Guides Mobile

Phone security without the theatre

Phones are attacked differently from computers, so the advice that works is different too - and it mostly is not about installing a scanner.

5 min read  ·  Last reviewed 11 August 2026  ·  Written for people looking after their own devices

Why a mobile scanner is not the answer it sounds like What a scanner can do Filter web pages Route traffic through a VPN Alert on breached addresses What actually goes wrong Apps from outside the store Over-broad permissions Phishing by message A lost, unlocked device
Both systems isolate apps from each other, so on iOS an app cannot inspect the system or other apps at all.

Why scanners do less here

Both major mobile systems isolate applications from each other. On iOS, an app simply cannot inspect the system or other apps, so a mobile "antivirus" cannot scan in any meaningful sense. What these apps actually provide is usually web filtering, a VPN, or alerts when your address appears in a breach.

Those can be worth having. They are just not the thing the name implies.

What actually goes wrong on phones

  • Applications installed from outside the official stores.
  • Permissions granted without thought - an app with no need for it reading contacts, location or messages.
  • Phishing through SMS, messaging apps and the browser, which works the same as on a computer but is harder to inspect on a small screen.
  • A lost or stolen device that was not locked.
  • Accounts compromised elsewhere, with the phone merely the place you notice.

What to actually do

  • Keep the system updated. Mobile updates frequently contain security fixes.
  • Install from the official store, and look at the developer before installing.
  • Review permissions occasionally and revoke what an app does not need.
  • Use a passcode of reasonable length along with biometrics, and turn on automatic locking.
  • Enable the remote find-and-erase feature, before you need it.
  • Use a second factor on your accounts - your phone is often the recovery route for everything else.

Public Wi-Fi, honestly

Traffic to sites using HTTPS - which is now nearly all of them - is already encrypted between your device and the site, so the old picture of someone reading your passwords from the next table is largely out of date.

A VPN on public networks still hides which sites you visit from the network operator and protects the smaller amount of traffic that is not encrypted. That is a real benefit, and a narrower one than the marketing suggests.