Mobile device security starts with the phone you already have: its lock screen, updates, account access, and recovery settings. You do not need to install a collection of “cleaner” apps or buy a VPN before doing the basics.
This checklist covers personal Android phones and iPhones. Many principles also apply to tablets, but theft-protection features and menu names vary by device. For a work-managed phone, check with your IT team before changing management settings or removing applications.
Use a strong screen passcode, enable biometrics, install system and app updates, and review app permissions. Protect your Apple or Google account with a unique password and two-factor authentication. Set up Find My or Find Hub before a loss, confirm a recent backup, and keep account-recovery access outside the phone. If it goes missing, mark it as lost promptly; consider erasing only after reviewing the consequences.
Table of Contents
Toggle1. Strengthen Your Screen Lock
A phone left unlocked exposes email, messages, saved accounts, and potentially payment apps. Choose a passcode that is not a birthday, a repeated digit, or a sequence someone can guess. Prefer a longer PIN or an alphanumeric passcode if you can use it reliably.
- iPhone: open Settings > Face ID & Passcode or Touch ID & Passcode. Review your passcode and biometric setup.
- Android: search Settings for Screen lock or Device unlock. Available biometric options depend on the hardware.
- On either platform: choose a short automatic-lock interval and limit sensitive notification previews on the lock screen.
Biometrics make a strong passcode more convenient, but you still need to remember the passcode. Shield it when entering it in public. Do not give it to someone who contacts you claiming they found your phone.

2. Keep Mobile Device Security Updates Current
System updates and app updates fix different things, so check both. A current messaging app does not mean the operating system has its latest security patches.
- iPhone: go to Settings > General > Software Update, install available updates, and review Automatic Updates. Follow Apple’s update instructions if space or installation errors get in the way.
- Android: search Settings for Software update or System update. Also check the Android security update and Google Play system update where available. Google’s update guide explains why availability varies by manufacturer and device.
- Apps: enable automatic updates in your usual app store and periodically check for failed or pending installations.
If the phone no longer receives security updates, treat that as a replacement-planning issue, especially if it handles banking or work accounts. An antivirus subscription cannot replace operating-system patches. Do not infer support status from an old-looking interface alone; check the manufacturer’s policy for your exact model.
Use the Android security patch guide to check the date and distinguish security updates from an Android version upgrade.
3. Review Apps and the Access They Request
Start with apps you no longer need: uninstalling them removes another place where personal information or permissions can accumulate. For new apps, use a trusted store, check the actual developer, and reach the listing from the developer’s official website when impersonation is a concern. A familiar logo or many downloads is not proof of safety.
On Android, open Play Store > profile icon > Play Protect > Settings and keep Scan apps with Play Protect enabled. Google Play Protect checks apps and can warn about, disable, or remove harmful ones. Do not bypass a warning just because a message promises a free upgrade.
Then inspect permissions:
- Android: Settings > Apps > [app] > Permissions. Google’s permission guide also explains the Permission manager for reviewing one category across apps.
- iPhone: Settings > Privacy & Security. Review location, contacts, photos, camera, and microphone access using Apple’s sharing controls.
Prefer access only while using the app where that meets your needs. A navigation app may need precise location; a simple calculator usually does not. If you restrict a permission and a feature stops working, reconsider that specific permission rather than granting everything.
Be especially cautious when a caller or message asks you to install remote-support software, grant Accessibility access, or add a device-management profile. These requests can give another party extensive control. Confirm legitimate workplace requirements through a contact method you already trust.
4. Protect the Account Behind the Phone
Your Apple or Google account is part of your mobile device security setup, not a separate housekeeping task. It may control backups, saved credentials, device location, and account recovery. Use a unique password and enable two-factor authentication; never approve a sign-in prompt you did not initiate.
Check that recovery email addresses and phone numbers are yours and still usable. Keep any recovery codes in a secure place you can reach without this phone. Do not store your only recovery information as a screenshot on the device you could lose.
For important services, consider supported passkeys or security keys. Different authentication methods have different resistance to phishing, so choose deliberately rather than assuming all “2FA” works the same way.
Compare authenticator codes, passkeys, and security keys in the two-factor authentication guide.
5. Set Up Finding and Theft Protection Before You Need It
Android: Find Hub and Supported Theft Controls
Check that the correct Google account is signed in and that Find Hub is enabled. In Settings, search for Find Hub and review whether the phone can be located, including its offline-finding options. Follow Google’s lost-device preparation checklist, then confirm the phone appears when you access Find Hub from another trusted device.
For additional controls, open Settings > Google > All services > Theft protection, or search Settings if your manufacturer uses another path. Review Theft Detection Lock, Offline Device Lock, and Identity Check if offered. Availability differs by model and software; some features do not support tablets or Android Go. Google’s theft-protection guide lists the requirements. A missing switch is not a reason to install an unknown replacement app.
iPhone: Find My and Stolen Device Protection
Confirm Find My is enabled before the phone disappears. Also review Settings > Face ID & Passcode (or Touch ID & Passcode) > Stolen Device Protection. Follow any setup requirements shown.
Stolen Device Protection adds biometric checks to certain actions and can require a security delay for sensitive changes. By default, its additional measures apply away from familiar locations; the Always option applies them regardless of location. It is extra protection, not a replacement for promptly marking a stolen phone as lost.
Test your ability to sign in to the finding service now. Do not test by erasing or marking a phone lost unnecessarily. Knowing your password is not enough if every recovery method depends on the missing device.
6. Confirm What Your Backup Actually Covers
Check the most recent successful backup, not just whether the backup switch is on. A full storage account, failed upload, or excluded app can leave important data behind.
- Android: check Settings > Google > All services > Backup. Use Back up now when needed and review the included data. Google notes that not every app can restore all its data; photos may need their separate Google Photos backup settings.
- iPhone: check Settings > [your name] > iCloud > iCloud Backup. Apple’s iCloud backup instructions show how to run a backup and check its completion time.
Check chat apps, authenticator apps, and files stored only inside an app separately. For irreplaceable photos and documents, keep another verified copy where practical. Syncing a library and keeping an independent recovery copy are not necessarily the same thing.
Use the backup guide to plan independent copies and check that you can actually restore important files.
7. Handle Messages and Public Wi-Fi Without Panic
A delivery text, QR code, or urgent account warning can lead to a convincing fake sign-in page. Open the organization’s known app or type its established website address yourself instead of following an unexpected login link. Good spelling and a familiar sender name do not make a request genuine.
Public Wi-Fi does not automatically expose every password. The FTC explains that widespread encryption makes public Wi-Fi use generally safer than it used to be. HTTPS protects data in transit, but a scam website can use HTTPS too.
Verify the network name with the venue, do not ignore certificate warnings, and use mobile data when you do not trust the connection. A VPN can change who carries your traffic; it does not make a fake website legitimate or stop you handing over a verification code. Never install a “security update” offered by a hotspot page.
8. If the Phone Is Lost, Lock First and Erase Carefully
From another trusted device, open the official finding service directly. On Android, use Find Hub and Mark as lost; on iPhone, use Find My or iCloud’s finding service and mark the device as lost. See Google’s lost-device instructions or Apple’s stolen-device checklist.
Contact your mobile carrier about suspending the line, and report suspected theft to local police. Do not confront someone at a map location. If account activity or transactions are suspicious, contact the affected provider through a known channel and secure the account from a trusted device.

Remote erasing permanently deletes local data. After an Android erase, its location is unavailable in Find Hub. For a stolen iPhone, do not remove it from Find My, even after erasing: removal disables Activation Lock. Review backups and the platform’s current instructions before confirming an erase.
Be suspicious of follow-up messages asking for your passcode or asking you to remove the device to “verify ownership.” If your employer manages the phone, notify IT as well so they can follow their incident process.
Mobile Device Security FAQs
Does an iPhone need an antivirus app?
Do not expect an iPhone app to scan the whole system like desktop antivirus. Apple’s sandboxing model limits third-party apps’ access to other apps and system resources. Security apps may offer specific services, but updates, careful app choices, account protection, and phishing awareness remain essential.
What should I do after opening a suspicious link?
Close the page and do not download anything or grant permissions. If you entered a password, change it through the real service on a trusted device and review active sessions. If you installed an app or profile, investigate and remove the unwanted access; contact IT for a managed device. A click alone does not prove infection or automatically require a factory reset.
Is fast battery drain proof that my phone is hacked?
No. Battery drain, heat, and extra data use can have ordinary causes such as an update, weak signal, or a busy app. Investigate unfamiliar apps, unexplained permissions, security alerts, and account activity together. Avoid “cleaner” apps advertised through frightening pop-ups.
Do I need every security switch enabled?
No. Understand what a setting does and whether your device supports it. Prioritize a strong lock, current updates, appropriate permissions, protected accounts, finding tools, and recoverable backups. Workplace policies or a higher-risk situation may call for additional measures.
Make Security a Short, Repeatable Check
Finish your mobile device security setup by checking updates, reviewing a few high-access apps, confirming the phone appears in its finding service, and checking the last successful backup. Repeat after changing phones, accounts, or important apps. The aim is a maintained setup you understand, not a screen full of security badges.



