We Built Symmetrium Go for the Deployment That Never Has to Wait

Now Live!

Secure Mobile Communication for Government Field Operations: Insights from a Pilot Evaluation

Government field teams depend on fast, discreet mobile communication. Yet the tools they rely on—personal messaging apps, unmanaged devices, and ad-hoc workphones—create unavoidable risk.

To explore a new operational model, a confidential government intelligence agency conducted a controlled pilot with Symmetrium. Their goal: evaluate whether a virtual mobile workspace—fully isolated, zero data at rest, and streamed to any personal phone—could support the realities of high-sensitivity field communication.

What follows is a summary of what was tested and what was learned.

The Operational Challenge: Secure Comms Without Compromising the Operator

For field personnel, mobile communication must feel natural, immediate, and trustworthy. But the operational environment introduces constraints:

  • Personal phones are often the only practical device in field or off-site scenarios.
  • MDM and surveillance agents are unacceptable—both operationally and from a privacy standpoint.
  • Apps like WhatsApp are indispensable, yet ungoverned messaging creates compliance, exposure, and data-leak risks.
  • A clean, separate work identity is needed—without touching or monitoring the personal environment.

The agency sought a model where operatives could use secure, policy-controlled communication without giving up their privacy or compromising their operational safety.

Why Symmetrium: A Separate, Secure Identity for Field Operations

Symmetrium provides a fully isolated work environment streamed from the organization’s infrastructure, with zero data ever stored on the physical device. For high-sensitivity field use, this architecture aligns naturally with operational constraints:

  • No enrollment, no agents, no access to personal data
  • A separate operational identity with full policy enforcement
  • Ability to run apps like WhatsApp, Telegram, Facebook and Instagram inside the workspace with compliance logging
  • Native performance that matches how operatives already communicate

This combination—security, compliance, and natural UX—made it a strong candidate for evaluation.

Inside the Pilot: Testing a Controlled Intelligence Workspace

During the pilot, the agency deployed 10 virtual mobile devices, each providing a secure workspace accessible from a personal phone. The environment included:

  • A dedicated operational WhatsApp number for each workspace
  • Secure messaging with organization-level visibility
  • An isolated workspace streamed from the agency’s server
  • Policy-controlled usage, including DLP features and access enforcement

All configurations aligned with the agency’s internal communication requirements.

How Operatives Used the System: Real-World Behavior at Real Volume

Over the course of the two-month pilot, operatives used the workspace heavily and consistently:

  • 4,435 messages exchanged
  • 986 chat sessions
  • 2,086 system connections
  • 210 average daily usage
  • 68 distinct conversation threads

Usage patterns mirrored everyday mobile behavior—fast exchanges, frequent reconnections, and natural communication flow. According to the pilot’s UX observations, participants reported a familiar, frictionless experience, similar to using their regular device. Support needs were minimal, and all issues were resolved quickly.

Validated Operational Capabilities: Privacy, Control, and Operator Effectiveness

Based on the pilot results, the agency validated several key operational advantages:

  • Sensitive data never touches the physical device—reducing risk during stops, searches, and inspections.
  • The operational identity remains fully separate and centrally controlled.
  • Messaging can be audited and governed without monitoring the personal phone.
  • Policy controls (screenshot, screen recording, copying, exporting) function reliably.
  • Operators retain full, native control over their day-to-day communication—adding contacts naturally and requesting new apps as operational needs evolve.
  • Approved tools and updates can be deployed across all workspaces within seconds, eliminating the back-office delays that typically slow down secure communication changes.
  • Teams can communicate and adapt quickly, without training or workflow disruption.

The pilot demonstrated that government field teams can operate securely on personal devices while maintaining both centralized governance and real-time operational flexibility.

Strategic Impact: A New Model for Government Field Mobility

The successful test of a single operational identity lays the foundation for broader applications across government field operations:

• Single-Identity Workflows: Secure Communications for Field Personnel

Validated during the pilot—ideal for teams operating across locations and departments.

• High-Sensitivity Operations: Separation That Protects the Operator

A secure work identity with zero data at rest and fully revocable access.

• Multi-Identity Operations: The Next Step Forward

While not part of the pilot, Symmetrium’s architecture supports evolving toward multiple isolated profiles and policy sets—important for agencies with complex operational roles.

What’s Next: Scaling Secure Mobility for Government Field Agencies

The agency is now analyzing expansion paths for additional field-focused operational groups. The pilot confirmed that a virtual mobile workspace can offer operations-grade security without compromising how personnel communicate or how field work is carried out.

Symmetrium continues to work with government field agencies to refine this model and support the next generation of secure mobile communication for high-sensitivity operational environments.
Symmetrium gives sensitive teams a secure mobile identity they can trust.
If you’re building capabilities for field, operational, or high-sensitivity teams, we’re here to help you evaluate whether this model is the right fit for your environment.
Reach out >>

How a Defence Agency Deployed Symmetrium to Secure its Reserve Units’ Members Access to Sensitive Data

The rollout of Symmetrium ensures the highly confidential data reserve members access remotely never leaves the security of the agency’s network and therefore never resides on external devices. 

Allowing access to confidential information to empower collaboration and data sharing forced a major rethink by a defense agency in Israel. This was not a problem for its full-time staff, who were only authorized to view this data securely from within the organizational IT network through approved and authorized devices. The big concern was how it could guarantee the same levels of security when giving access to its reserve members, which numbered in the tens of thousands and used their own private devices. 

These reserves are in essence third-party contractors that routinely require access to confidential data and systems within the defense agency’s IT network. Third-party vendors are known as the weakest link in enterprise security, and these reserve members were identified as a significant vulnerability. 

 

Vulnerability Due to Use of Non-Secure Instant Messaging Apps 

While most of the agency’s communication is already digital, access to confidential data for reserves was restricted to physical access. This is because it had no solution to maintain its security posture when dealing with reserve members accessing network data using their own devices. Each reserve member is a private individual who from time to time is called to be a part of the agency’s activities. They have their own private device and these are often managed by their employer. Supplying each reservist with a secure and approved device was not practical from a logistical perspective.

The result was that reserve commanders were communicating with their peers  and soldiers over open instant messaging apps without taking into account the confidentiality and security requirements of the defense agency. 

A solution was required that allowed the defense agency to seamlessly manage third-party access in a Bring Your Own Device environment allowing reservists to:

  • Access a secured data sharing system 
  • Seamlessly comply with all confidential data requirements
  • Collaborate in a zero-trust digital environment
  • Create a total separation between their virtual workspace and their personal device

 

Creating a Minimum-Resources Mobile Management Environment 

Symmetrium was the ideal solution as it does not rely on the user profile, device, network or hardware to make sure that the confidentiality of military data is maintained in line with national security requirements.

It sits protected within the perimeter of an organization’s network, adhering to all existing enterprise network security protocols. It can be fully on-prem or in the cloud — the organization decides where. The Symmetrium server is managed from here via a control panel that creates virtual mobile devices (VMDs) as needed. 

These VMDs are hosted on a second Symmetrium server, again deployed inside the organization’s network, which uses P2P encrypted streaming to allow authorized external devices to view data via a portal. This view-only data never leaves the protected organizational network and therefore is never transferred to an external device. This ensures the data at all times remains secure. This helps to reduce and minimize the attack surface, because the assets are not publicly accessible over the internet. 

 

A Fast, Secure Solution for Data Access for Reserve Units 

The defense agency has begun the rollout with high ranking reserve soldiers in one platoon with the setup of 100 VMDs, which will quickly grow up to 10,000 devices as the project expands. It took just three days to set up the entire infrastructure within the agency’s IT network to allow the data to be shared through one portal, with all access managed through the Symmetrium app.

The defense agency’s IT team is now able to create a single virtual device in less than five minutes without any support from the Symmetrium team. This includes assigning it to reserve unit members during their specific service period.

Reservists use a username and password to access the virtual device via a secure portal using their personal phone. While at present they have their two-factor authentication if needed in the future they could also activate biometric authentication (using an eye scan) for an extra layer of authentication. 

If an authorized user (for example, one whose reserve duty has ended) tries to use his phone’s native browser and not using the Symmetrium app installed on their device to access the reserve portal, the data will not be visible. 

 

The Result: An Easy-to-Manage Zero-Trust Environment

The defense agency now benefits from the creation of an easy-to-manage zero-trust environment, which automatically adheres to all existing network security protocols, reducing the headache for its CIO and IT department, saving time, money and resources. 

If there are any violations, such as a reservist or adversary capturing the screen of data, an alert will pop up in the Symmetrium management console. This console also allows administrators to block or allow specific requests for specific users, and change the information they are approved to access. It can also limit access to specific locations or specific networks. This is achieved regardless of the hardware being used to access the data.

Symmetrium’s minimum-resources mobile management solution has very light operational requirements and allows for the quick onboarding and offboarding of reserve users with one single app. This allows productive collaboration with reserves when they are serving with the defense agency, while dramatically minimizing the risk of data breaches. 

Ultimately the complete roll out of Symmetrium will empower secure data sharing and collaboration among the agency’s tens of thousands of reservists.

Isn’t it time you reconsidered your approach to zero-trust data access? Book a demo with Symmetrium here.

close-tag

We’re proud to be the ones making TPRO, CISO, IT and vendors - happy

by ramping up zero-trust mobile access.

Explore all use cases now