Blogs

Your phone is probably one of the most important of the devices you own. It may contain your WhatsApp conversations, email, photographs, social media accounts, contacts, banking applications, work documents, and access to dozens of other services.

For many people, the phone has effectively become a digital wallet, office, communication centre, and personal diary all in one. That makes it a very attractive target for cybercriminals.

When people hear the word 'hacking', they sometimes imagine a highly skilled attacker breaking directly into their phone. In reality, many successful attacks do not involve technically “breaking into” the device at all.

Attackers often succeed by tricking people into giving them access. It's usually called social engineering.

That is why protecting your phone requires more than installing an antivirus application. It requires a combination of technology, good settings, and sensible behaviour.

Keep Your Phone Updated

One of the simplest things you can do is keep your phone's operating system and applications updated. Software updates often include security fixes that address vulnerabilities discovered by manufacturers and security researchers.

Don't continually postpone updates simply because they are inconvenient. The same applies to the applications installed on your device.

Use a Strong Screen Lock

Your phone contains a lot of information about you. Don't reveal the unlock key or password to everyone. Don't leave your phone unattended, and don't leave it without a security lock and/or password.

Protect it with a strong PIN, password or other secure authentication method. Biometric options such as fingerprint recognition or facial recognition can also provide convenient additional protection where supported by the device.

Avoid obvious PINs such as birthdays or simple sequences that someone who knows you could easily guess.

Protect Your Accounts

Your phone itself may be secure, but your accounts can still be compromised. Your phone will often have multiple accounts set up inside, and all of them need to be secure. Pay particular attention to your Google or Apple account, email accounts, WhatsApp, social media accounts, banking and financial applications, and other important online services.

Use strong, unique passwords and enable two-factor authentication (2FA) wherever possible. Especially for accounts that require someone to log in, like banks, etc., it is important to stick to just a few devices that you use to log into your sensitive accounts. We recommend using just one or two browsers, and one or two gadgets. That way, the moment the attacker tries on another gadget, the provider might sense a strange request and send a warning. 

Your email account deserves particular attention because it can often be used to reset passwords for other services or send a malicious link to hack into the phone.

Be Careful What You Click

A message arrives on WhatsApp:

“Look what I found about you!”

Or perhaps:

“Your account has been selected for a reward. Click here.”

Or:

“Your bank account will be blocked unless you verify your details.”

These messages are designed to make you act before you think. Don't click immediately. Even if the message appears to come from someone you know, remember that their account may have been compromised. Check it carefully, including the URLs given, and find out if they look genuine. You can search on Google separately about a claim (including job adverts) and verify. When it comes to security, stay alert and think negatively until you prove otherwise.

If a message seems unusual, verify it through another channel before taking action.

Be Careful With Apps

Only install applications from trusted and official sources whenever possible. Avoid downloading applications from unknown websites simply because they promise something for free. Most scams work because something is promised for free.

Before installing an application, consider:

  • Who developed it?
  • Does it really need the permissions it is requesting?
  • Does the application have a credible reputation? Check reviews.
  • Is it requesting access to contacts, messages, photographs, microphone, or location without an obvious reason?
  • How old is the application? Who else is using it?

An application should not automatically receive access to everything on your phone simply because you want to use one of its features.

Protect Your WhatsApp

WhatsApp has become an essential communication tool for individuals and businesses across Africa. That also makes it attractive to criminals.

Enable two-step verification on your WhatsApp account and never share verification codes with anyone. 

Be especially cautious if someone asks you to send them a code that has just arrived on your phone.

That code may be the very thing an attacker needs to take over your account.

Be Careful With Public Wi-Fi

Free public Wi-Fi can be convenient, but you should be cautious when using unfamiliar networks. As much as possible, you can avoid them. But if you do use them, be careful about which applications and/or websites you open when connected to such Wi-Fi. 

Avoid carrying out sensitive activities on networks you don't trust, particularly where you cannot verify who operates the network. When possible, use your mobile data or a trusted network for sensitive transactions.

Protect Your Financial Apps

Your phone may provide direct access to your bank and other financial services.

Never share banking passwords, PINs, one-time passwords (OTPs), verification codes, or authentication codes that come to you via SMS or WhatsApp, or any other App. Actually, this is how even Facebook and other platforms get hacked. Including MPESA apps. And don't just click any link that comes along.

A legitimate bank or service provider should not need you to disclose your confidential authentication credentials to them.

If you receive an unexpected call or message asking for such information, stop and verify through the organisation's official channels. You can disconnect the call and then immediately call the organization using the official phone numbers to verify such claims.

Think Before You Give Someone Remote Access

Be cautious if someone unexpectedly asks you to install an application that will allow them to control or access your phone remotely. This type of access can be legitimate in some technical-support situations, but it can also be abused. If you don't understand why someone needs access to your device, don't grant it. You also do not need to trust anyone with remotely accessing your device, even if they're from authentic organizations and service providers. You cannot guarantee that every employee is ethical. 

Back Up Important Information

Phones can be lost, stolen, or damaged. Make sure your important photographs, contacts, and other valuable information are backed up using a trusted backup service. A backup can help you recover your information when your device is lost or replaced.

However, remember that your backup account itself must also be protected with a strong password and two-factor authentication.

What If You Think Your Phone Has Been Compromised?

Don't panic. Start by changing the passwords of your most important accounts, beginning with your email and other accounts that can be used for password recovery.

Review recent account activity and remove applications you don't recognise.

Check your WhatsApp and other important accounts for unusual activity.

If you believe your financial accounts may have been compromised, contact your financial institution immediately through its official channels.

And if you suspect that someone has obtained access to your device, seek professional technical assistance rather than continuing to use it as if nothing happened.

Your Behaviour Is Your First Line of Defence

The most sophisticated security technology cannot completely protect someone who willingly gives an attacker their password, verification code, or access to their account. It is said that the safest security method is to wrap up all your devices, switch them off, and never use them. But that is not practical. So you just stay alert and cautious. Reduce the risk. You cannot eliminate it. 

This is why cybersecurity is not just about technology. It is also about awareness and behaviour. Situational awareness, so to speak. 

Before clicking, installing, sharing or approving something, pause and ask: â€śWhy am I being asked to do this, and who is asking me?” That simple question can prevent many problems.

The Bottom Line

Your phone is more than just a gadget for calling and receiving calls. It is your communication centre, financial gateway, work tool, entertainment device, and often the key to your digital identity. Protect it accordingly.

Keep it updated. Lock it securely. Protect your accounts. Use two-factor authentication. Be careful with links and applications. Never share verification codes. Back up your important information. And, above all, think before you click.

You don't need to become a cybersecurity expert to become significantly safer. You simply need to develop better digital habits.

Your phone may be smart. Make sure your security habits are smarter. 

At ICT Gurus EA, we believe that technology should make life and business better—not expose you to unnecessary risk.

Stay informed. Stay secure.

No comments yet
Search