Mobile apps are vulnerable, by definition. Whether your mobile app is in a heavily regulated industry like finance or health care or not, you must take privacy and security measures to protect your users and their data and, if applicable, to comply with industry regulations.
Some security best practices include encryption of data in transit (i.e., SSL/TLS) when transferring personal information, de-identifying user data (i.e., hashing), user authentication (preferably two-factor authentication) and encrypting all sensitive data stored in the cloud. Make sure to consider the effects on power consumption as well.

