Advanced Mobile Solutions (AMS) guidance trailer
Chris P explains how AMS will enable high-threat organisations to stay connected ‘on the go'.

Curly_photo via Getty Images
Accessing work resources on mobiles or tablets while out of the office has been standard business practice for most of this century. However, organisations with highly sensitive data and systems, which are under threat from the most capable attackers, have not been able to work in this way without taking significant security risk.
To address this, the NCSC has developed ‘Advanced Mobile Solutions’, or AMS. AMS is a risk model, together with a set of architecture patterns and associated technologies, that allow high-threat organisations to stay connected ‘on the go’.
This blog outlines what AMS is, and why you might want to use it. In the meantime, you can talk to us about it at CYBERUK 2024.
Why secure mobile is hard
In the past, governments have created bespoke secure phones. However, this is no longer practical; users expect a modern experience, commensurate with their personal devices. Creating a bespoke, appropriately secure phone with a similar experience (and keeping it up to date) would be unfeasibly costly. Realistically, this means we have to use ‘consumer grade’ devices.
However, this causes issues:
- Across government we use ‘high grade’ (ie carefully designed and evaluated) crypt appliances to protect our most sensitive communications. However with current technology, it's not practical to use such an approach with consumer grade mobile devices.
- Consumer grade mobile devices are complex and powerful. This means that they sometimes have vulnerabilities (such as those that were exploited by the widely publicised Pegasus malware). For most consumers this should not be of significant concern, as any widescale use of such vulnerabilities will be rapidly discovered and fixed. However for high threat organisations (that are subject to attacks from the most capable attackers), this is a problem. Such attackers may be able to find as-yet undiscovered vulnerabilities, and keep them secret.
- If a user’s device is compromised, it could be used to attack services that it is legitimately allowed to access (such as an email server). This means the attacker now has a way to attempt to attack core infrastructure.
So the challenge is to design a risk model and architecture where:
- We accept that individual devices (and the data they can access) may from time to time be compromised.
- We aim to protect entire fleets of devices from compromise.
- Compromises don’t threaten data in bulk, or threaten the security of sensitive systems.
The AMS risk model
To use AMS, you first need to accept the risk model that underpins it, and be happy that you can appropriately manage the risks.
The AMS risk model states that you need to:
- accept some data loss from the mobile system to enable modern business practices
- reduce systemic risk (that is, reduce the likelihood of staff using less secure comms platforms, or finding insecure workarounds)
As mentioned, AMS is for organisations and systems which are under threat from the most capable adversaries, such as nation states. We assume these attackers will invest significant time and money to attempt to compromise such organisations’ systems. They may use zero-day vulnerabilities, social engineering and other techniques over a number of years to obtain data or disrupt systems.
To operate secure mobile solutions in the face of such threats, AMS has the following key principles:
1. Mobile devices cannot be trusted
We presume that an individual mobile device may be compromised, that information on it may be at risk, and that it may be used as an attack path into your mobile infrastructure.
You must accept this risk if you want to deploy mobile devices; any protections you try to deploy to protect the device will be imperfect.
Networks should therefore be designed in a way that assumes that individual devices will be compromised, and security built around protecting other devices and data when this happens.
2. Core networks and services must be protected
As we assume an attacker will be able to compromise any server the devices can connect to, we must build a robust border between your mobile infrastructure and your core network. This must prevent an attacker who has fully compromised the mobile infrastructure from reaching the core.
3. Sensitive data must not be aggregated in the mobile infrastructure
As we assume the mobile network will be compromised, we must avoid any point in the mobile infrastructure aggregating plain text, sensitive data. For the purpose of this principle, we consider aggregation to include data which is transiting across servers, as well as being stored on the servers.
The AMS architecture
To enable secure mobile working in line with the threat and risk model described above, we have developed an AMS architecture that:
- protects consumer mobile devices as well as possible
- prevents data from being aggregated in mobile infrastructure
- provides very robust protections for core systems by using hardware-backed, cross domain technology
We are currently writing detailed architectural guidance along with risk advice. The risk advice is important, as every organisation has different needs, and secure mobile is not ‘one size fits all’. Where appropriate we provide different options or explain what additional risks you take if you deviate from parts of the architecture. This helps you to make sensible, pragmatic risk decisions for your business needs.
Below is a high-level overview of the key elements of the architecture.
Protect the device
User devices are managed by an MDM (Mobile Device Management) system and locked down so that only required apps are available. Internet-connected apps shouldn’t be used without going via remote browser isolation gateways (which in government, we call ‘browse down gateways’).
We use carefully designed MDM deployment configurations, sometimes with cross domain technology to protect the fleet against compromise.
We are building devices to mitigate baseband (radio stack) attack risks.
Protect data on global networks
While ultimately we want to support NCSC-evaluated high grade cryptography, this isn’t possible with current technology (and isn’t desirable for some use cases, such as where users may be in locations where network connections may be restricted, or certain protocols blocked). Therefore we use best-of-breed commercial technology to protect data in line with the wider AMS risk model.
Protect your border
We use the scale of public cloud services and highly specific monitoring rules to reduce the risk of DDoS attacks on data centres, and to help identify malicious activity.
We recommend either high grade or ephemeral VPN terminators to reduce the risk of direct attack from the internet.
Protect your remote access zone
We define the remote access zone as the infrastructure between the internet and cross domain gateways protecting your core systems.
Our patterns are based on the DMZ being highly ephemeral; that is, few services (or pieces of user data) persist across sessions. This makes it harder for attackers to maintain persistence, and reduces the risk of data being stolen in bulk.
We also use layers of cryptography to protect against information being disclosed due to elements of the infrastructure being compromised.
Protect your core networks and systems
Not all secure mobile systems need to access enterprise services such as email and chat. But where they do, we use cross domain solutions built on hardware (FPGA)-based cross domain gateways to robustly inspect all data entering core networks. This protects against network and content bound attacks. You can read more about this in the NCSC blog on cross domain security.
We use public key cryptography-based user identity, and release control to manage the risk of sensitive data being exfiltrated from core systems.
Assume compromise
Because of the nature of secure mobile systems, you should assume that they will be periodically compromised. This may seem like a security failure, but it's simply being realistic. To assume otherwise implies a lack of understanding of the risks that exist. If your system is well architected and monitored, limited compromise should not be catastrophic, and this risk can be balanced against the business benefits of mobile working.
AMS’s monitoring approach aims to quickly detect compromise, ideally before data is stolen. AMS’s architecture is designed to be rapidly re-deployed to recover from compromise.
How is AMS being deployed?
We have developed the architecture and risk models for AMS. Much of the required technology has been (or is being) licenced for sale to government, and we are finalising the documentation of the risk and design guidance.
A managed service for enterprise workers (based on AMS) is now available across government. We are looking to expand the available of AMS patterns and technology to other sectors, such as critical national infrastructure.
AMS has taken years of research and development, funded from multiple government departments and working with many organisations and subject matter experts. We’d like to thank everyone who’s been involved in it so far.
We’ll post further information on the NCSC’s website over the coming months. But in the meantime, you’ll be able to talk to a number of AMS technology providers at CYBERUK 2024, or you can contact the NCSC directly for further information.


