In Mobile App Marketing, Engagement Is Success

Jul 26, 2018 | Mobile, Social Media

Featured article by Emma Jones, content writer at TechsCrunch

The very nature of mobile app advertising is changing. Marketers used to measure the click-through rate as a metric of campaign success. Then came the era of mobile installs, meaning the primary goal was to drive mobile app users to install the app, regardless of what actions followed. Now we’re in the era of driving engagement—that is, meaningful actions users take after the initial installation of an app.

App Engagement: Going Beyond Installs

The problem with optimizing your marketing campaigns for app installs is that there’s no guarantee users will take subsequent actions. Many apps today operate on a “freemium” pricing model, meaning there’s no up-front cost for users to download them. This makes installing an app very low risk because people have nothing to lose except a bit of storage space. However, it also means many users will install your app without taking any further action.

Monetizing your app in a freemium landscape depends heavily on users engaging in important post-install events that boost the lifetime value of your user base. The lifetime value of a user who installs a free app then neglects to engage further is $0. But the value for a user who creates an account or makes an in-app purchase is much higher, thereby justifying the acquisition cost and increasing ROI.

This change in priority from installs to post-install engagement is precisely why some modern app advertising companies now optimize for Cost-Per-Action (CPA) instead of Cost-Per-Install (CPI). This means marketers will only pay when mobile users engage in these desirable actions specific to the nature of the app. For example, post-install events for ecommerce apps may look like account registration, placing an item in the shopping cart or completing a transaction. Social networking apps measure actions like creating a profile and sharing content. Post-install events for dating apps include creating a profile, sending a message and signing up for a premium subscription.

The key is to define the post-install events important to your app based on their potential for driving conversions and revenue. Then it’s important to market with this engagement in mind as the goal rather than installs alone.

Targeting the Right Mobile Users

Part of driving engagement is simply connecting with the right mobile users—people inherently more likely to derive value from your app and thus keep engaging over time. The data analytics available to marketers today makes it possible not only to identify your target audience, but to create a target lookalike audience based on shared demographics and mobile behaviors. In other words, it’s possible to seek out people like those users who already engage with your app, heightening the relevancy of your ad campaigns.

Data also makes it possible to show this target lookalike audience highly personalized ads. Dynamic ads assemble programmatically on the spot based on user data, meaning individuals will see ads that speak to their lifestyles and behaviors.

Let’s say you’re launching a mobile campaign for your dating app. Serving dynamic ads to your target lookalike audience ensures users see relevant ads, whether we’re talking about a 20-year-old female iPhone user from Chicago or a 40-year-old male Android user from rural Texas.

Re-Engaging Dormant App Users

There’s also the matter of reengaging users. Many people install an app with the intention of using it, only to get sidetracked shortly thereafter. Thus, the app sits dormant on their mobile device. This represents a wasted monetization opportunity for developers. The solution? Serving dynamic retargeting ads specifically motivating users to re-engage wherever they left off in the funnel.

In today’s mobile app marketing world, engagement—not installation—is success.

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more