DEVICE SECURITY CyberArtical Editorial Team

The personal device checklist worth doing once, properly

Two people working at a laptop in a room lit by blue and purple neon light

Most device security advice is a long list of habits, which is why almost nobody follows it. This is the opposite: a set of things you configure once and then largely forget, because they run without you. That is deliberate. CISA’s own patching instruction is to remove yourself from the loop entirely, so that updates install as soon as they are available rather than when you next remember.

The instructions behind each item

  • CISA: ‘Turn on automatic updates’ so devices ‘install updates without any input from us as soon as the update is available.’
  • FTC: ‘Use at least a 6-digit passcode’, with the phone set to lock when not in use.
  • CISA: Windows — turn on device encryption and ‘Back up your BitLocker recovery key’; macOS — ‘Protect data on your Mac with FileVault’.
  • CISA: ‘Use a standard user account for day-to-day tasks to make it more difficult for threat actors to steal your data.’
  • CISA: ‘Avoid leaving the external drive connected when not actively backing up your data.’

For anyone who has never opened these settings

Anyone with a phone and a laptop who has never deliberately gone through their settings, and does not intend to make a hobby of it.

It is not written for people who believe they are being targeted by a sophisticated adversary. That situation has different advice, and CISA is careful about the threshold — it scopes Lockdown Mode on macOS and iOS to people who ‘believe you are being personally targeted by a sophisticated threat actor’, noting it disables device features. It is not a general-population setting, and articles that recommend it to everyone are misreading the source.

The settings, in the order to change them

  1. Turn on automatic updates for the operating system on every device, and for apps where the option exists.
  2. Set a passcode of at least six digits on your phone, and set the screen to lock automatically after a short idle period.
  3. Turn on disk encryption on your computer: BitLocker on Windows, FileVault on macOS. On Windows, back up the recovery key somewhere separate from the machine, as CISA specifies.
  4. Create a standard user account on your computer and use it for everyday work, keeping the administrator account for installing software.
  5. Enable the built-in find, lock and erase feature on your phone. The FTC’s point is that it is already part of the operating system and only helps if it was switched on beforehand.
  6. Set up a backup — cloud, or an external drive that you disconnect and store safely between backups.
  7. Go through app permissions and switch off what an app does not need. CISA’s instruction is to manage permissions specifically to reduce what third parties can reach.
  8. Install a password manager, and give your email account a long unique password and the strongest second factor it offers.

The two that must be on beforehand

Find, lock and erase is the first. It is a pre-loss configuration step masquerading as a post-loss action — the FTC notes the capability is built into mobile operating systems, but nothing you do after the phone is gone will enable it retroactively.

Backups are the second. The FTC ties them directly to loss: back up regularly so that if you lose the phone, you still have your information. That is also what makes remote-erasing a stolen device a decision you can afford to take quickly rather than agonise over.

Both are worth checking today rather than adding to a list, because both are worthless the moment you need them if they were not already running.

When to run through it again

When you get a new device, when you change your phone number, and when a service you use announces a breach. Otherwise, a quick look twice a year is enough: confirm automatic updates are still on, that the backup has actually run recently, and that permissions have not accumulated with new apps.

Explicitly do not add a password rotation schedule. NIST prohibits verifiers from requiring periodic changes, and the reasoning applies to you as much as to them: forced rotation pushes people towards weaker passwords and predictable variations.

And restore something from your backup once, deliberately. An untested backup is a belief.

What this list does not cover

It does not make you phishing-resistant. NIST states that passwords are not phishing-resistant, and a fully patched, encrypted, backed-up laptop will still show you a convincing fake login page. The control for that is a passkey or security key on your important accounts, which CISA identifies as the only widely available phishing-resistant authentication.

It does not cover your home network, which is a separate set of settings on the router — encryption standard, unique admin credentials, WPS disabled, guest Wi-Fi for smart devices.

And it does not cover what happens after a loss becomes fraud. If a stolen device leads to identity theft, IdentityTheft.gov produces a personalised recovery plan; device intrusion and spyware are reportable to the FBI at IC3.gov.

Sources: CISA — update software · CISA — how to protect data stored on your devices · FTC — how to protect your phone from hackers · CISA — best practices against tracking technologies and spyware · NIST SP 800-63B-4, Digital Identity Guidelines

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from CISA, the FTC and NIST. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories