The Security Setup I Walk Through on Every New Phone
My mum called me the week she got her new phone, excited to show it off, and completely unaware that half the settings that actually protect her hadn't been touched since it left the box. That's not unusual. A new phone arrives set up for convenience, not security, and most people start using it straight away without changing a thing, transferring their whole digital life onto a device that's still running its factory defaults. I've got a fixed routine I run through on any new device before it goes into daily use, whether it's mine or a family member's, and it takes about fifteen minutes, done in a specific order because some of these settings are far harder to fix retroactively once the phone's already full of accounts and habits built around it.
Setting a Proper Lock Screen Before Anything Else
The very first thing I do, before signing into a single account, is set a proper lock method. A six-digit passcode is the minimum I'll accept, never four digits and never a pattern swipe, which is far easier for someone to spot over your shoulder. I turn biometric unlock on too, fingerprint or face, because it means the phone gets locked more often in practice rather than left open out of sheer inconvenience. This step matters more than people think, since almost everything else on the phone, banking apps, email, photos, is only as protected as whatever's stopping someone from picking it up and unlocking it.
Turning On Find My Device Immediately
Before I add a single app or account, I make sure Find My Device or Find My iPhone is switched on, tied to the account that'll actually be used going forward. It sounds like an afterthought, but it's dramatically harder to enable retroactively once the phone's already lost or stolen, and it's the difference between a phone that can be tracked, locked, and wiped remotely and one that simply vanishes along with everything on it. I also confirm the SIM has its own PIN set, separate from the lock screen, since a SIM swapped into another device without one is still usable by whoever has it.
Checking Every Automatic Backup Is Actually Running
Once the lock screen and Find My Device are sorted, I go into the backup settings and confirm photos, contacts, and app data are actually being backed up automatically, not just available as an option someone meant to turn on eventually. I've seen too many people lose years of family photos because a new phone's backup toggle sat switched off from day one. This is also the point where I check the account behind that backup has its own strong, unique password and two-factor authentication switched on, since a backup is only as safe as the account holding it.
Going Through App Permissions One by One
New phones ask for a lot of permissions during setup, and most people tap through them without reading what they're agreeing to. I go into the permissions menu directly and check what has access to location, the microphone, contacts, and photos, revoking anything that doesn't have an obvious reason to need it. A flashlight app doesn't need your contacts. A game doesn't need your microphone running in the background. This step alone usually cuts the list of apps with location access in half, and it takes less time than most people expect.
Triggering a Manual Software Update Before Anything Else Loads
New phones often ship with an operating system version that's already a few weeks or months out of date by the time it reaches a shop shelf, sitting there waiting for the buyer to eventually notice an update is available. I go into settings and force a manual check straight away rather than waiting for it to prompt me, because security patches are usually the biggest part of any update, and a phone running its out-of-the-box software is running with known gaps that have likely already been fixed upstream. This is also the point where I turn automatic updates on going forward, so this isn't a one-off fix but something the phone keeps doing on its own without anyone having to remember.
Installing a Password Manager Before Anything Else Gets Signed Into
Rather than signing into each account with whatever password comes to mind, I install NordPass on a new phone before touching email, banking, or social apps, and let it generate a unique password for every account from that point forward. Doing this before signing into anything means every single account on that device starts out with a strong, unique password rather than a reused one carried over out of habit. It's a much easier habit to start clean than to retrofit six months later once dozens of accounts are already set up with the same weak password.
The One Setting I Check Last, Not First
The very last thing I do, once everything else is in place, is check what's actually visible on the lock screen itself: message previews, notification content, and whether the phone stays unlocked longer than it needs to before locking itself again. I set the auto-lock timer to thirty seconds rather than the two or five minutes most phones default to, since a phone that stays unlocked on a table for several minutes after last use is functionally the same as no lock screen at all for that stretch of time. I've written before about the everyday habits that quietly put people at risk, and a lock screen showing full text previews of banking codes or private messages is exactly that kind of quiet risk nobody thinks to check, right up until the wrong person glances at the wrong moment. NCSC has straightforward guidance on securing a new device that's worth a look if you want a second source beyond mine. Fifteen minutes with a new phone, done in this order, closes off most of the obvious ways it could go wrong later, and my free Safety Toolkit has a version of this checklist you can run through on your own device today.
