Device & Wi-Fi security basics
Simple steps to keep the computers, phones, and networks your team uses every day secure against common threats.
- Difficulty
- Beginner
The devices your team uses every day — laptops, phones, tablets — are access points to everything your business runs on. A compromised device can expose passwords, email, files, and access to every system the device is connected to.
The good news: basic device security doesn't require any technical expertise.
Quick summary
Keep operating systems and software up to date. Use a PIN, password, or biometric lock on every device. Check that disk encryption is on — it usually is on a modern device, but not always. Be careful on public Wi-Fi. Don't give others access to your work devices. And know how to wipe a device remotely if it is lost or stolen.
Keep your operating system and apps up to date
Software updates fix security vulnerabilities. When attackers find a flaw in Windows, macOS, iOS, or Android, the makers release a patch quickly — but only devices that install the update are protected.
Enable automatic updates:
- Mac: System Settings → General → Software Update, click the info button next to Automatic Updates, then turn on "Install macOS updates" and "Install Security Responses and system files"
- Windows: Start → Settings → Windows Update, then turn on getting updates as soon as they are available
- iPhone/iPad: Settings → General → Software Update → Automatic Updates, then turn on "Automatically Install"
- Android: look for system updates in Settings (the exact path varies by manufacturer — searching Settings for "update" is the quickest way to find it)
Lock your devices with a PIN, password, or biometrics
Every device should require authentication to unlock. This prevents someone who picks up your unlocked laptop from instantly accessing everything.
- Use Face ID, Touch ID, or a fingerprint on your phone, backed by a passcode. Apple's own guidance is that the most secure passcode choices are a custom alphanumeric or custom numeric code, so go longer than a short PIN if you can
- Use a screen lock on your laptop with a short timeout: five minutes or less. On iPhone, the equivalent setting is Settings → Display & Brightness → Auto-Lock
- Lock manually whenever you step away from your desk (Mac:
Cmd + Control + Q; Windows:Win + L)
Enable full-disk encryption
Full-disk encryption means that if someone takes your hard drive out of your laptop, they cannot read any of the data without your login password. Most modern devices encrypt storage, but it is worth checking rather than assuming:
- Mac: On a Mac with Apple silicon or a T2 security chip, your data is encrypted automatically. Turning FileVault on adds a layer by stopping anyone from getting at that data without your login password. Check in System Settings → Privacy & Security → FileVault.
- Windows: Device Encryption is available on a wide range of devices including Windows Home, and it is turned on when you set the device up with a Microsoft or work account — but not if you use a local account. Check in Settings → Privacy & security → Device encryption. BitLocker Drive Encryption is the version on Windows Pro, Enterprise, and Education.
- iPhone/iPad: Setting a passcode turns on data protection, which encrypts your data with 256-bit AES encryption.
- Android: Modern Android devices encrypt their storage. Android 7.0 and later supports file-based encryption, and new devices running Android 10 or later have to use it.
If yours is not enabled, turn it on now.
Enable "Find My" or remote wipe
If a device is lost or stolen, you want to be able to locate it or wipe it remotely.
- Apple devices: Open Settings, tap your name, tap Find My, then turn on Find My iPhone (or iPad). Turn on Find My network too, so the device can still be found when it is offline. You can then locate devices in the Find My app or at icloud.com/find. Note that you need two-factor authentication on your Apple Account to erase a device from the Find My app.
- Android: Google's service is called Find Hub, and Google says it is automatically turned on once you have added a Google Account to the device. Use the Find Hub app, or google.com/android/find in a browser, to locate, lock, or erase a device. Setting a PIN, pattern, or password is what lets the Find Hub network help locate it.
- Windows: Turn on Find my device in Windows Settings — searching Settings for "find my device" is the quickest route. Microsoft's version needs a Microsoft personal account signed in on the device, and you then find or lock the device at account.microsoft.com/devices.
Test this once so you know how it works before you need it.
Be careful on public Wi-Fi
Public Wi-Fi networks (cafes, hotels, airports) can be insecure. Attackers can create fake networks or monitor traffic on open networks.
Safer practices on public Wi-Fi:
- Use your phone's mobile hotspot instead for sensitive tasks
- Avoid logging into banking, financial, or admin accounts when possible
- If you must use public Wi-Fi, use a reputable VPN to encrypt your traffic
- Never use an unsecured network for anything involving passwords or confidential data
See Safe browsing habits for your team for more on this.
Don't let others use your work devices
Lending your work laptop or phone to a family member, friend, or colleague — even briefly — creates risks:
- They may inadvertently install something malicious
- Children can unknowingly download malware
- Your accounts and saved passwords are accessible if your browser remembers them
Keep work devices for work. Set up a separate limited account if you need to let someone else use a device occasionally.
Install reputable security software
On Windows, the built-in Windows Security app is solid: it includes Microsoft Defender Antivirus, the Windows firewall, and Smart App Control. On Mac, the built-in protections are strong too. Consider adding:
- Malwarebytes — available for Mac and Windows, and its free download scans for and removes malware
- A reputable paid VPN service if your team frequently works from public locations
Avoid installing security software from pop-up ads — these are often malware themselves.
Create a plan for lost or stolen devices
Know what you'll do before it happens:
List what each device can reach. Make a list of which accounts are accessible from each device (especially for shared team devices).
Learn how to lock or wipe each device remotely. Find My for Apple devices, Find Hub for Android, and Find my device on Windows. Erasing cannot be undone, so Apple's advice is to try everything else first.
Act fast if a device goes missing. If a device with business access is lost or stolen: immediately change passwords on your most sensitive accounts, and sign out of active sessions in those accounts' security settings.
Common questions
Do I need antivirus software on a Mac?
Macs have strong built-in protections that handle most threats. Apple describes three layers: the App Store and Gatekeeper combined with Notarization stop malware launching in the first place, and XProtect blocks and removes malware that gets through. Macs are not immune, though, especially through downloaded files. Running an occasional scan with Malwarebytes is reasonable belt-and-suspenders protection. You don't need paid antivirus on a Mac.
Is it safe to use personal devices for work (BYOD)?
Personal devices for work (Bring Your Own Device) are common, but they blur the line between personal and business data. The security steps in this guide apply regardless of who owns the device. If your team handles sensitive customer data, a clearer policy — and potentially device management software — may be worth considering.
What is a VPN and do I need one?
A VPN (virtual private network) encrypts your internet traffic and routes it through a server, hiding your activity from people on the same network. It is most useful on public Wi-Fi. For office or home use, its benefit is more about privacy than security. Use a reputable paid VPN service rather than a free one.
Our office has Wi-Fi. Should I do anything to secure it?
Yes. Use the strongest encryption your router offers: CISA recommends WPA3 Personal with AES, which it calls the most secure router configuration available for home use. If your router is too old to offer WPA3, use WPA2. Use a strong, unique network password, and change the router's admin password from the default, since CISA warns those default credentials may be readily available on the internet or even printed on the device itself. Keep the router's firmware up to date, turn off remote management and WPS, and create a separate guest network for visitors or non-work devices.
Related guides
- Safe browsing habits for your team
- Two-factor authentication, explained
- Malware & your website explained
- Your business security checklist
- Data privacy basics for your business
Need a hand?
Learn more
Last updated
Why backups are your safety net
How website and data backups protect your business when everything else fails — and what a good backup strategy looks like.
Securing your social media accounts
How to protect your Facebook, Instagram, LinkedIn, and other social media accounts from hackers and unauthorized access.