Cyber Security
Mobile Phone Security: How to Protect Your Smartphone and Personal Data
Your smartphone may be the most important computer you own.
It contains your email, messages, photos, banking applications, passwords, authentication codes, contacts and often access to both personal and business systems.
That makes mobile phone security about much more than protecting the physical device. If someone gains access to your phone, they may also gain access to a large part of your digital life.
Fortunately, modern smartphones include excellent security features. The key is making sure they are enabled and using the phone in a way that does not accidentally bypass those protections.
Why your phone is such a valuable target
Think about what your phone can access.
- Your primary email account
- Online banking and payment applications
- SMS authentication codes
- Authenticator applications
- Saved passwords and passkeys
- Social media accounts
- Business email and cloud systems
- Personal photos, documents and messages
- Your contacts and communication history
Your email account is particularly important because password reset links for many other services are sent there.
If someone controls both your phone and your email account, they may be able to reset passwords and progressively take control of other accounts.
Start with a strong phone lock
Your screen lock is the first line of defence if your phone is lost or stolen.
Use Face ID, fingerprint recognition or another supported biometric method, backed by a strong PIN or passcode.
Avoid obvious PINs such as your birthday, address, repeating numbers or simple patterns.
Your phone should also lock automatically after a short period of inactivity. Leaving a phone unlocked for long periods greatly increases the damage that could occur if someone gets physical access to it.
Keep your phone and apps updated
Install operating system updates. Security updates repair vulnerabilities that attackers may otherwise be able to exploit.
Update your applications. Apps can also contain security vulnerabilities, so keeping the operating system updated is only part of the job.
Enable automatic updates. For most users, automatic updates are the simplest way to avoid running outdated software.
Replace unsupported devices. A phone that no longer receives security updates can become increasingly difficult to protect regardless of how carefully it is used.
Be careful which apps you install
Applications can potentially access an enormous amount of information stored on your phone.
Wherever possible, install applications through the official Apple App Store or Google Play Store rather than downloading software from unknown websites, advertisements or links received in messages.
An app appearing in an official store does not mean you should install it without consideration. Check who developed it, whether you actually need it and whether its requested permissions make sense.
An application providing a simple calculator, for example, should not normally need access to your contacts, microphone, location and photographs.
Review app permissions
Both Android and iPhone allow you to control what information applications can access.
Periodically review which apps have permission to access:
- Your location
- Camera
- Microphone
- Contacts
- Photos and files
- Bluetooth
- Local network devices
If an application does not need access to something, remove that permission.
It is also worth deleting applications you no longer use. Every unnecessary application is another piece of software that needs to be maintained and trusted.
Your phone does not protect you from phishing
Smartphones can actually make some phishing attacks more difficult to recognise.
Small screens may hide parts of an email address or website URL, and people tend to interact with messages quickly while using a phone.
Be cautious with unexpected links received through SMS, email, messaging applications or social media.
Delivery notifications, banking warnings, unpaid tolls, account suspension notices and password expiry messages are commonly used to persuade people to open fraudulent websites.
If a message claims there is a problem with an account, open the organisation's official app or type its website address into your browser rather than using the supplied link.
Be careful with public Wi-Fi
Prefer mobile data where practical. Your mobile data connection is generally a better choice than an unknown public Wi-Fi network.
Check the network name. Attackers can create Wi-Fi networks with names that resemble those of hotels, airports, cafes and other public locations.
Disable automatic connection. Do not allow your phone to automatically join any available public network.
Avoid sensitive activity on untrusted networks. Be particularly cautious with banking, business systems and other sensitive services.
Forget networks when finished. Removing old public networks can prevent your phone automatically reconnecting to them later.
Bluetooth, QR codes and unexpected connections
Mobile phones interact with more than just websites.
Bluetooth, QR codes, wireless networks, USB connections and nearby devices can all cause your phone to communicate with other systems.
Do not connect unfamiliar USB cables, storage devices or accessories simply because you find them in a public place.
QR codes should also be treated as links. A QR code can direct your phone to a fraudulent website just as easily as a link in an email.
Before continuing after scanning a QR code, check what website or action your phone is proposing to open.
Protect banking and financial apps
Banking applications should use biometric authentication or another additional security control wherever available.
Avoid storing banking passwords in plain text notes, messages or contacts.
Be particularly suspicious of telephone calls or messages asking you to transfer money to a so-called safe account, install remote access software or provide authentication codes.
Legitimate security controls are designed to protect you. Anyone asking you to disable those controls should immediately be treated with suspicion.
Use multi-factor authentication
Multi-factor authentication provides an additional barrier if someone obtains your password.
Authentication applications, passkeys and hardware security keys can provide stronger protection than relying entirely on SMS verification.
However, never approve an authentication request you did not initiate.
An unexpected login approval request may indicate that someone already has your password and is attempting to access your account.
Prepare for your phone being lost or stolen
Enable device tracking. Make sure Apple's Find My or the equivalent Android device-finding service is configured before you need it.
Keep backups. Important photographs, contacts and other information should not exist only on your phone.
Know your account password. You may need to access your Apple or Google account from another device quickly.
Know how to remotely lock the device. Lost-device services can help locate, lock or erase a missing phone.
Contact your mobile provider. If the phone has been stolen, your provider can assist with protecting the mobile service and replacing the SIM.
iPhone users should consider Stolen Device Protection
Apple provides a feature called Stolen Device Protection that adds extra security if someone steals an iPhone and also knows the device passcode.
Certain sensitive actions can require Face ID or Touch ID rather than allowing the phone's passcode to be used as an alternative.
Other important account changes may also introduce a security delay, giving the owner additional time to identify that the phone is missing and protect the account.
This can be particularly valuable because knowing a phone's unlock code can otherwise give a thief access to information that may help them target other accounts.
Remember that your mobile number is also an account
Your mobile number may be used to receive password reset messages and authentication codes.
Criminals sometimes attempt to take control of a victim's mobile number through SIM replacement or account takeover attacks, commonly referred to as SIM swapping.
Protect your mobile provider account with a strong password or PIN where available, and investigate unexpected loss of mobile service immediately.
If your phone suddenly loses service without an obvious reason, particularly while other people nearby still have normal reception, contact your mobile provider.
Mobile security matters for business too
Personal phones are frequently connected to business email, cloud storage, customer information and workplace messaging systems.
This means a compromised personal device can potentially become a business security incident.
Businesses should decide what information can be accessed from mobile devices, require appropriate screen locking and multi-factor authentication, and have a procedure for removing access when a device is lost, stolen or an employee leaves.
What about privacy-focused phones?
Standard iPhone and Android devices can be secured very well when they are kept updated and configured correctly. However, some users want a higher level of privacy and tighter control over the operating system and installed services.
One option is GrapheneOS, a privacy and security-focused mobile operating system built for selected Google Pixel phones. It is designed to strengthen Android security while giving users greater control over permissions, applications and Google services.
For users with higher privacy requirements, including business owners, professionals and people handling sensitive information, a properly configured GrapheneOS phone can be worth considering.
A simple mobile security checklist
Use a strong PIN or passcode and enable biometric unlocking.
Enable automatic operating system and application updates.
Only install applications you actually need.
Review app permissions periodically.
Use multi-factor authentication on important accounts.
Do not approve unexpected authentication requests.
Treat unexpected SMS and messaging links with suspicion.
Prefer mobile data over unknown public Wi-Fi.
Enable your phone's lost-device tracking service.
Maintain backups of important information.
Your phone is part of your cyber security
Mobile security is no longer separate from computer security.
Your phone is often the device used to approve logins, reset passwords, access banking and communicate with both personal and business contacts.
Keeping the device updated, locked and properly configured significantly reduces the likelihood that losing a phone, installing the wrong app or opening a malicious message develops into a much larger security incident.
Further information
The Australian Signals Directorate's Australian Cyber Security Centre provides practical guidance for securing mobile phones and other devices.