When I look at a client's phone, I do not just see a device. I see a single pocket holding their identity, their money and their privacy all at once. So I treat it the way I treat house keys: the technology matters, but the habits that make an attack more costly matter more.
Your phone holds more than data: it holds the way to you
A phone appeals to an attacker because a single breach opens a whole chain of access, from email and banking to family photos. Let the device out of your hands and you are not risking just one app, but often that entire chain. That is exactly why protecting a phone takes more than a decent lock-screen passcode.
I explain it to clients with a simple picture. A phone is like your house keys, your wallet and the family photo album packed into one pocket. You do not want someone to get hold of all of it at once just because you left one weak lock open.
The best defence is rarely complicated. It usually comes down to a handful of settings and habits that make every attempt far more costly for an attacker. In practice, that is what matters most: not a promise of absolute security, but making an attack genuinely harder.
A SIM swap depends on persuading your mobile operator, not on technical wizardry
SIM swapping works through social engineering aimed at the mobile operator. The attacker gathers your personal details and tries to persuade the operator to move your number to their SIM. If they succeed, they start intercepting your calls and text messages, including one-time codes and password resets.
The weak point is not the SIM card itself but a person or process at the operator that can be manipulated into transferring the number using details the attacker has obtained elsewhere. I covered SIM swapping in detail in the instalment on two-factor authentication, so here I will simply summarise what is worth doing.
- call your mobile operator and set a PIN or password on your account
- ask whether you can add a lock against number transfers
- move verification from SMS to an authenticator app
- for higher-risk accounts, consider a hardware key or a passkey
Lockdown Mode is for highly exposed people, not for convenience
For people who are in the public eye, wealthy or travelling to higher-risk countries, I also look closely at Lockdown Mode on the iPhone. It shrinks the attack surface drastically by restricting link previews and attachments in messages, some web technologies and incoming connections. It is a feature for situations where security has to come before comfort.
The point of the mode is not that it is pleasant to use. The point is that it reduces the room commercial spyware has to work with. Public analyses by security researchers so far suggest that Lockdown Mode is highly effective. I read that as a strong signal, not as a promise of complete immunity.
Top-tier spyware also often works on a zero-click basis. The victim does not have to click anything, and the infection may show no visible symptoms. That is why system updates matter, as do any warnings from the manufacturer. With an attack like this, by the time you are dealing with the consequences, it is already too late.
A zero-click case shows why gut feeling is not enough
The case of former MEP Stelios Kouloglou illustrates this well. His phone was hit by a zero-click exploit that abused HomeKit and iMessage on iOS 15.5. The first infection has been dated to 21 October 2022; the second came in March 2023, during the final meetings of the European Parliament's committee of inquiry that was itself investigating spyware cases. Over time, Apple sent him three threat notifications, the first as early as the beginning of March 2023, and forensic analysis confirmed the infection only after the event.
It shows something important: top-tier spyware does not need a single click and is often discovered only after the fact. Anyone who relies on noticing something suspicious is usually already too late. With a risk like this, what counts is prevention, not a hunch.
For me, that leads to a simple rule. Anyone in a higher risk category should not wait for a visible problem. They should reduce the attack surface in advance, keep the system up to date and assume that the most dangerous attacks are the quiet ones.
App permissions, the cloud and public Wi-Fi all call for discipline
Another way I protect a phone is by going through app permissions. Wherever an app does not need location, the microphone, contacts or photos, I take that permission away. I install apps only from the official app store and avoid sideloading, because that is where malware usually has more room to operate.
The cloud follows the same logic. iCloud Advanced Data Protection extends end-to-end encryption to backups, photos and notes as well. Without it, some of the keys stay with Apple. Once it is on, however, the responsibility also rests with you: you need to set up a recovery contact in advance or keep the recovery key somewhere safe, away from the phone.
On public Wi-Fi, I no longer worry about the old myth that anyone can easily pluck your banking password out of the air. Most web traffic runs over HTTPS, so the content is usually encrypted. The real risk lies elsewhere: fake networks, spoofed login portals and DNS leaks. If you do not know the network, check its name, steer clear of dubious portals and, on untrusted networks, use an audited VPN, as I described in the instalment on VPNs. That hides your traffic from whoever runs the network. Encrypted DNS (DNS over HTTPS) deals with a narrower point: stopping the network operator from seeing which domains you look up.
- remove unnecessary app permissions
- install apps only from the official store
- enable iCloud Advanced Data Protection if you use iCloud and it is available to you (Apple no longer offers it to new users in the UK)
- set up a recovery contact in advance or store the key away from the phone
- on unfamiliar Wi-Fi, check the network name and watch out for fake portals
A habit reset helps most, and the conclusion needs no drama
Before a sensitive trip, I do a simple habit reset. I restart the phone, because that forces the PIN rather than biometrics, and I also consider switching biometrics off temporarily. I keep sensitive data on the device to a minimum and check what I have stored in the cloud. It is rather like checking what you are actually carrying before you walk into a sensitive area.
A strong alphanumeric passcode is better than a four-digit PIN. Add automatic erasure after repeated failed attempts and the phone becomes distinctly uncomfortable territory for an attacker. For people facing higher risk, this step makes particular sense.
In short, a phone is not just a piece of electronics. It is the main point of access to your life, and that is exactly why it deserves discipline. If you would like to review your settings, app permissions and mobile operator account with no wasted words, we can go through them together, factually and with no obligation. What you need is not fear but order.
“I no longer carry my phone as just an object. It is the key to everything else, and I treat it accordingly.” — Robert Václavík




