The Cybersecurity Course · Episode 8
Read time ~8 min · No prior knowledge

Phone
security

Your phone is now your most important computer: it carries your email, your e-ID, your payment cards and ten years of photos — and it goes everywhere with you, ready to be lost or stolen. Here are the basics that make it hard to get into, the truth about Android versus iOS, and an exact action plan for the day it disappears.

Contents
  1. The basics: screen lock, permissions, sideloading
  2. The DMA conflict: sideloading comes to iPhone
  3. Android vs iOS — and the counterintuitive phishing result
  4. Updates, remote features and radio risks
  5. If your phone is stolen — step by step
  6. Sources

The basics: screen lock, permissions, sideloading

The screen lock

Your phone carries your email, your e-ID and your photos — the screen lock is the door to all of it. Use biometrics (fingerprint/face) for everyday use and a PIN of at least six digits as backup. Not your birth year, not 123456. Important: set the screen to lock immediately, not after five minutes — and shield your PIN from curious eyes in public; thieves "shoulder surf" the code before taking the phone, because the code is often enough to change your passwords.

App permissions

Review once a quarter: Settings → Privacy/Permissions. Does the flashlight need your location? Does the game need the microphone? Revoke anything that isn't obvious — and choose "only while using the app" for location. Both iOS and Android now show when the microphone and camera are active.

Sideloading

Installing apps outside official stores (sideloading) bypasses the platform's review and is by far the most common route for mobile malware on Android. "Modded" apps, cheats and paid apps for free — the same trojan pattern as in episode 6. Ground rule for most people: stick to the App Store and Play Store.

The DMA conflict: sideloading comes to iPhone

The EU's Digital Markets Act has forced Apple to open the iPhone in the EU to alternative app stores and installation outside the App Store — something Apple has loudly protested on security grounds, while critics note the resistance is also about App Store revenue. The truth, as usual, sits in between: competition is good, but the review process in official stores does have protective value.

For you as a user, nothing changes in practice: nobody forces you to sideload. Keep using official sources, be extra sceptical of sites urging you to "install our app directly", and know that the same advice now applies on both platforms.

Android vs iOS — and the counterintuitive phishing result

The eternal question. Short version: both are secure when managed well. iOS has a more tightly controlled app environment; Android offers more flexibility and therefore more opportunity to make unsafe choices. In practice, the difference comes down to updates (next section) and your own habits.

And now the counterintuitive part: mobile security firms like Lookout have repeatedly found in their threat reports that iOS users are exposed to and fall for phishing at least as much — often more — than Android users. A likely explanation: the feeling that "iPhone is safe" lowers the guard, and phishing doesn't care about operating systems. The platform protects against malware — not against persuasion (episode 4).

Updates, remote features and radio risks

The update schedule decides your phone's lifespan

A phone without security updates is the episode 5 problem in pocket format. Apple updates iPhones for a long time; on the Android side, Google publishes monthly security bulletins but the manufacturer decides whether they reach your model — Google Pixel and Samsung now promise up to seven years of updates (Samsung's per-model list), while cheaper brands may go silent after two. Check your model's status — and factor the update promise into your next purchase.

Remote features — enable in advance

Both Apple's Find My and Google's Find My Device can locate, lock and wipe the phone remotely — but only if the feature was switched on before it disappeared. Do it now; it takes a minute.

Bluetooth and WiFi

Turn off automatic connection to open WiFi networks, and remember your phone calls out for known networks wherever it goes. Bluetooth can stay on for everyday use — but never accept unexpected pairing requests, and update (again, episode 5): serious Bluetooth vulnerabilities surface at regular intervals. More on public networks in episode 11.

If your phone is stolen — step by step

  1. Lock and track immediately from another device via iCloud or Find My Device. Enable "lost mode" with a contact number.
  2. Block the SIM card with your carrier so the thief can't receive your SMS codes (episode 3 — the SIM is a factor).
  3. Change your email password first, then bank and social media — from a clean device.
  4. File a police report with the phone's IMEI number (on the box or receipt; your carrier has it too). The report is required for insurance.
  5. Wipe remotely once hope of recovery is gone. With the remote feature enabled, the phone also stays locked to your account — worthless to resell.
Next time What happens to your photos and documents if the device disappears — or if ransomware encrypts everything? Episode 9 is about backups and encryption: the 3-2-1 rule, why cloud sync isn't backup, and the settings that save you.

Sources

Want to dig deeper? These are the sources behind this episode.

  1. European Commission — Digital Markets Act — the regulation opening iOS in the EU.
  2. Lookout — lookout.com — mobile threat reports, incl. phishing exposure per platform.
  3. Google — Android Security Bulletins — monthly security updates.
  4. Samsung — Security update scope — update promise per model.
  5. Apple — Find My — remote lock and wipe.
  6. Google — Find My Device — remote lock and wipe on Android.
  7. CISA — Mobile Communications Best Practice Guidance — government mobile security advice.
  8. Swedish Police — If you're the victim of crime — reporting theft.
  9. Apple — Apple Platform Security — the security model behind iOS.
Next episode

Episode 9 — Backups & encryption

The 3-2-1 rule, why cloud sync isn't backup, and what ransomware means without copies.