Mobile device security
The only device nobody set upon purpose
Your laptop was configured by someone. Your phone was configured by whoever was standing in the shop, and it has since become the thing that holds your email, your second factor, your photographs and frequently your firm’s files. It is also the only one of your devices that regularly gets left in a taxi.
This page is a guide, not a product. Everything below can be done by you, this afternoon, for nothing. Each item says how long it takes and — more usefully — what it does not protect you from.
Worth doing
Eight things, in order of consequence
The first four change what happens when a phone is lost or an account is taken. The rest reduce how often you get there. If you only do one, do the first.
0 of 8 done
Ticks are yours alone — nothing is saved or sent, and a refresh clears them.
01Protect the email account above everything else
Ten minutes, onceYour email address is the reset mechanism for every other account you own. Someone who controls it controls your bank, your practice-management login and your cloud storage, without needing any of those passwords. It should have a password used nowhere else and the strongest second factor the provider offers.
What it does not cover — It does nothing for accounts that do not use that address, and nothing at all if the second factor is a text message and your phone number is taken from you — which is the next item.
02Move off SMS codes where you can, and set a carrier PIN where you cannot
Twenty minutes across your main accountsCodes sent by text are the weakest common second factor, because a phone number can be moved to another handset by convincing a carrier's support agent. An authenticator app or a passkey stays on your device. Where a provider only offers SMS, ask your carrier to put a port-out PIN or account lock on the line.
What it does not cover — Carrier protections vary and are enforced by people, so they reduce the risk rather than remove it. Authenticator apps are still lost with the phone unless the backup is set up deliberately.
03Set a real passcode, then add the fingerprint or face
Two minutesBiometrics are the convenience layer; the passcode is the actual key, and it is what protects the encrypted contents of the device. Six digits is the sane floor and an alphanumeric passphrase is meaningfully better. A four-digit code on a phone that holds your email is not a lock, it is a gesture.
What it does not cover — It protects a device that is off or locked. It does nothing about a phone handed over unlocked, and nothing about what is already synced to a cloud account.
04Turn on remote find and remote wipe, and check it works
Five minutes, plus one testBoth platforms include it and both need an account signed in for it to function. Test it once from a laptop so you know what the screen looks like, because the afternoon you actually need it is not the afternoon to learn the interface.
What it does not cover — A wipe needs the device to reach the network. A phone that is already switched off, or has had its SIM pulled, may never receive the command — which is why the passcode matters more than the wipe does.
05Let the operating system update itself
One minuteThe gap between a phone patch being published and being installed is the window that attacks are written for. Automatic updates close it without anyone having to notice. This is the single highest-value setting on the device and it takes one toggle.
What it does not cover — Only while the handset is still supported. A phone past its last security update cannot be made safe by any setting, and that is the point at which it should be replaced rather than configured.
06Install from the official store, and review what you already gave away
Fifteen minutes for a first passSideloaded applications and configuration profiles from a link are the most common way a personal phone ends up genuinely compromised. Worth doing once: read the list of apps with access to your location, microphone, contacts and photos, and remove the ones that no longer earn it.
What it does not cover — Store review catches a lot and not everything. A well-reviewed app can still collect more than you would like, which is what the permission list is for.
07Treat the browser's password memory as a convenience, not a vault
An hour to move across, then easier foreverPasswords saved in a mobile browser sit in a place that malware is specifically written to read, and it takes everything at once — including the accounts used to reset the other accounts. A real encrypted password manager is a different category of thing and syncs across your machines properly.
What it does not cover — A password manager concentrates risk into one vault, so its own password has to be strong, memorised and different from everything else.
08Assume public Wi-Fi is somebody else's network, because it is
No setup; it is a habitMost traffic is encrypted in transit now, so a hostile network learns less than it used to. It still learns which services you connect to and when, and it can interfere with anything not properly encrypted. Cellular data is the simplest answer. A tunnel is the other one — see below.
What it does not cover — Encryption in transit does not protect you from a convincing login page. The network is rarely the thing that catches people out; the page asking for a password is.
One tool worth knowing about
Cloudflare WARP, and what it actually does
Cloudflare publishes a free app called 1.1.1.1 with WARP. It runs on phones, tablets and computers, and it does two related but genuinely different things depending on which mode you leave it in.
1.1.1.1 on its own
Encrypts your DNS lookups only — the step where your device asks what address a name belongs to.
Your network operator stops seeing a plain-text list of every site you visit. Everything else about your connection is unchanged.
WARP switched on
Routes your device's traffic through Cloudflare's network as well as forwarding DNS. Cloudflare's own documentation calls this Traffic and DNS mode, and describes it as routing device traffic for all ports and protocols.
The sites you visit see a Cloudflare address rather than yours, and the network you are sitting on sees far less. On a congested or badly-routed connection it is sometimes faster, because you join Cloudflare's network early.
- It moves trust, it does not remove it. Your ISP and the coffee shop see less; Cloudflare sees more. That is a reasonable trade for most people and it is still a trade, and you should make it knowingly.
- It is not an anonymity tool and it is not a country-shifting VPN. It will not make you untraceable and it will not get you a different region's streaming catalogue.
- Tunnelling everything costs some battery and some data overhead. On a metered plan that is a real number rather than a rounding error.
- Some corporate networks, hotel portals and public Wi-Fi logins break while it is on. The fix is usually to turn it off for a minute, which is fine, as long as you remember to turn it back on.
Worth installing on a personal phone, particularly one that travels. Leave it off on a device your employer manages, because it will collide with whatever they already run and you will spend an afternoon finding out why.
Where this meets work
Three situations, and they are not the same
Most confusion about phones comes from treating a company-issued handset, a personal one that reads company email, and a partner’s own device as if they were one problem.
If your employer provisions the phone
It is already managed, and the settings above are mostly decided for you. Do not install a personal tunnel on it, do not sideload, and raise anything that looks wrong with whoever runs it rather than fixing it yourself.
If it is your phone and it reaches work email
You are the boundary. Everything on this page applies to you more than to anyone else, because a compromise of your personal device is a compromise of your firm's mailbox, and most firms have no way of finding that out.
If you are the one who decides
Then the question is not whether staff phones reach company data — they do — but whether anyone can list which ones and remove access from a phone that walks out. That is a bring-your-own-device conversation, and it is a short one.
If your household needs this handled rather than explained, home and family memberships cover phones alongside everything else. If it is your firm’s devices you are thinking about, cloud, email and identity is where mobile management sits.
Nothing here needs us
That is deliberate. If you want the rest of it handled rather than done yourself, that is a twenty-minute conversation and we will tell you plainly if you do not need one.
Or call 1-855-966-2967