Keeping Your Devices Safe Updates, Malware, Public Wi-Fi and Lost Devices

Most device security comes down to a handful of habits rather than expensive software. This guide explains what actually protects you, and what is mostly marketing.

Technology & Digital Life

↓
Chapter I

How Devices Get Compromised The Few Ways That Cause Most Problems

Headlines about hacking suggest sophisticated attacks by criminals in hoodies. The reality for most people is far more ordinary. The majority of successful attacks on individuals rely on a small number of simple methods.

The most common is deception. Criminals send emails, texts and messages that look legitimate and persuade people to click a link, open an attachment, enter a password on a fake site or install software. This is known as phishing, and it works because it targets people, not machines. The second is exploiting known flaws in software that has not been updated, which lets malware in without any action from the user. The third is reused or weak passwords, which allow criminals to take over accounts using lists of credentials stolen from other services. A fourth is installing software or apps from unofficial sources, which may carry hidden malware.

Malware is a general term for malicious software. It includes viruses that spread between files, spyware that watches what you do, ransomware that locks your files until you pay and trojans that pretend to be something useful. Modern malware is often designed to be silent, so you may not know that you have it.

The National Cyber Security Centre, part of GCHQ, publishes plain-English advice for individuals, based on the idea that a few basic habits stop the great majority of attacks: keep software updated, use strong, unique passwords and two-step verification, back up your data and be suspicious of unexpected messages.

Most successful attacks do not break into your device. They persuade you to open the door.

· · ·
Chapter II

Updates: Your Best Defence Why They Matter and How to Manage Them

If you do only one thing for your security, install updates. They are the single most effective protection that most people can adopt.

When researchers or criminals find a flaw in software, the maker produces an update to fix it. Once the fix is released, the flaw becomes public knowledge, and criminals use it against people who have not updated. That is why leaving an update for weeks, however inconvenient, leaves you exposed. Switch on automatic updates for your operating system, your browser and your apps, so that you do not have to remember.

Devices also reach the end of their supported life, after which the maker no longer issues security updates. Windows 10, for example, reached the end of its standard support in October 2025. Phones and tablets stop receiving updates after a number of years, which varies by manufacturer. A device that does not receive updates becomes steadily more dangerous to use, especially for banking and email. Check the support dates for your devices, and plan to replace those that are no longer supported, or at least avoid using them for sensitive tasks. Some manufacturers offer extended security updates for a fee.

Do not forget other devices. Routers, smart TVs, printers, cameras and smart home equipment also need updates, and many are neglected. Check them from time to time.

Safe Updating

Only install updates through the device's own settings or the official app store. Never click on a pop-up in a web page that claims that your computer needs an update, or on a link in an unexpected message. These are common ways of delivering malware.

· · ·
Chapter III

Protection Software and Safe Browsing What You Actually Need

The security software industry sells a great deal of protection, and some of it is useful. But the right choice for most people is simpler than advertising suggests.

Modern operating systems come with built-in protection. Windows includes Microsoft Defender, which is well regarded by independent testers and is adequate for most home users. Macs include several layers of built-in protection, and iPhones and iPads have a tightly controlled app system that makes malware rare. Android phones are protected by Google Play Protect, and most malware reaches Android through apps installed from outside the official store. For many people, built-in protection, kept up to date, together with good habits, is enough. Paid security suites may add features such as password managers, identity monitoring and parental controls, which some people find useful, but are not essential.

Be careful with free security tools offered by pop-ups or adverts, and beware of fake virus warnings that claim your device is infected and tell you to call a number or download a program. These are scams. Close the browser and, if necessary, restart your device. If you have called a number or let someone have remote access, change your passwords from a different device and contact your bank.

Browse sensibly. Keep your browser updated, use an ad blocker if you wish, and be suspicious of sites that offer something too good to be true, such as free films, cracked software or prizes. Download programs only from the maker's website or official stores, and check the address carefully.

· · ·
Chapter IV

Public Wi-Fi, VPNs and Travelling Staying Safe Away From Home

Public Wi-Fi in cafés, stations, hotels and airports is convenient, and it carries some risk. The risk is real but often overstated.

Most websites and apps now encrypt their traffic using HTTPS, which means that even on an open network, other users cannot easily read what you send. The padlock symbol in the browser indicates an encrypted connection, although it does not show that the site is trustworthy. The more serious risks on public networks are fake hotspots set up with a name that looks genuine, and the possibility that someone on the same network could attempt to interfere with unprotected traffic. Confirm the exact network name with staff, and avoid doing sensitive tasks, such as banking, on public Wi-Fi if you can. Your phone's mobile data is usually safer.

A virtual private network, or VPN, encrypts your connection to a server run by the VPN provider. It can protect you on untrusted networks, and can hide your internet address from websites. However, it does not make you anonymous, it does not protect you from phishing or malware and it means that you must trust the VPN provider with your traffic. Choose a reputable, independently audited provider, and be wary of free VPNs, some of which make money by selling data. Many people do not need a VPN for everyday use.

Travelling brings additional risks. Keep devices with you and locked, avoid charging from unknown public USB ports, which can be tampered with, in favour of your own charger or a power bank, and be cautious of shoulder surfing when entering passwords.

· · ·
Chapter V

Lost, Stolen and Hacked Devices What to Do When Something Goes Wrong

Sooner or later, many people lose a device or find that an account has been compromised. Preparation reduces the harm, and prompt action limits the damage.

Prepare in advance. Use a screen lock on every device, switch on device encryption, which is on by default on most modern phones and available on computers through tools such as BitLocker and FileVault, and enable the find-my-device feature. Keep backups. With these steps in place, a lost device is an inconvenience rather than a disaster.

If a device is lost or stolen, use the find-my-device service to locate it, lock it and, if necessary, erase it remotely. Report theft to the police and ask your mobile provider to block the SIM and, for stolen phones, the handset. Change passwords for key accounts, especially email and banking, and review active sessions. Tell your bank if you use banking apps.

If you think an account has been hacked, change the password immediately from a device that you trust, using a unique new password, and switch on two-step verification. Check the account's recovery email, phone number and forwarding rules, which attackers often change. Tell your contacts if someone could be sending messages in your name, and watch your bank statements. If you used the same password elsewhere, change those too. If you have been the victim of fraud, contact your bank at once and report it to the police.

Check for Breaches

The free service Have I Been Pwned lets you check whether your email address has appeared in known data breaches. If it has, change the passwords for the affected services and any others where you used the same one.

· · ·
Chapter VI

Building Good Habits A Realistic Routine for Everyday Security

Security is a habit, not a product. A small set of routines, practised regularly, provides far more protection than any tool.

Set up a short monthly check. Confirm that automatic updates are on and that no important updates are waiting. Review your apps and delete those you no longer use. Check your backups. Glance at your accounts for anything unfamiliar, such as unknown devices signed in or unexpected transactions. Run a check on your passwords using a password manager if you have one.

Practise safe habits every day. Pause before clicking links, particularly in messages that create urgency. Look at the sender's address and the web address. Do not open unexpected attachments. Use a separate, strong password for your email and your main accounts. Lock your screen when you leave a device, and do not leave devices unattended in public places.

Teach those around you. Families and small businesses are only as secure as their weakest member. Explain the basics to children and older relatives, agree a way to check unusual requests, and share what you learn about new scams. If you run a small business, the National Cyber Security Centre's guidance and the Cyber Essentials scheme offer a practical framework.

The Five Habits

Update everything. Use strong, unique passwords and two-step verification. Back up what matters. Think before you click. Know what to do if something goes wrong.

· · ·
Subscribe for Full Access