virtual, virtual reality, technology, reality, digital, metaverse, 3d, headset, device, entertainment, modern, goggles, glasses, tech, simulation, game, gadget, person, man, vision
Photo by JESHOOTS-com on Pixabay

Maintenance

Part of Consumer device security: a practical guide for phones and computers

Personal device and account security checklist

Device security checklist for updates, locks, encryption, accounts, MFA, recovery, apps, permissions, networks, backups, physical care, travel, and repair.

What to take away

  • Check updates, backups, account alerts, and physical condition every week.
  • Review permissions, sessions, recovery methods, and connected apps monthly.
  • Test backup and lost-device recovery quarterly.
  • Treat travel, repair, sale, and a phone-number change as security events.
  • Stop and escalate when there is swelling, smoke, unknown administration, or active compromise.

Use the exact controls for the device and current software. Organization-managed devices may require an administrator to make changes. The reasoning behind each item here is set out in the consumer device security guide.

Weekly device check

  • Install supported operating-system, browser, app, and security updates.
  • Restart after completed updates.
  • Confirm the latest backup date and scope.
  • Read sign-in and security alerts.
  • Inspect charger, port, battery area, case, and screen.
  • Investigate unfamiliar apps or profiles before deleting them.
  • Record repeated crashes, heat, pop-ups, or redirects.

CISA's software-update tip sheet explains that providers issue updates to patch security weaknesses and that the protection depends on users installing them. Use automatic updates where supported, then check that they succeed. If none of this has been done yet, start with how to harden personal devices and accounts.

Lock and encryption

  • Use a long passcode or password.
  • Set a short automatic-lock delay.
  • Review enrolled fingerprints and faces.
  • Hide sensitive lock-screen previews.
  • Confirm full-device encryption status.
  • Store encryption recovery keys separately.
  • Lock the screen whenever you step away.

Account review

  • Prioritize email, password manager, device, carrier, and financial accounts.
  • Replace reused passwords.
  • Enable the strongest practical MFA.
  • Register a spare method.
  • Store recovery codes offline.
  • Remove old sessions and devices.
  • Check recovery email and phone details.
  • Inspect email forwarding rules.

App and browser review

  • Remove unused apps after exporting local records.
  • Review camera, microphone, location, contacts, photos, and file access.
  • Inspect accessibility and device-administrator permissions.
  • Remove unused browser extensions.
  • Confirm app publishers and trusted download sources.
  • Review startup and background activity.
  • Cancel subscriptions separately from uninstalling apps.

Network and accessory review

  • Forget old public and guest networks.
  • Remove old Bluetooth pairings.
  • Review VPN and management profiles.
  • Use trusted charging cables and adapters.
  • Do not approve data access when charging only is intended.
  • Secure the home router and inventory connected devices.

Backup and loss preparation

  • Restore a harmless test file.
  • Confirm photos, messages, app exports, and authentication data separately.
  • Turn on lost-device finding and remote lock.
  • Test access from another device without erasing anything.
  • Record serial number, carrier, warranty, and insurer.
  • Keep support contacts outside the device.

FTC guidance on protecting a phone from hackers specifically recommends locking the phone, updating software, backing up data, and enabling the platform feature that can find, lock, or erase a lost phone. These steps need configuration before the phone disappears. The copies that make a lost phone survivable are designed in how to build a personal backup system.

Before travel

  • Update and back up several days early.
  • Download required files and maps.
  • Carry account recovery separately.
  • Review roaming and border rules.
  • Avoid public USB data connections.
  • Keep devices under physical control.

Before repair or sale

  • Back up and photograph device condition.
  • Use repair mode if supported.
  • Ask whether data or storage will be erased.
  • Remove external cards and keys.
  • For sale, remove accounts and activation locks as directed.
  • Erase through the supported process and keep a receipt.

Common questions

Are automatic updates enough?

No. Check that the device remains supported and that updates complete. Some firmware and applications need separate action.

Should I keep Bluetooth off?

Turn it off when it has no purpose, but consider hearing devices, watches, cars, and accessibility tools that depend on it.

Does a backup contain my authenticator codes?

Not necessarily. Confirm the authenticator's own transfer and recovery process.

Is a factory reset a security check?

No. It erases data and settings. Use it only within a verified recovery or disposal process.

More in Maintenance

Maintenance

Cloud storage, sharing, and recovery checklist

Cloud storage checklist for accounts, synchronization, sharing, offline files, versions, deleted-item recovery, local backups, export, subscriptions, and review.