On-the-Go Security

Phone Security Checklist: Stop Risky Apps & Phishing Links

Your phone is a wallet, inbox, 2FA key and work tool at once. It deserves more than just a PIN — here are the settings that actually protect it.

· Jun 21, 2026 · updated Jun 15, 2026
Phone Security Checklist: Stop Risky Apps & Phishing Links
Table of contents
  1. Why the phone is the main target
  2. The settings checklist
  3. Step-by-step: lock down your phone
  4. Phishing-link hygiene: the part that actually saves you
  5. Bluetooth and Wi-Fi on the move
  6. Where a VPN fits (and where it doesn't)
  7. Bottom line

Your phone is the most important device you own from a security point of view. It's your bank, your email, your 2FA key, your social media and increasingly your work tool — all behind one lock screen. That's also why most incidents that reach everyday people start here: a scam SMS, a sketchy app, or a notification that nudges you to tap a link. A four-digit PIN is the floor, not the ceiling.

This is a checklist of phone settings worth turning on once, plus the day-to-day habits that stop the most common attacks. It works for both iPhone (iOS) and Android — the menus differ, but the ideas are identical.

Why the phone is the main target

Microsoft's Digital Defense Report 2025 found that the vast majority of identity attacks are simple credential attacks — guessing, reusing or stealing passwords — and that MFA blocks over 99% of them. Your phone is usually where that MFA lives, which makes it both your strongest shield and the prize attackers want. The FTC notes that scam links on phones can lead to spoofed login pages that steal your username and password, or quietly install malware. Locking the phone down protects everything else.

The settings checklist

Setting Why it matters iOS Android
Auto-updates on Closes known security holes Settings › General › Software Update Settings › System › Software update
Strong lock (passcode/biometric) First line of defense if lost Face ID & Passcode Security › Screen lock
Auto-lock (short timeout) Limits exposure when you step away Display & Brightness › Auto-Lock Display › Screen timeout + Lock
Find My / Find My Device Locate, lock or erase a lost phone Settings › [name] › Find My Settings › Security › Find My Device
App permission review Stops apps over-collecting data Privacy & Security Security & privacy › Permission manager
Notification privacy Hides codes/messages on lock screen Notifications › Show Previews Lock screen › notification content
Only official app stores Reduces malicious-app risk App Store (default) Play Store; avoid sideloading

Step-by-step: lock down your phone

  1. Turn on automatic updates. Both the FTC and CISA stress that updates exist mostly to fix security risks. Letting them install automatically is the single easiest win.
  2. Set a strong screen lock. Use a 6-digit (or longer) passcode plus Face ID / fingerprint. Biometrics are convenient; the passcode is the real backstop.
  3. Shorten auto-lock to 30–60 seconds so the phone isn't sitting unlocked on a table.
  4. Enable Find My (iOS) / Find My Device (Android). If the phone is lost or stolen, you can locate it, lock it, display a message, or remotely erase it. Set this up before you need it.
  5. Review app permissions. Go through the permission manager and revoke anything that doesn't make sense — a flashlight app does not need your contacts, location and microphone. Prefer "Allow only while using."
  6. Tidy notification privacy. Stop message and 2FA-code previews from showing on the lock screen, so a glance over your shoulder can't read a login code.
  7. Install apps only from the official store. Sideloaded or "cracked" apps are a common malware route. Stick to the App Store or Google Play.

Phishing-link hygiene: the part that actually saves you

No setting beats not tapping the link. The FTC's guidance on scam texts is direct: if you get an unexpected message asking you to click a link or hand over personal or financial information, don't click. If you think it might be real, contact the company using a phone number or website you already know — never the contact details in the message.

Practical rules:

  • Slow down on urgency. "Your account is on hold," "confirm this delivery," "verify your bank" — manufactured urgency is the tell. Legitimate companies don't text you a link to update payment details.
  • Check the sender and the link, but don't rely on it. Spoofed numbers and look-alike domains are easy. When unsure, open the app or type the address yourself.
  • Report and delete. The FTC recommends forwarding spam texts to 7726 (SPAM) so your carrier can block similar ones, reporting in the Messages app, and reporting to ReportFraud.ftc.gov. Then delete it.
  • Use a safe browser with built-in warnings (Safari and Chrome both flag known dangerous sites) and keep it updated.

For a deeper look at how these messages are crafted today — including AI-generated scam texts:

Read next: AI text scams and smishing in 2026

Bluetooth and Wi-Fi on the move

The FCC recommends turning Bluetooth off when you're not using it and keeping it in "hidden" rather than "discoverable" mode, so unknown devices can't find it. On Wi-Fi, disable auto-connect to unknown networks and watch for fake "imposter" hotspots — if two networks claim to be the café's, ask staff which is genuine.

Where a VPN fits (and where it doesn't)

A VPN app is a useful privacy add-on for your phone when you're on public Wi-Fi, traveling, or using a shared hotspot. It encrypts your traffic so others on the network can't snoop, which is exactly what the FCC suggests for frequent hotspot users.

Be clear about its limits, though. A VPN does not protect against the threats that actually hit phones most: it won't stop a phishing link, it won't remove malware or infostealers, and it won't rescue an account with a weak, reused password. It protects the connection, not your accounts or your taps. It's a layer on top of the basics here — lock screen, updates, MFA, app hygiene — not a substitute for any of them. And the FTC warns that some VPN apps (especially free ones) don't really encrypt your data or quietly share it, so pick a reputable paid provider.

Bottom line

  • Your phone holds your money, identity and 2FA — give it more than a PIN: updates, a strong lock, Find My Device, and tight app permissions.
  • The biggest real-world risk is a tapped link, not a hacker — slow down on urgent texts, verify independently, and report to 7726.
  • A VPN helps on public Wi-Fi and travel, but it doesn't stop phishing, malware or account takeover — treat it as one layer, not the whole defense.

Which do you need first: VPN, antivirus or a password manager?