Smartphone Security: How to Protect the Phone That Runs Your Business

By J. Mesa

Your phone receives your bank’s security codes. It holds your work email, your customer texts, your authenticator app, and your saved passwords. A thief who gets into it gets into nearly everything else. Summer travel season raises the odds of a lost or stolen phone, so spend fifteen minutes on the settings below before your next trip.

Why do criminals target phones?

A phone is the key ring for your digital life. Password resets go to its email. Verification codes go to its text messages. Banking apps live on its home screen. Criminals pursue phones in four ways: stealing the device, hijacking the phone number, tricking you with a text message, and planting a malicious app.

What are the most important phone security settings?

Work through this list.

  1. Set a strong passcode. Use six digits at minimum. A longer alphanumeric passcode is better. Skip birthdays and repeated numbers.
  2. Use Face ID or fingerprint unlock. Biometrics keep you from typing the passcode in public, where a thief can watch.
  3. Set the screen to lock after 30 seconds to one minute.
  4. Turn on automatic updates for the operating system and for apps.
  5. Turn on the theft protections. On an iPhone, enable Stolen Device Protection. On Android, enable Theft Detection Lock and Identity Check where available. These features demand a biometric check, and sometimes a delay, before anyone changes your account password or security settings.
  6. Turn on Find My on iPhone or Find Hub on Android, so you can locate, lock, and erase a missing phone.
  7. Hide message previews on the lock screen. A thief should not be able to read a verification code without unlocking the phone.
  8. Back up the phone to iCloud or your Google account, with a strong password and multi-factor authentication on that account.
  9. Limit what works from the lock screen: wallet, control center, voice assistant, and USB accessories.

Thieves in bars and on transit watch a victim type a passcode, then grab the phone. With the passcode, they change the account password within minutes and lock the owner out. The theft protection features in step 5 exist to stop that attack.

What is SIM swapping, and how do I prevent it?

SIM swapping is a fraud in which a criminal convinces your mobile carrier to move your phone number to a SIM card or eSIM the criminal controls. Your phone loses service. The criminal receives your calls and texts, including the codes your bank and email provider send.

Protect the number:

  • Add a port-out or number transfer PIN with your carrier.
  • Turn on the carrier’s SIM protection or number lock feature. AT&T, Verizon, and T-Mobile each offer one in their apps.
  • Set a unique password and multi-factor authentication on your carrier account.
  • Move your important accounts away from text message codes. Use an authenticator app, a security key, or a passkey.

If your phone shows “No service” or “SOS only” in a place where it normally works, call your carrier from another phone at once, then check your bank and email accounts.

What is smishing?

Smishing is phishing by text message. Common versions claim an unpaid toll, a package that could not be delivered, a bank fraud alert, or a message from your boss asking for gift cards. The link leads to a fake page that collects your card number or password.

Do not tap links in unexpected texts. Do not reply. Open the company’s app or type its address yourself. Forward the text to 7726, which spells SPAM, and delete it.

Are iPhones more secure than Android phones?

Both are secure when you keep them updated and install apps only from the official store. The differences that matter:

  • Apple controls the hardware and the software, so iPhones receive updates for many years on one schedule.
  • Android update support depends on the maker. Google Pixel and recent Samsung Galaxy phones receive up to seven years. Low-cost models may receive two or three.
  • Android allows app installs from outside the Play Store. Leave that setting off.

An old, unpatched phone of either type is the real risk. Check your model’s support end date, and replace the phone when updates stop.

How do I spot a dangerous app?

  • Install apps only from the App Store or Google Play.
  • Read the developer name and the reviews. Fake apps copy the icons of real ones.
  • Question the permissions. A flashlight app has no need for your contacts, microphone, or location.
  • Review app permissions twice a year and remove apps you no longer use.
  • Decline any request to install a configuration profile or enable accessibility access unless your own IT team asked for it.
  • Leave Play Protect on.

Is public Wi-Fi safe on a phone?

Mostly, for everyday use. Apps and websites encrypt their traffic. The remaining risks are fake networks that imitate the hotel or airport name and login pages that ask for personal details. Use cellular data or your own hotspot for banking and work. Turn off automatic joining of open networks.

Should I worry about public USB charging stations?

The risk is low on a current phone, which asks before it allows a data connection over USB. Carry your own charger and cable or a power bank, and tap “Do not allow” or “Charge only” if the prompt appears.

Should employees use personal phones for work?

Many small businesses rely on personal phones. That arrangement is called bring your own device, or BYOD. It works when you set rules in a written policy.

  • Minimum requirements. A passcode, automatic lock, encryption, a supported operating system, and automatic updates.
  • Approved apps. Staff reach company email and files through approved apps, such as Outlook or the Google Workspace apps, and not through whatever mail app came with the phone.
  • Company control of company data. State that the business may remove its data from the phone when the employee leaves or the phone goes missing.
  • Reporting. Require staff to report a lost or stolen phone within hours.
  • Privacy. State what the company can and can’t see on a personal device.
  • Offboarding. Remove company accounts on the employee’s last day.

Businesses that handle patient, card, or financial data should issue company-owned phones to the staff who handle it, or manage the personal ones.

What is mobile device management?

Mobile device management, or MDM, is software that lets a business enforce security settings on phones and tablets, push required apps, and erase company data from a distance. Microsoft Intune comes with Microsoft 365 Business Premium. Google Workspace includes endpoint management. For personal phones, app protection policies let you control and wipe the work apps while leaving personal photos and messages untouched.

What should I do if my phone is lost or stolen?

  1. Use Find My or Find Hub from another device to mark the phone as lost and lock it.
  2. Call your carrier to suspend service and block the SIM.
  3. Change the password for your Apple or Google account, then for email and banking.
  4. Tell your employer or your IT provider so they can remove company data and end active sessions.
  5. Erase the phone from a distance if you do not expect to recover it.
  6. Report the theft to the police, and give them the serial or IMEI number.
  7. Watch for texts or emails that claim your phone was found and ask you to sign in. Thieves send them to capture your account password and unlock the device.
  8. Move your authenticator app and passkeys to the replacement phone, and remove the old device from each account.

Plan for step 8 before you travel. Save backup codes for your important accounts and store them on paper at home.

How do I prepare an old phone for sale or disposal?

Back it up. Sign out of your Apple or Google account. Remove the SIM card and erase the eSIM. Run the factory reset from the settings menu. For a company phone, record the serial number and the date in your asset inventory.

What about travel?

Update the phone before you leave. Confirm that Find My and the theft protections are on. Carry a power bank. Keep the phone in a front pocket or a zipped bag in crowds, and avoid typing your passcode where others can watch. Know your carrier’s number for reporting a lost phone from abroad.

Your next step

Check three settings tonight: the theft protection feature, the SIM lock with your carrier, and lock screen previews. Then ask how many personal phones carry your company’s email. Cerberus Cybersecurity writes mobile device and remote work policies and covers phone threats in our cybersecurity training. See our services or contact us.