DEVICE SECURITY CyberArtical Editorial Team

A storage checklist for company phones and tablets

Two Lexar Professional 64GB memory cards still in their retail packaging

A company phone holds mail, documents, chat history and saved credentials, and it spends its life in coat pockets and taxis. The good news is that the encryption is already there and mostly free: on modern handsets, setting a screen lock is what switches it on. The rest of this list is about the parts that are not automatic — the passcode, the backups, and the ability to erase a device you no longer have.

The baseline this checklist enforces

  • CISA: on iOS, setting a passcode is what enables encryption; on newer Android, ‘the device will be encrypted automatically once you set a screen lock’.
  • FTC: ‘Set your phone to lock when you’re not using it and create a PIN or passcode to unlock it. Use at least a 6-digit passcode.’
  • FTC: mobile operating systems include a find, lock and erase capability — it must be switched on before the device is lost.
  • CISA: ‘Avoid leaving the external drive connected when not actively backing up your data.’
  • CISA: ‘Manage your application permissions to minimize the amount of data third parties might be able to access on your device.’

Written for whoever hands out the phones

Whoever hands out the phones in a small organisation, and whoever is carrying one. It assumes no mobile device management platform and no IT department — just a handful of handsets and someone responsible for them.

If you do have management software, the same list is worth reading as the set of settings to confirm are actually enforced, rather than merely recommended in a policy document nobody has opened.

What to set on every device you issue

  1. Set a passcode of at least six digits on every device, per the FTC. Where an alphanumeric passcode is available, use it — CISA describes the system encryption credential as one that should be long, random and unique.
  2. Confirm encryption is actually on. On iOS the passcode enables it; on newer Android it follows automatically from setting a screen lock. Check rather than assume, particularly on older handsets.
  3. Set the screen to lock automatically after a short idle period. Encryption at rest protects a locked device, not one left open on a table.
  4. Turn on automatic operating system updates. The FTC is direct: updates ‘often include critical patches and protections against security threats. Set your phone to update automatically.’
  5. Enable the built-in find, lock and erase feature on each device, and confirm somebody knows the account it reports to.
  6. Review app permissions and remove what is not needed. CISA’s instruction is to manage them specifically to reduce what third parties can reach on the device.
  7. Set up a regular backup, so that erasing a lost handset remotely is a decision you can make without losing work.
  8. Record which devices exist, who holds each, and how to reach the account that can erase it — before you need that information urgently.

Backups that survive the handset

The FTC ties backups directly to loss: back up regularly to the cloud or a computer, so that ‘if you lose your phone, you’ll still have access to your personal information.’

If you back up to an external drive, CISA adds the part that matters for a business: do not leave the drive connected when you are not actively backing up, and store it somewhere safe. A drive permanently attached to a machine is available to anything that reaches that machine.

The test of a backup is a restore. Restore one device from its backup occasionally, deliberately, at a time you choose. A backup nobody has ever restored is an assumption, not a control.

How often to go through this

Every time a device is issued or reassigned, which is the moment when settings are actually changeable and someone is paying attention.

Then a light review roughly twice a year: confirm automatic updates are still on, that the find-and-erase feature still points at an account you control, and that permissions have not crept back with newly installed apps.

Do not build a passcode rotation schedule into this. NIST prohibits verifiers from requiring periodic password changes, on the evidence that forced rotation drives people towards weaker and more predictable choices. Change a passcode when a device changes hands or when there is reason to think it has been observed.

What device settings cannot do for you

They do not protect data that has already been copied elsewhere — into a personal cloud account, a messaging app, or a note synced to someone’s own device. That is an account and policy question, not a storage setting.

They do not stop a phishing message reaching the person holding the phone. NIST notes that passwords are not phishing-resistant, and the strongest handset in the world will happily display a convincing fake login page.

And if a lost device leads to identity theft, the recovery route is IdentityTheft.gov, which produces a personalised plan and pre-filled letters. Fraud that follows a device compromise is reportable to the FTC at ReportFraud.ftc.gov, and device intrusion or spyware to the FBI at IC3.gov.

Sources: CISA — how to protect data stored on your devices · FTC — how to protect your phone from hackers · CISA — best practices against tracking technologies and spyware · FTC IdentityTheft.gov · NIST SP 800-63B-4, Digital Identity Guidelines

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from CISA, the FTC and NIST. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories