Back to all articles

Smartphone hygiene everyone can manage: updates, permissions, lock screen

Phones now gate mail, banking, health portals, and family photos. Attackers target weak lock patterns, outdated OS builds, sideloaded apps, and fake alerts. Most defense is settings and habit, not expensive suites.

Lock screen and biometrics

A strong PIN/password is baseline; biometrics are convenience, not a substitute for account recovery codes stored safely. Avoid trivial patterns. On Android, ensure periodic full-password challenges, not only biometrics.

Enable remote lock/wipe (Find My Device / Find My) before a loss — not after.

OS and app updates

Vendors patch kernel and browser bugs constantly. Overnight auto-updates are the simplest defense against known exploits. Outdated apps carry the same risk.

Devices that no longer receive security updates accumulate risk; plan replacement when support ends.

Permissions and install sources

Stick to Google Play and the App Store; Android APKs from e-mail bypass store review. Question whether a flashlight app needs SMS and contacts — usually not.

Remove unused apps periodically. For children, use family profiles to block surprise installs and purchases.

Public Wi‑Fi and VPN

Avoid logging into sensitive sites on café Wi‑Fi without HTTPS (rare today, but not impossible). A reputable VPN or mobile data helps for high-sensitivity work. See guest and office Wi‑Fi.

Backups and post-theft steps

Cloud backup for photos and contacts speeds recovery. After a theft, change major passwords from another device and revoke sessions where providers allow (Google, social, banking).

Related: MFA and password managers, smishing, patching in business (same ideas, stricter process).