| |
1. Keep the operating system and applications up to date
|
|
Updates fix vulnerabilities that can be exploited to compromise the device or install malware. Enable automatic updates whenever possible and do not delay the installation of security updates.
|
|
2. Protect access to your device and accounts
|
|
Start with the device itself: use a strong PIN or password, complemented by biometric authentication. For the accounts and services you use, enable multi-factor authentication (MFA), preferably using authenticator applications rather than codes sent by SMS. Whenever the service supports them, adopt passkeys, a more secure, phishing-resistant authentication method that removes the need for a password.
|
|
3. Install applications only from official app stores
|
|
Download applications exclusively from the App Store or Google Play. Official stores significantly reduce the risk, although they do not eliminate it entirely, so you should always check the developer, reviews and requested permissions. Avoid installing unnecessary applications and remove those you no longer use. Every application you remove means one less potential attack surface.
|
|
4. Review application permissions regularly
|
|
Many applications request access to features they do not need. Regularly review the permissions granted for location, camera, microphone, contacts and files, allowing only the access that is strictly necessary.
|
|
5. Be wary of unexpected messages, calls and QR codes
|
|
Phishing attacks now extend to SMS messages (smishing), telephone calls (vishing), messaging applications and QR codes (quishing). Before clicking a link or providing personal information, always verify the authenticity of the request through the organisation’s official channels, never through the contact details provided in the message itself.
|
|
6. Take extra care when using public Wi-Fi networks
|
|
Public Wi-Fi networks can be exploited by attackers, particularly through fraudulent access points designed to imitate legitimate networks. Disable automatic connections to open networks, confirm that the websites you visit use HTTPS and, for sensitive activities such as online banking, use mobile data or a trusted VPN instead.
|
|
7. Enable location, remote locking and remote data erasure
|
|
These features allow you to locate the device, block unauthorised access and erase stored information in the event of loss or theft. Make sure they are enabled before you need them, because after an incident it may be too late. Storage encryption, which is enabled by default on modern devices, provides an additional layer of protection.
|
|
8. Back up your data regularly
|
|
Theft, device failure or a cyberattack can result in the loss of information. Keep automatic backups enabled and up to date, and regularly check that you are able to restore them. A backup that has never been tested may prove useless when you need it most.
|
|
9. Protect the accounts linked to your smartphone
|
|
The accounts connected to your smartphone, including email, cloud services and social media, are often the gateway to all your other services. Use a different password for each service, ideally managed through a password manager, review authorised devices and monitor suspicious activity, particularly on your main email account, which can be used to recover access to almost everything else.
|
|
10. Remain vigilant and informed
|
|
Technology evolves rapidly, but the human factor remains one of the main vulnerabilities. Developing a critical mindset, verifying the identity of the sender and following the recommendations of cybersecurity authorities are among the most effective ways to reduce risk.
|
|
|
There is no single solution for protecting a smartphone: security results from a combination of technology, good practices and informed users. By adopting these recommendations, you will significantly reduce the risk of fraud, identity theft and the compromise of personal or professional information.
If you suspect that you have been the victim of an incident, act quickly: change your passwords from a secure device, contact your bank if financial information may be at risk and report the incident to the relevant authorities, such as Portugal’s National Cybersecurity Centre (CNCS), or through the electronic reporting services provided by the PSP or PJ.
A strong cybersecurity culture is just as important as the best technological solutions, because prevention remains the first line of defence.
Discover the Devoteam Cyber Trust newsletters here: https://www.integrity.pt/newsletters.html
|
|
|
|