Phones and tablets now hold the keys to your business - email, files, customer data and access to your systems. Yet mobile security is still treated as an afterthought compared with laptops and servers, even though a modern smartphone has at least as much reach into your business as a PC. This checklist closes that gap with practical, achievable steps every UK business should take, whether you run company devices, BYOD or a mix of both.
Why mobile security matters more than ever
The threat picture has shifted. Attackers increasingly target mobiles directly because that is where people read messages quickly, tap links without thinking, and approve login prompts on the move. A stolen password is far less useful than a compromised phone that holds the email account, the authenticator app and the saved logins all in one place. Treat the phone as a full endpoint - because it is one - and the rest of this checklist follows naturally.
1. Lock every device
It sounds obvious, but an unlocked phone is an open door. Enforce a strong passcode (six digits or more, not a four-digit PIN) or biometric lock on every work device, with automatic locking after a short idle period. This is your first and most important line of defence if a phone is lost or stolen, and it is the precondition for encryption being effective.
2. Turn on encryption
Modern phones encrypt their storage by default once a passcode is set - but confirm it is actually enabled across your fleet rather than assuming. Encryption means that even if someone removes the storage or tries to extract data physically, it is unreadable without the passcode. Combined with a strong lock, it is what lets you treat a lost device as a low-risk event.
3. Deploy Mobile Device Management
MDM is the backbone of business mobile security. It lets you enforce every policy on this list centrally - rather than hoping each member of staff has done it - and, crucially, remotely lock or wipe a device that goes missing. If you take one action from this list, make it MDM: everything else becomes enforceable once it is in place.
4. Use multi-factor authentication
Pair mobile access to company systems with multi-factor authentication, so a stolen password alone is not enough to get in. Prefer app-based or hardware MFA over SMS codes where you can, because SMS is vulnerable to SIM-swap fraud (see below). This ties directly into your wider Microsoft 365 security setup, and is one of the highest-impact controls you can enable.
5. Keep software up to date
Operating system and app updates fix the security holes attackers rely on. Enable automatic updates and use MDM to ensure no device is running an outdated, unsupported OS. This is the mobile equivalent of patch management on your computers - and just as important, because an unpatched phone with email access is a soft target.
6. Control apps and downloads
Restrict installation of risky apps, and only allow company data in trusted, managed apps. On BYOD devices, keep work data in a managed container separate from personal apps, so company information cannot drift into personal cloud backups or messaging apps you have no visibility of. Conditional access - allowing only compliant, enrolled devices to reach your systems - closes the loop.
7. Defend against smishing and phishing
Mobile phishing is rising fast. Text-message scams ("smishing"), fake delivery notifications and bogus MFA prompts are designed for the small screen and the quick tap. Train staff to treat unexpected links and login requests on their phone with the same suspicion they would an email phishing attempt - and never to approve an MFA prompt they did not trigger. Our phone scams guidance is a useful primer for the kinds of social-engineering calls and texts your team will encounter.
8. Guard against SIM-swap fraud
This one catches businesses out. In a SIM-swap attack, a criminal persuades (or tricks) a network into moving a number to a SIM they control, then intercepts SMS-based verification codes to break into accounts. Defences: use app-based MFA rather than SMS where possible, set a porting PIN or account password with your provider, and watch for a phone suddenly losing signal for no reason - a classic SIM-swap symptom. A managed business account with a named contact is also harder to socially engineer than a consumer line.
9. Train your team
Technology only goes so far - your people are the deciding factor. A short, regular briefing on locking devices, reporting losses immediately, spotting scam texts and not approving unexpected prompts pays for itself many times over. The best-secured estate still fails if one person hands over a code to a convincing caller.
The at-a-glance checklist
| Control | What to do | Why it matters |
|---|---|---|
| Device lock | 6+ digit passcode / biometric, auto-lock | First barrier if lost |
| Encryption | Confirm enabled fleet-wide | Data unreadable without passcode |
| MDM | Enrol every device | Central enforcement + remote wipe |
| MFA | App or hardware, not SMS | Stops stolen-password logins |
| Updates | Auto-update, block old OS | Closes known vulnerabilities |
| App control | Managed apps, container on BYOD | Stops data leaking to personal apps |
| Anti-phishing | Train + filter | Smishing is the top mobile threat |
| SIM-swap defence | Porting PIN, app MFA | Protects your numbers and accounts |
| Training | Short, regular briefings | People are the last line |
How this fits Cyber Essentials and your wider security
These controls map closely onto the kind of baseline expected by certifications such as Cyber Essentials and onto your broader IT security posture. Mobiles are simply endpoints, and they belong in the same security thinking as your laptops and servers. For the bigger picture, see our small business IT security checklist - mobile security is one chapter of it, not a separate world. It is also worth buying from a network and provider that take business security seriously, which we weigh up in our comparison of the best mobile network for business.
Get a business mobile quote and we will build these controls into your mobile estate from day one.
Make it effortless
The best mobile security is the kind your staff barely notice while it quietly protects the business - locks and encryption they never think about, updates that happen automatically, and a remote-wipe safety net they never need to know about until the day it saves you. That is entirely achievable, and it is mostly about consistent enforcement rather than expensive tools.
Our Mobile Products service builds this in from day one, alongside a sensible company mobile phone policy. Get a business mobile quote to secure your mobile fleet.
Frequently asked questions
What are the key mobile security best practices?
Lock every device with a strong passcode, enable encryption, deploy MDM, use app-based multi-factor authentication, keep software updated, control apps, defend against smishing and SIM-swap fraud, and train staff. Most are free or built in - the work is enforcing them consistently across the whole fleet.
What is the single most important mobile security control?
Mobile device management, because it lets you enforce every other control centrally and remotely lock or wipe a lost or stolen device before data is exposed. Without it, you are relying on each individual to secure their own phone correctly.
Are mobiles really a security risk for business?
Yes. Phones hold email, files, authenticator apps and access to your systems, so an unsecured or lost device is as serious as an unsecured laptop - arguably more so, because attackers increasingly target mobiles directly with scam texts and fake login prompts.
What is SIM-swap fraud and how do I prevent it?
SIM-swap fraud is when a criminal gets your number moved to a SIM they control, then intercepts SMS verification codes to break into accounts. Prevent it by using app-based MFA instead of SMS, setting a porting PIN with your provider, and treating an unexpected loss of signal as a warning sign.
Should I use SMS or an app for two-factor authentication?
Prefer an authenticator app or hardware key over SMS codes wherever possible. SMS is convenient but vulnerable to SIM-swap interception, whereas an app-based code is tied to the device and far harder to steal remotely.
How do I secure phones if staff use their own devices?
Use MDM to create a managed work container, enforce baseline security through a BYOD policy, and use conditional access so only compliant devices reach your systems. That secures company data without intruding on the owner's personal apps and photos.
Does mobile security count towards Cyber Essentials?
Mobiles are in scope as endpoints, so the same baseline - secure configuration, access control, patching and malware protection - applies to them. Building these mobile controls in is part of meeting that bar and your wider security obligations, not a separate exercise.
