s capabilities and limitations. Questions were answered directly, and the communication remained transparent throughout the evaluation.
That approach was particularly important for a media organization handling sensitive journalistic information. The combination of privacy-conscious mobile security, technical transparency, and collaborative support helped establish confidence in iVerify as a long-term security partner.
With iVerify Enterprise, Schibsted Media gained visibility into the security of mobile devices used by journalists and other employees. Its security and SOC teams can better understand risks affecting those endpoints, investigate issues that require additional attention, and access iVerify’s incident response expertise when deeper investigation or response support is needed.
Implementation: From 50 Devices to 500 Ahead of the World Cup
iVerify was Schibsted Media’s first mobile EDR deployment, so the organization was building its mobile endpoint security program without the complexity of migrating from a previous solution.
The initial implementation through Schibsted Media’s MDM was straightforward, despite zero-touch enrollment not being available at the time. The initial deployment was completed in approximately two weeks and covered a small group of 50 devices.
As the platform evolved, Schibsted Media remained informed about new capabilities and product developments. This allowed the security team to adapt its internal processes and create a smoother enrollment experience for new users over time.
The deployment expanded significantly ahead of the 2026 FIFA World Cup. With journalists preparing to travel to North America to cover the event, Schibsted Media wanted greater confidence that their mobile devices would remain protected while working abroad. The organization expanded its iVerify Enterprise deployment from 50 devices to approximately 500, increasing coverage tenfold.
Results: Greater Visibility Into the Endpoints That Matter Most
Since deploying iVerify Enterprise, Schibsted Media’s security and SOC teams have gained greater visibility into mobile devices that play a critical role in journalists’ daily work.
Because journalists frequently work in the field, mobile devices are central to how they communicate and access information. iVerify gives the security team better insight into the risks affecting those devices and helps them identify when an issue requires further investigation. If a security incident does occur, Schibsted Media can also draw on iVerify’s incident response team for additional investigative and response support.
The deployment has also had a broader impact on security awareness. Mobile security has become a more visible part of the organization’s overall security conversation, while end users have become more conscious of keeping devices updated and considering the sensitivity of the information they store and access on them.
For journalists, that awareness is particularly important. Mobile devices can contain or provide access to information about confidential sources and privileged journalistic material. Strengthening awareness of mobile risk alongside technical visibility has therefore been an important outcome of the deployment.
The experience has also helped Schibsted Media identify a security gap it had not previously fully recognized: the need to go beyond mobile device management and gain deeper visibility into and protection of mobile endpoints.
Looking ahead, Schibsted Media’s goal is to continue expanding iVerify across its device fleet. As the organization sees increasing value in mobile security that extends beyond device management alone, broader deployment would provide another layer of protection across the devices employees rely on every day.
ABOUT
Schibsted is at the forefront of technological development to deliver even better journalism and user experiences.
Schibsted Media is one of the Nordics’ leading media companies, with a history dating back to 1839. Following a strategic split in 2024, its news media operations became a standalone company under the ownership of the Tinius Trust, allowing Schibsted Media to focus exclusively on independent journalism across the region.
PRODUCT
CASE STUDY