Your smartphone contains more sensitive information than almost any other device you own — banking apps, email, messaging history, payment credentials, authenticator codes, health data, and years of location history. Unlike a laptop that stays at a desk, your phone travels everywhere and is far more likely to be lost, stolen, or briefly accessed by someone else. Keeping your phone secure addresses both the physical access layer (what happens if someone gets the physical device) and the software layer (what apps are installed, what permissions they hold, what data they transmit). You’ll find the complete rundown in our Complete Guide to Online Security and Privacy.
Both layers matter. A phone with excellent software security but no screen lock is immediately exposed when lost. A phone with a strong screen lock but dozens of permission-hungry apps is leaking data continuously even without physical theft.
Screen lock and encryption — the foundation
A phone without a screen lock is fully accessible to anyone who picks it up. The screen lock must be a PIN of at least 6 digits, a password, or a biometric (fingerprint or face recognition) backed by a PIN or password fallback. A 4-digit PIN provides only 10,000 combinations — insufficient against a determined attacker with unlimited attempts. Six digits provides 1 million combinations; eight digits provides 100 million.
- Android: Settings → Security → Screen lock → PIN/Password → choose 6+ digits
- iPhone: Settings → Face ID & Passcode (or Touch ID & Passcode) → Turn Passcode On → select 6-digit or Custom Alphanumeric Code
Full-device encryption is enabled by default on all modern iPhones (hardware encryption tied to the Secure Enclave from the first screen lock) and on Android 10 and later. To verify it’s active:
- Android: Settings → Security → Encryption → should show “Encrypted”
- iPhone: Settings → Face ID & Passcode → scroll to the bottom → “Data protection is enabled” appears when a passcode is set
Encryption means that even if a thief removes the storage from the device or uses forensic tools, the data is unreadable without the passcode. An encrypted phone that is powered off is dramatically more protected than one that is merely screen-locked.
The automatic lock timeout has a bigger impact than most users expect. A 30-minute timeout means anyone who picks up your phone while you’re briefly away from it has 30 minutes of full access. Optimal for most users: 30 seconds to 1 minute of inactivity before the screen locks.
- Android: Settings → Display → Screen timeout → 30 seconds
- iPhone: Settings → Display & Brightness → Auto-Lock → 30 Seconds
App and permission hygiene
The apps installed on your phone and the permissions they hold determine how much data flows to third parties — often without any visible activity on the screen. Every app should have only the permissions it genuinely needs to function, and apps you no longer use should be uninstalled rather than left dormant with existing permissions.
Location permissions are the most sensitive category. Review which apps have location access and change most from “Always” to “While using the app” or “Never.” Maps, navigation, and weather apps legitimately need location. Most other apps do not.
- Android: Settings → Location → App permissions
- iPhone: Settings → Privacy & Security → Location Services
Microphone and camera: apps with these permissions can record audio and video. Grant only to communication and camera apps. Revoke from any app that requested them but has no obvious communication function. iPhone makes active use visible through the orange dot (microphone in use) and green dot (camera in use) indicators at the top of the screen.
Contacts: many apps request contacts to “improve recommendations” or “find friends” — in practice, this uploads your entire address book to their servers. Grant contacts access only to communication apps that genuinely need it.
The quarterly permission audit: in Android, Settings → Privacy → Permission manager shows which apps have which permissions. In iPhone, Settings → Privacy & Security → review each permission category. Remove access from apps that don’t have a clear reason for needing it.
The step-by-step hardening process
- Set a 6+ digit PIN and enable biometric unlock — sets the baseline physical access barrier
- Set auto-lock to 30 seconds — limits the exposure window when the phone is unattended
- Review and update all app permissions — run through Location, Microphone, Camera, and Contacts at minimum
- Uninstall apps you haven’t used in 30+ days — removes permission surface area from apps serving no active purpose
- Enable automatic OS updates — Android: Settings → Software update → Auto download; iPhone: Settings → General → Software Update → Automatic Updates → both toggles On. Security patches address actively exploited vulnerabilities; delays matter.
- Enable Find My / Find My Device — provides remote locate, lock, and wipe capability if the device is lost. iPhone: Settings → [your name] → Find My → Find My iPhone → On. Android: Settings → Security → Find My Device → On (also requires a Google account).
- Back up the device regularly — ensures data survives even if the device must be remotely wiped. iPhone: Settings → [your name] → iCloud → iCloud Backup → Back Up Now. Android: Settings → Google → Backup → Back up now.
- Disable Bluetooth and WiFi when not in use — reduces attack surface in public spaces. Bluetooth in particular enables proximity-based attacks when active.
App-based threats and scams
Install apps only from the official App Store or Google Play. Avoid sideloading apps from third-party websites — these bypass the platform’s malware scanning and represent the primary delivery mechanism for mobile malware on Android. On iPhone, sideloading is not possible through normal means, but third-party apps approved through Apple Business Manager or developer certificates have been used to distribute malware in targeted attacks.
Even within official app stores: review permissions during installation before accepting them. An app requesting camera access for what is described as a barcode scanner is legitimate; an app requesting camera access for a flashlight is not.
SMS phishing (smishing) is increasingly common — text messages claiming to be a delivery service, a bank, or a government agency with a link to click exploit exactly the same instincts as email phishing but through a channel users are often less sceptical of. Treat every text message link from an unknown sender with the same suspicion as an email phishing attempt: don’t click — navigate directly to the service’s official app or website to verify any claimed action. Our guide on avoiding phishing scams covers the full range of techniques including the SMS-specific variants targeting mobile users.
Physical security in public and while travelling
Shoulder surfing — where an observer watches you enter your PIN in public — is a genuine attack vector that has been used to steal PINs before phone theft. Use biometric authentication in public spaces so the PIN is not entered visibly. Keep the phone face-down or in a pocket in crowded areas rather than on a café table or restaurant bar.
Public USB charging ports in airports, shopping centres, and hotels pose a risk called “juice jacking” — charging hardware designed to also transfer data from connected devices. Carrying a power bank eliminates the risk entirely. If you must use a public charging port: use a charge-only USB cable (without data transfer pins) or a USB data blocker adapter that passes power but blocks data lines.
Border crossings: many jurisdictions allow border agents to access unlocked devices during inspection. A powered-off phone with a strong PIN provides more protection than a locked-but-powered-on device in these situations. If concerned about device inspection at a specific border, research the current enforcement practices for that jurisdiction before travel.
Our guide on using a VPN covers encrypting traffic on public WiFi — a complement to device-level hardening that protects the data in transit from your phone, not just the data stored on it. For the technical specifications of iOS and Android security models including Secure Enclave and TrustZone implementations, Apple’s Platform Security Guide covers iOS security in technical detail.
Security comparison — iOS vs Android defaults
| Security feature | iPhone (iOS) | Android |
| Default encryption | Yes — hardware-tied to Secure Enclave | Yes on Android 10+ (enforced by Google Play requirements) |
| App store controls | App Store only (no sideloading for most users) | Google Play + sideloading possible |
| Permission visibility | Excellent (orange/green dots for active use) | Good (Permission manager, but varies by manufacturer) |
| Automatic security updates | 3–5 years of OS updates from Apple directly | Varies widely by manufacturer (2–4 years typical, Pixels longest) |
| Find My / Remote wipe | Find My — integrated, reliable | Find My Device — requires Google account |
| Biometric unlock | Face ID or Touch ID + mandatory passcode backup | Fingerprint / face + PIN/password backup |
iPhone’s more closed ecosystem provides stronger baseline security for most users. Android’s flexibility comes with more security variability — particularly around update cadence, which varies dramatically by manufacturer. A Google Pixel phone with guaranteed update commitments and Android’s latest security features is meaningfully more secure than a budget Android from a manufacturer with a poor update track record. When purchasing Android: consider the manufacturer’s historical update record alongside the hardware specifications.
The often-missed security settings
A few settings that aren’t on most hardening checklists but matter:
- Disable lock screen notifications that show sensitive content: if your lock screen displays full SMS and email content, anyone who picks up the phone can read it without unlocking. iPhone: Settings → Notifications → Show Previews → When Unlocked. Android: Settings → Notifications → sensitive notifications control varies by version.
- Review which apps can send notifications: notification spam from apps you rarely use is a distraction that desensitises you to important security alerts. More importantly, some apps abuse notification permissions for advertising — revoking notification access from apps that misuse it is a worthwhile maintenance step.
- Enable Stolen Device Protection (iPhone, iOS 17.3+): Settings → Face ID & Passcode → Stolen Device Protection → On. Requires biometric authentication (not just PIN) for sensitive actions like changing the Apple ID password when the phone is away from familiar locations. Specifically designed to protect against the attack where a thief watches you enter your PIN then steals the phone.
- Review Google/Apple account activity: these accounts control your phone’s security. Regularly check which devices are logged in and which apps have access — accessible at myaccount.google.com (Android users) and appleid.apple.com (iPhone users).
Phone security, done well, doesn’t require spending more time on your phone — it requires spending a few hours once getting the settings right, then maintaining the habit of quarterly permission reviews and prompt OS updates. The configuration investment is small; the protection it provides is comprehensive against the most common mobile threats.
Two-factor authentication on mobile — the right setup
Authenticator apps on the phone (Google Authenticator, Authy, Microsoft Authenticator) are one of the most important security tools on any device. But the phone is also the device most likely to be lost, broken, or stolen — which creates a recovery risk if authenticator codes are stored only on that phone without backup.
For this reason, cloud backup of authenticator codes matters:
- Google Authenticator: added encrypted Google account backup in 2023 — enable it in the app to ensure codes survive a phone loss
- Authy: has provided cloud backup from the start, accessible on multiple devices simultaneously
- Apple’s iCloud Keychain: stores passkeys and some authentication data, but doesn’t back up third-party TOTP codes
If the phone containing your authenticator app is lost or broken without backup: recovery depends on the backup codes provided during 2FA setup for each account. This is why storing those backup codes in a password manager (accessible from any device) or printed in a physically secure location matters — they’re the only recovery path when the primary second factor is unavailable.
Mobile banking and payment security
Banking apps are among the highest-value targets on any phone. A few specific practices for mobile banking:
- Only use the official bank app from the App Store or Google Play. Don’t access banking through a browser link sent in a text or email — navigate directly to the app or type the URL manually.
- Enable transaction notifications from your bank’s app — immediate alerts for any account activity. A fraudulent transaction detected within minutes limits the damage significantly more than one discovered days later on a statement.
- Avoid using mobile banking on public WiFi without a VPN. Use mobile data (cellular) instead of public WiFi for banking transactions when a VPN isn’t available.
- Log out of banking apps after each session rather than relying on the session timeout — particularly on shared devices or when the phone will be away from your control.
Apple Pay and Google Pay are generally more secure than entering card numbers in apps or websites. The payment credential stored on the device is a device-specific tokenised version of the card number — the real card number is not transmitted during the transaction. A stolen card number from a payment processor breach can’t be used to generate the device token, and the device token can’t be used without the device’s biometric authentication.
Keeping a phone secure is an ongoing practice rather than a one-time configuration. The settings in this guide address the most common mobile threats — physical theft, app-based data collection, smishing, and public network exposure — with controls that, once configured, require minimal ongoing attention beyond the quarterly permission review and prompt response to OS update notifications. The investment is an afternoon; the protection is continuous. See also Secure Remote Desktop for a related case.







