The Security Checklist I Run Through Every Time I Set Up a New Device
Every time I bring a new phone, laptop, or tablet into my life, I go through the same sequence before I let myself actually use it for anything, and I don't let convenience or excitement about a new device shortcut it. None of these steps take long individually, but skipping even one is exactly how devices end up compromised in their first few weeks, back when everything on them still looks new, nothing's backed up yet, and nobody's paying close attention. This is the order I actually follow, every single time.
The First Thing I Do Is Update Everything Before I Touch a Single App
A brand new device can still be running software that's weeks or months out of date by the time it reaches me, since it was likely sitting in a warehouse, a delivery van, or a shop shelf before I bought it. I go straight to the settings menu and run every update available, operating system, firmware, and any pre-installed apps I'm actually going to keep, before I sign into a single account or download anything new. I do this even when the device claims to already be up to date, since I've had more than one new phone quietly have a second update waiting once the first one finished installing. Known vulnerabilities in outdated software are one of the easiest ways in, and there's no reason to carry that risk forward from day one just because I was excited to start using the thing.

Every New Device Gets Its Own Unique Password From Day One
I don't carry old passwords over to a new device, and I don't reuse a password I've already got sitting on something else either, no matter how strong that old password is. Every account I sign into on that device, starting with the device's own lock screen or user account, gets a fresh password generated by my password manager rather than something I type from memory. It sounds like more effort than reusing something I already know, but the manager fills it in for me anyway once it's set up, so the actual day-to-day friction is close to zero. What I get back in exchange is that a breach on one account, or one device, never quietly becomes a breach on everything else I own.
Two-Factor Authentication Goes On Before the Device Ever Leaves My Hands
Setting up two-factor authentication is one of the last things a lot of people get around to, if they get around to it at all, but I do it before the device is even fully set up for anything else. Every account that supports an authenticator app over a text message code gets the authenticator app instead, and I add the new device itself to whatever account recovery method I'm already using so I don't end up locked out of my own accounts later. It's a five-minute job while I'm already sitting in the settings menu, and it's a far worse job to try and do retroactively once something's already gone wrong.
I Turn On Full-Disk Encryption Even Though It's Rarely the Default
Most phones ship with encryption switched on by default now, but laptops and some tablets often still don't, and even when it's available it's usually a single toggle buried a few menus deep rather than something turned on automatically for me. I check it on every new device regardless of what I'd expect the default to be, because I've been wrong about that assumption before. If the device is ever lost or stolen, encryption is the entire difference between someone getting a locked box they genuinely can't do anything useful with, and someone getting a device they can plug straight into a computer and pull every file, photo, and saved login off in a few minutes.
Find My Device Gets Switched On Before I Ever Need It
I can't set this up after the device is already missing, so I do it the same day it arrives instead, while I still have it in my hands to test with. Every device I own gets added to whatever remote find, lock, and wipe service its platform offers, and I actually confirm the location and remote wipe functions work rather than assuming they do. It's not something I think about again once it's done, right up until the one time a phone goes missing on a train or gets left in a taxi, and it's the only thing standing between me and someone else having full access to everything on it.
I Go Through Every App's Permissions Before I Trust It With Anything
The last step is going through whatever apps came pre-installed on the device and removing the ones I'm never going to use, since bloatware sitting there untouched is still software that can carry its own vulnerabilities even if I never open it. For everything I do keep, and everything I install afterward, I check what permissions it's actually asking for against what it plausibly needs to do its job. A flashlight app asking for access to my contacts list or my precise location gets uninstalled on the spot, no matter how convenient or well-reviewed it looked in the app store. The one app I do install deliberately, before almost anything else gets the chance to land on the device first, is the antivirus app I trust on my own devices so it's already watching by the time anything risky has a shot at getting through.
None of these steps are complicated on their own, they just have to happen in the right order and before the device has any of my real information sitting on it, not after. Most of it takes less time overall than setting up the wallpaper and home screen the way I actually like them. Once a device has been running for a while, this setup checklist stops applying and becomes the same account check-in I already run every few months instead, checking what's still logged in, what's changed, and what needs fixing. My free Safety Toolkit covers the account-level basics that sit underneath all of this, and NCSC has more detailed guidance if you want to go further than my own checklist covers.
