Key Takeaways
- Outdated software is one of the most common entry points for attackers — updates close those gaps.
- Lock screens, screen timeouts, and encryption are your first line of physical defense.
- Unused apps and old accounts expand your attack surface without you noticing.
- Backing up your data regularly limits the damage if a device is lost or compromised.
- A full device audit takes under 20 minutes and is worth repeating every few months.
Summary
18 items · 10–20 minutes
Why a Device Audit Matters More Than You Think
Most security breaches don't happen through sophisticated hacking — they happen because a setting was left at its default, an update was skipped, or an old app was forgotten. A quick, structured review of your devices can surface these gaps before someone else takes advantage of them.
This checklist covers phones, tablets, and computers. You don't need technical expertise. Work through it one device at a time and make changes as you go. For a broader review that includes your router and Wi-Fi, see the Home Network Audit Checklist.
Software & System Updates
Lock Screen & Physical Security
App Permissions & Installed Software
Browser & Saved Credentials
Backups & Data Protection
What You'll Need to Get Started
No specialist software is required. You'll mainly navigate built-in settings menus on each device. Having your passwords and Apple ID or Google account credentials accessible will speed things up. Once you finish here, consider running the Account Security Audit checklist to strengthen your login credentials across services.
Device Settings App
Used to check OS version, lock screen configuration, encryption status, and app permissions on phones and tablets.
Password Manager
Helps review, organize, and strengthen saved credentials identified during the browser step.
Cloud Backup Service
Used to verify that recent device backups have completed and are accessible for restore.
Common Oversights — and Why They're Risky
Two areas trip up most users: software updates and app permissions. Skipping updates leaves known vulnerabilities unpatched — attackers routinely scan for devices running older software versions. Granting an app access to your location, microphone, or contacts without reviewing it later means that access persists indefinitely, even after you stop using the app.
Physical security is equally underestimated. A device without a lock screen or with a long screen-timeout window can be accessed by anyone who picks it up. Encryption ensures that even if a device is lost or stolen, the data on it isn't immediately readable.
Don't Skip Permissions on Older Apps
Apps you installed years ago may hold permissions granted under older, less restrictive OS defaults. Operating system updates don't automatically revoke previously granted permissions. Make a point of reviewing apps sorted by install date — the oldest ones often have the broadest access.
Finally, browser hygiene deserves attention. Saved passwords in a browser are convenient but only as secure as the browser itself. Reviewing which sites have stored credentials — and removing ones you no longer use — is a fast, high-value step. When evaluating unfamiliar links on any of your devices, the Before You Click checklist provides a quick framework.
A Backup You Haven't Tested Isn't Reliable
Many people assume their backup is working simply because it appears enabled. Backup processes can fail silently — storage quotas fill up, authentication tokens expire, or sync errors go unreported. Confirm the timestamp of your last successful backup and, where practical, verify you can open or restore at least one file from it.
