smartwatch, technology, watch, time, device, wireless, smart, digital, modern, mobile, gadget, electronic, wristwatch, wearable, touchscreen, wearable tech, sportswear, smartwatche
Photo by indraprojects on Pixabay

Guides

Part of Consumer device security: a practical guide for phones and computers

How to harden personal devices and accounts in one afternoon

Device hardening steps for inventory, updates, locks, encryption, passwords, MFA, recovery, permissions, browser safety, backups, networks, and loss planning.

What to take away

  • Begin with an inventory so no old phone, browser, or account is forgotten.
  • Secure primary email and the device-platform account before lower-impact services.
  • Create recovery methods that do not depend on one phone.
  • Remove excess apps, extensions, permissions, sessions, and network relationships.
  • Finish by testing backup and recovery from another device.

This session is for a stable phone, tablet, or computer that you own. Do not change organization-managed settings without authorization. The reasoning behind each control here is set out in the consumer device security guide. If compromise is already suspected, preserve evidence and use the provider's incident steps instead of treating the device as clean.

A blue USB security key with a gold key symbol
Media credit: Bautsch photographed U2F.USB-Token.jpg on December 11, 2014 and dedicated it under CC0 1.0. The pictured early FIDO U2F device illustrates a physical authenticator; current compatibility varies by service and connector. This media will be removed if the author requests it.

Step 1: make the inventory

List current and spare devices, primary email, device-platform accounts, password manager, carrier account, banking, work or school access, social accounts, cloud storage, and smart-home administration. Mark which phone number, email, or security key recovers each account.

This map reveals circular recovery, such as email requiring the phone while the phone account requires the same email.

Step 2: update the foundation

Back up first, connect reliable power, and install supported system, browser, app, and firmware updates. Restart and check again. Remove devices that no longer receive fixes from sensitive work or replace them when safe use requires current support.

Step 3: strengthen device access

Set a long passcode or password and a short automatic lock. Review enrolled biometrics, lock-screen notification previews, guest accounts, administrator accounts, and automatic sign-in.

Turn on full-device encryption where supported. Save the recovery key away from the device and verify that it belongs to the correct machine.

Step 4: secure primary accounts

Change reused passwords to unique ones generated or stored by a trusted password manager. Begin with primary email, password manager, device account, carrier, and financial services.

Enable multi-factor authentication. Prefer a phishing-resistant method when the service and your devices support it. Register a backup method and store recovery codes offline. Two security keys can provide primary and spare access for suitable accounts, but enrollment and recovery rules vary. How each method fails, and what recovery it needs, is compared in passwords, passkeys, and MFA compared.

CISA's Secure Our World program centers consumer action on recognizing phishing, using strong passwords, enabling multi-factor authentication, and installing software updates. Use those four behaviors as the minimum pass through every important account.

Step 5: review sessions and recovery

Sign out old devices and unfamiliar sessions. Remove obsolete app passwords and third-party connections. Confirm recovery addresses, phone numbers, and trusted people. Check email forwarding rules and filters.

Do not store every recovery code inside the email account it recovers. Hardened recovery also means hardened suspicion: the FTC's notes on recognizing phishing describe email and text messages built around a story, an urgent problem, or a prize, all engineered to pull passwords, account numbers, or codes out of you. Treat recovery prompts you did not initiate with the same suspicion.

Step 6: reduce software reach

Uninstall unused apps after exporting local data. Review browser extensions and mobile permissions. Pay close attention to accessibility, screen recording, full-disk access, device administration, VPN profiles, and configuration profiles.

Restrict camera, microphone, location, contacts, and photos to the narrowest workable access. Test each change so a broken feature has an identifiable cause.

Step 7: secure network relationships

Forget old hotels, rentals, offices, and guest networks. Remove cars, speakers, and computers you no longer use. Review hotspot password and sharing controls. Secure the home router separately with current firmware and encryption.

Step 8: verify backup and loss controls

Check the latest backup date and covered categories. Restore a harmless file. Turn on lost-device location and remote locking, then confirm from another device without issuing an erase.

Record serial number, carrier support, device-maker support, and insurance details. Keep these records outside the device.

Step 9: create a maintenance date

Repeat updates and alerts weekly, permissions and sessions monthly, restore testing quarterly, and full inventory annually or after a move, job change, new phone number, or family change. The item-by-item form of that schedule is the personal device and account security checklist.

Common questions

Should I change every password at once?

Prioritize reused passwords and high-impact accounts. A rushed mass change can cause lockout if recovery is weak.

Are text-message codes useless?

No. They are generally better than password-only access, though stronger phishing-resistant choices may be available.

Should I remove all app permissions?

No. Grant permissions required for a clear function, then test. The goal is least necessary access, not unusable software.

Can I harden a device that may be infected?

Use a known-clean device for account changes and follow trusted incident guidance. Ordinary settings cleanup may not remove persistent malware.

More in Guides