Check the device lock
Start with the control that protects the device when someone has physical access to it.
Your phone, tablet or computer can provide access to email, banking, messaging, recovery methods, files and personal information. Device security is therefore more than installing updates. Check the device itself, the software on it, the permissions it has granted and the accounts connected to it. When something unusual happens, verify it through an independent official channel before you act.
Device security is a chain of controls. A strong screen lock, current software, trusted applications, sensible permissions, protected accounts and a prepared lost-device response work together.
The goal is not to make every device impossible to misuse. The goal is to reduce unnecessary access, recognize warning signs early and know what to verify when something changes.
Work through the checks when setting up a device, reviewing an existing phone or computer, installing important software or responding to something unusual.
Start with the control that protects the device when someone has physical access to it.
A device that is not maintained can remain exposed to known security weaknesses.
The name and icon of an application are not proof that it is genuine.
An application should not receive sensitive access simply because it asks for it.
Your device may be the gateway into many other services.
The best time to prepare for a lost or stolen phone is before it happens.
A device problem can create the perfect conditions for a fake support scam.
You do not need to inspect every setting at once. Start with the device functions and accounts that could cause the greatest harm if someone gained control.
Ask what access this provides, whether you still need it and what official control you would use if the device were lost or compromised.
Ask what access this provides, whether you still need it and what official control you would use if the device were lost or compromised.
Ask what access this provides, whether you still need it and what official control you would use if the device were lost or compromised.
Ask what access this provides, whether you still need it and what official control you would use if the device were lost or compromised.
Ask what access this provides, whether you still need it and what official control you would use if the device were lost or compromised.
Ask what access this provides, whether you still need it and what official control you would use if the device were lost or compromised.
Ask what access this provides, whether you still need it and what official control you would use if the device were lost or compromised.
Ask what access this provides, whether you still need it and what official control you would use if the device were lost or compromised.
Ask what access this provides, whether you still need it and what official control you would use if the device were lost or compromised.
Ask what access this provides, whether you still need it and what official control you would use if the device were lost or compromised.
The safest answer to an unexpected installation request is not to install first and investigate later.
Compare the publisher or developer with the organisation's official website and the official app-store listing. A copied name or logo is not enough.
Prefer official app stores or the developer's official distribution channel. Be cautious with APKs and installation files sent through messages, social media, email or unknown websites.
Identify the actual task the application is supposed to perform. If someone creates urgency but cannot explain the legitimate purpose, pause and verify independently.
Review permissions and ask whether they make sense for the application's purpose. A simple utility should not automatically receive unrestricted access to unrelated sensitive information.
A device-security decision often happens when someone is creating pressure. The familiar logo, urgent warning or confident caller is not the evidence you need.
Someone sends you an APK and says your bank has released a security update that must be installed immediately. Do not install it simply because the file has the bank's name or logo. Open the bank's official website or app store listing yourself and check whether the update actually exists and how the bank distributes it.
Your phone unexpectedly loses service and you also begin receiving account-security alerts you did not request. The loss of service could have an ordinary network explanation, but the combination deserves investigation. Contact your mobile provider through its official channel and check important accounts through their official apps or websites.
A caller says your phone has been compromised and asks you to read out the verification code that just arrived. Do not disclose the code. End the call and contact the relevant service through a channel you find independently.
Someone contacts you claiming to have found your stolen phone and asks for your password or verification code so they can unlock it for you. Treat the request as unverified. Use the manufacturer's official device-finding tools and contact your network provider or relevant service directly.
A simple utility application asks for access to your messages, contacts, microphone and files. The permissions may not make sense for the function you need. Check the app's publisher and official documentation, then review the permissions through your device settings before deciding whether to install or keep it.
You open a familiar-looking banking or payment page and the browser displays a security warning. Do not dismiss the warning just because the page uses familiar branding. Close the page and open the organisation's official website or application yourself.
An unexpected caller says they can fix your banking or account problem if you install a remote-access application. Do not grant remote control simply because the caller sounds professional. Verify the support request independently through the organisation's official channels.
You discover that an old phone you no longer use may still have access to your email or cloud account. Open the service's official security settings, review signed-in devices or sessions and remove access that is no longer needed.
After installing an unexpected APK, you notice unusual permissions, pop-ups or account activity. Do not assume that deleting the app alone has solved the problem. Preserve useful evidence, secure affected accounts, review sessions and contact the relevant service through official channels.
1. LOCK: Is the device protected against unauthorized physical access?
2. SOURCE: Did the software come from an official or independently verified source?
3. PERMISSION: Does the access requested by the application make sense for its purpose?
4. ACCOUNT: Which important accounts and recovery methods are connected to this device?
5. SESSION: Are there unfamiliar signed-in devices, applications or account sessions?
6. NETWORK: Is a website, network or support request asking you to install or approve something unexpected?
7. RESPONSE: Do you know what you will do if the device is lost, stolen or compromised?
A suspicious app, unexpected account alert or lost phone should not automatically lead to panic. Start by identifying what happened and use official controls.
Identify the application, preserve useful evidence if an incident may have occurred, review its permissions and account activity, then use trusted procedures to remove it or seek official support. Do not assume deletion alone has undone every possible effect.
Open the affected service's official app or website directly. Review recent activity, active sessions and recovery settings. Change exposed credentials where appropriate and do not use contact details supplied by a suspected attacker.
Check whether there is a normal network explanation, but if the loss is unexplained or appears alongside unusual account activity, contact your mobile provider through an official channel and review important accounts.
Use the manufacturer's official location or remote-lock tools, contact the network provider, secure important accounts and review financial activity. Preserve relevant information and report the incident through appropriate channels.
A lost phone, suspicious application or account problem can make you vulnerable to someone who claims to be helping. They may ask for a password, verification code, recovery phrase, payment or remote access.
Stop and verify the supposed helper separately. Open the organisation's official website or app yourself, use a phone number already known to you, or use another independently published contact channel.
The person contacting you is not the proof. The independently verified channel is what you use to establish whether the request is genuine.
Use the manufacturer's official device-finding or remote-lock service where available.
Contact your mobile network provider through an official channel and follow its procedure for a lost or stolen SIM or phone.
Prioritise accounts that can reset other accounts, especially your primary email and other critical recovery routes.
Review banking and payment accounts through their official applications or websites and report suspicious transactions through official channels.
Keep relevant messages, alerts, account references and other useful records before deleting or changing them unnecessarily.
Continue checking affected accounts and recovery methods after the immediate response is complete.
"The logo looks right." A copied logo does not establish the identity of an application or support account.
"They sent me the update." An unexpected APK or installation file should be independently verified before use.
"The code arrived on my phone, so I can read it out."Verification codes are security controls. Do not disclose them to unexpected callers or messages.
"I deleted the suspicious app, so I am safe."If compromise is possible, review accounts, sessions, permissions and credentials as well.
"I lost network service, so it is definitely a SIM swap."There are ordinary explanations for service loss. Investigate the wider context rather than assuming a cause.
"Support contacted me, so they must be legitimate."Verify support through a channel you find independently.
Confirm the device lock and automatic screen-lock settings.
Check operating-system and important app updates through official sources.
Review unfamiliar, unnecessary or unofficial applications.
Remove unnecessary sensitive access where appropriate.
Check important signed-in accounts, sessions and recovery routes.
Know how to respond if the device is lost, stolen or compromised.
Protect the physical device. Keep its software current. Verify what you install. Review what applications can access. Check the accounts connected to the device. Prepare for loss or compromise. Then repeat the review.
The objective is not to inspect every setting every day. It is to make device security a normal part of how you protect your digital life.
Do not trust an application because it looks familiar, a caller because they sound convincing, or an installation request because it is urgent. Check the source, purpose, permissions and official channel before giving software or people access to your device.
VERIFY BEFORE YOU TRUST.