Amvix

Device security checklists

Practical settings to work through on each device you own, ordered by how much difference they actually make. None of this costs anything.

How to use these

Work down one list at a time, on one device at a time. Most of it is a single pass of twenty minutes per device, after which only the backup and the update habit need ongoing attention. The measures at the top of each list do far more than the ones at the bottom, so stopping halfway still leaves you meaningfully better off. Where a setting is named, the wording differs slightly between versions — the location described is the section to look in rather than an exact path.

What actually moves the needle

Before the per-device lists, the general ranking. These five apply everywhere and outrank any purchasing decision in this category.

Measures ranked by practical effect for a typical household
MeasureWhat it preventsEffort
Automatic updates, everywhereExploitation of vulnerabilities that already have fixes available. Most successful attacks on home devices use known, patched flaws.One-time setup
Multi-factor authentication on emailAn attacker with your password taking over the account that can reset every other account you own.Ten minutes
Unique passwords, stored in a managerOne breach at one company unlocking your other accounts through password reuse.An hour, then ongoing convenience
A backup that is disconnectedRansomware, theft, drive failure and accidental deletion — the only measure that recovers data rather than protecting it.One-time setup, occasional checks
Screen lock on every deviceCasual access to a phone or laptop that is lost, stolen or simply left on a table.Two minutes

The Australian Cyber Security Centre publishes free step-by-step guides for individuals and families covering these same fundamentals, written for people without technical background.

Windows computers

  • Confirm Windows Update is on and the machine has restarted recently enough to apply what it downloaded. Pending updates do nothing until the restart happens.
  • Check that real-time protection is enabled, whether that is the built-in protection or a product you installed. Only one real-time product should be active.
  • Turn on the built-in disk encryption if the edition you have supports it, and record the recovery key somewhere outside the machine.
  • Review the accounts on the device. Remove accounts nobody uses, and use a standard account rather than an administrator account for everyday work.
  • Open the list of installed applications and remove anything you do not recognise installing, particularly browser toolbars and system optimisers.
  • Review browser extensions and remove any you did not add deliberately. Extensions can read every page you visit.
  • Set a scheduled scan for a time the machine is on but idle, weekly or fortnightly.
  • Check that the firewall is on for both private and public networks.
  • Set up File History or another backup to an external drive, and disconnect that drive when it is not running.

Mac computers

  • Turn on automatic updates, including the separate option for security responses and system files.
  • Enable FileVault so the disk is encrypted, and store the recovery key away from the computer.
  • Check the firewall setting, which is not always on by default.
  • Review which applications have been granted Full Disk Access, Screen Recording and Accessibility permissions, and revoke anything you do not recognise. These permissions are powerful and rarely reviewed after they are granted.
  • Set the app installation policy to allow only the App Store and identified developers.
  • Check the login items list and remove anything unfamiliar that starts automatically.
  • Review browser extensions, as on Windows.
  • Set up Time Machine to an external drive, and keep that drive disconnected between backups.

Android phones and tablets

  • Check that system updates and Google Play system updates are both current. Update availability depends on the manufacturer and the age of the device.
  • Confirm Play Protect is on.
  • Review app permissions, particularly location, microphone, camera, contacts and SMS. Remove permissions an app does not need for its stated function.
  • Check which apps hold Accessibility permissions or the ability to display over other apps. Both are legitimate for some tools and heavily abused by malicious ones.
  • Uninstall apps you no longer use. Unused apps still receive permissions and still run in the background.
  • Avoid installing applications from outside the official store unless you have a specific reason and know the source.
  • Set a screen lock with a PIN of at least six digits, or a passphrase.
  • Turn on the find-my-device feature and confirm it works before you need it.
  • Check that photos and documents are backing up somewhere.

An Android device that no longer receives security updates from its manufacturer is the one case where age matters directly. Manufacturers publish support periods; once that period ends, no security app closes the gap.

iPhones and iPads

  • Turn on automatic updates, including Rapid Security Responses.
  • Set a six-digit or alphanumeric passcode rather than four digits.
  • Review app permissions in the privacy settings, especially location, photos and microphone, and set location access to "while using" wherever the app still works that way.
  • Turn off lock-screen access to features you do not want available without unlocking, such as the notification preview contents.
  • Check that Find My is on.
  • Review which accounts are signed in on the device, and enable two-factor authentication on the Apple account itself.
  • Confirm iCloud Backup or a computer backup is running.

Because iOS prevents apps from inspecting other apps or the file system, a security product on an iPhone provides web filtering, breach monitoring and network features rather than scanning. That is a platform constraint, described further on the page about how these products work.

Home router

The router is the device most often skipped, and it is the one that every other device connects through.

  • Change the administration password from the default. The default for most models is published online.
  • Check for firmware updates, and turn on automatic firmware updates if the model supports them.
  • Use WPA3 if available, or WPA2 if not, and set a long Wi-Fi passphrase.
  • Turn off remote administration from the internet unless you specifically need it.
  • Turn off WPS, the push-button pairing feature, which weakens the passphrase protection.
  • Set up a guest network for visitors and for smart-home devices, keeping them separate from computers and phones.
  • If the router was supplied years ago by an internet provider and no longer receives firmware updates, ask about a replacement.

Shared and family devices

A device used by several people needs a different approach, because the security of the device becomes the security of whoever is least cautious using it.

  • Give each person their own account rather than sharing one. It separates files, browser sessions and saved logins.
  • Keep administrator rights on one account, used deliberately when something needs installing.
  • Agree on what gets installed and where software comes from, rather than relying on individual judgement in the moment.
  • For children's devices, the eSafety Commissioner publishes age-specific guidance covering device settings, parental controls and how to respond to online harm.
  • Make sure more than one person knows how to reach the backups and the password manager, in case the person who set them up is unavailable.

The backup rule worth following

A widely used guideline is three copies of anything you care about, on two different kinds of storage, with one copy kept away from the others. For a household that usually means the working copy on the device, an automatic backup to an external drive, and a cloud copy.

The detail that matters most is disconnection. Ransomware encrypts whatever it can reach, and a permanently attached backup drive is reachable. A drive that is plugged in for the backup and unplugged afterwards is not. The second detail is restoring: a backup nobody has ever restored from is an assumption rather than a backup. Restoring a single file occasionally is enough to confirm the process works.

Related reading