Device SecurityUpdated: 2026
Computers, phones, tablets — every device is a potential way in. Learn to lock, protect, and manage your digital equipment day to day.
By the end of this module, you'll be able to…
- Assess the security level of each of your devices
- Apply essential protections to computers and smartphones
- Understand the risks of mixed personal/professional use
- Set up locking, encryption and backups correctly
Every device is a way in
On average we use 3 to 5 connected devices: desktop, laptop, smartphone, tablet, smartwatch. Each one stores data, accesses online accounts, and communicates with the internet. A single compromised device can be enough to expose your entire digital life.
Attackers target the least protected device, not the most important one. It's often the forgotten old phone, the kids' tablet, or the home-office computer that serves as the initial entry point.
In 2022, a Quebec SMB suffered a data breach because an employee used their personal tablet to access work email. The tablet had no passcode and had apps downloaded outside the official store. The attacker had installed spyware through a free game app.
Protecting your computer (Windows/macOS)
Computers are the devices most exposed to malware and ransomware. Basic best practices eliminate the vast majority of common risks.
✓ Best practices — Computer
- Windows: Enable Windows Defender (included and free), keep Windows Update on, enable the built-in firewall, and use a standard user account (not administrator) for daily use.
- macOS: Enable FileVault for disk encryption, verify the firewall is on in System Settings, and only allow apps from the Mac App Store or identified developers.
- Both: Enable automatic locking after 2-5 minutes of inactivity. Set a strong session password. Never leave your computer unattended in public without locking it (Win+L / Cmd+Ctrl+Q).
✗ Common mistakes
- Using an administrator account for all daily tasks — this gives malware extended privileges.
- Disabling automatic updates to "avoid interruptions".
- Sharing your session password with family members.
Protecting your smartphone
Smartphones today hold more sensitive information than most computers: saved passwords, banking details, private conversations, photos, real-time GPS location. Yet their security is often neglected.
✓ Essential smartphone protections
- Strong passcode: Use a 6-digit PIN minimum or an alphanumeric password. Avoid pattern unlocks — too easy to observe.
- Biometrics: Fingerprint or facial recognition is acceptable as a second factor, but not as the only protection.
- Encryption: iOS encrypts automatically. On Android, check that encryption is enabled in Settings > Security.
- Location and remote wipe: Enable "Find My iPhone" or "Find My Device" (Android). If stolen, you can wipe the device remotely.
- Official apps only: Download only from the App Store (iOS) or Google Play (Android). Avoid "sideloading" unverified apps.
Updates and patches — why they're essential
Most successful cyberattacks exploit known vulnerabilities for which a patch already exists. Not updating your devices means leaving a window wide open when a lock is available for free.
According to the Verizon 2023 DBIR report, 60% of breaches exploit vulnerabilities for which a patch had been available for more than 30 days. The average time between a patch's release and its exploitation by attackers dropped from 15 days to under 5 days in 2024.
✓ Good update practice
- Enable automatic updates for the operating system AND for all apps.
- Don't postpone restarts needed to install patches — schedule them during downtime.
- Update your home router's firmware at least once a year.
- Uninstall apps you no longer use — each app is a potential attack surface.
Mobile apps and permissions
A flashlight app that asks for access to your contacts, microphone, and GPS location — that's an obvious red flag. Yet most users accept every permission without reading them.
Mobile permissions give apps direct access to your sensors and data. Unjustified access can be used for surveillance, commercial data collection, or even malicious spying.
✓ Managing permissions
- Apply the principle of least privilege: grant only the permissions essential to the app's function.
- Location: choose "Only while using the app" rather than "Always". Decline if the app doesn't need it.
- Microphone and camera: grant these only to legitimate apps (video calls, camera). Revoke unnecessary access.
- Audit regularly: iOS: Settings > Privacy. Android: Settings > Apps > Permissions.
Antivirus, EDR and local protection
Antivirus software detects and blocks known threats by comparing files against a database of malicious signatures. EDR (Endpoint Detection and Response) tools go further by analyzing suspicious behavior in real time — especially useful in a professional context.
✓ Recommendations by context
- Personal use (Windows): Microsoft Defender (built in) offers solid, free protection. Keep it active — never disable it to install a suspicious app.
- Personal use (macOS): The system is relatively well protected by Gatekeeper and XProtect. A third-party antivirus (free Malwarebytes) can add extra protection.
- Professional use: Require a centrally managed EDR (SentinelOne, CrowdStrike, Microsoft Defender for Endpoint). These tools enable coordinated detection and response.
- Smartphone: Official stores already filter apps. A mobile antivirus adds protection against phishing and malicious links.
✗ Common myths
- "I have a Mac, I'm not at risk" — false. Macs are increasingly targeted as their popularity has grown.
- "My antivirus is enough to protect me from everything" — antivirus is one layer of protection among several, not an absolute guarantee.
Locking, encryption and backup
Three complementary mechanisms form the foundation of device protection: locking prevents unauthorized physical access, encryption makes data unreadable without the key, and backup guarantees recovery in case of loss or ransomware.
✓ The three pillars
- Automatic locking: Set your device to lock after 2 to 5 minutes of inactivity. On a computer, lock manually before stepping away (Win+L / Cmd+Ctrl+Q).
- Disk encryption: Windows: enable BitLocker (Pro/Enterprise) or Device Encryption. macOS: enable FileVault. iOS: automatic if a passcode is set. Android: Settings > Security > Encryption.
- 3-2-1 backup: 3 copies of your data, on 2 different media, with 1 kept offsite (cloud or an external drive stored elsewhere). Test the restore at least once a year.
If a thief takes your unencrypted laptop, they can access all your data by removing the hard drive and connecting it to another computer — even if your session is locked. With encryption enabled, this technique no longer works: the data is unreadable without the decryption password.
Separating personal and professional use
Using the same device for work and leisure creates risk in both directions: a threat from a game or personal site can compromise work data, and conversely, sensitive work data can end up exposed through personal apps.
✓ Separation strategies
- Dedicated devices (ideal): A work computer provided and managed by the employer, a separate personal phone. This physical separation is the most effective.
- Separate user profiles: If only one device is available, create separate user accounts for work and personal use.
- Dedicated browser: Use Firefox or Chrome for personal, Edge for work (or vice versa). Don't share password managers between profiles.
- Email: Never forward work emails to your personal account. This exposes data to uncontrolled third-party servers.
BYOD — risks and precautions
BYOD (Bring Your Own Device) means using your own personal device in a work context. This practice is widespread, especially in SMBs and for remote work, but it creates significant security gray areas.
- Data mixing: Personal and work data coexist on the same device — hard to protect the confidentiality of one without affecting the other.
- Limited employer control: The organization can't enforce its security policies on a personal device.
- Risky personal apps: Apps installed for personal use can access work data stored on the device.
- In case of incident: Who is responsible? The employee or the employer? The legal boundaries are unclear.
✓ If your organization allows BYOD
- Ask for a clear, written BYOD policy before enrolling your device.
- Accept an MDM (Mobile Device Management) profile install only if you understand the implications — it gives your employer the ability to wipe the device remotely.
- Keep your device updated and encrypted — that's your responsibility under BYOD.
- Use the organization's VPN for any access to internal resources.
Security checklist for all devices
Device security isn't a one-time state but an ongoing practice. This lesson summarizes the essential checks to run regularly across all your equipment.
✓ Recommended monthly checks
- All system and app updates are current.
- Antivirus or built-in protection is active and its definitions are recent.
- Automatic backups are working and have been tested.
- Mobile app permissions have been audited.
- No unknown device is connected to your home Wi-Fi network.
- Unused devices are disconnected or reset.
Device security checklist
Simulated example for educational purposes — the brands mentioned are not affiliated with ObjectifCyber.
Assess your main device's security across 12 points.
Module quiz
Test what you've learned with 4 questions.
See also