By Jackson Godwin. Cybersecurity Analyst & Penetration Tester
After fixing the app permissions, I thought I had found the biggest problem.
I was wrong.
The second mistake was something almost everyone does without thinking.
I opened my browser settings and checked my saved passwords.
There were dozens of them.
Some belonged to websites I hadn’t visited in years.
Others were accounts I had completely forgotten existed.
One or two were accounts I no longer even used.
That immediately raised another question.
“If I don’t use these accounts anymore, why are my passwords still stored on my phone?”
It was time for another cleanup.
Why Saved Passwords Can Become a Security Risk
Saving passwords in your browser is convenient.
You don’t have to remember every login.
You don’t have to type long passwords every time.
But convenience comes with responsibility.
Old accounts often become forgotten accounts.
Forgotten accounts are attractive targets because people rarely monitor them.
If one of those websites suffers a data breach and you’ve reused that password elsewhere, attackers may try the same password on your email, social media, or other important accounts.
This is known as credential stuffing, where attackers use usernames and passwords exposed in previous breaches to attempt logins on other services.
The safest approach is to use a unique password for every important account.
What I Changed
I removed passwords for websites I no longer use.
Then I reviewed the remaining accounts.
For the most important ones, I made sure the passwords were unique and difficult to guess.
If you have dozens of online accounts, a reputable password manager can make this much easier by generating and storing strong, unique passwords.
Security Mistake #3 — Multi-Factor Authentication Wasn’t Enabled Everywhere
I often tell clients:
“Your password is your first lock.
Multi-Factor Authentication is your second.”
Then I looked at my own accounts.
To my surprise, not every important account had Multi-Factor Authentication (MFA) enabled.
Some older accounts still relied only on a password.
That wasn’t good enough.
Why MFA Is So Important
Imagine someone somehow discovers your password.
Without MFA, they may be able to sign in immediately.
With MFA enabled, they still need a second verification step before accessing your account.
Depending on the service, this could be:
- A code from an authentication app
- A hardware security key
- Another approved verification method
MFA doesn’t make an account impossible to compromise, but it greatly reduces the likelihood of unauthorized access.
After my audit, I enabled MFA everywhere it was available.
Security Mistake #4 — Bluetooth Was Always Turned On
The next discovery made me laugh.
My Bluetooth had been enabled for days.
Not because I was using it.
Because I had simply forgotten to turn it off.
Many people do the same thing.
Is leaving Bluetooth on automatically dangerous?
Not necessarily.
Modern smartphones include security improvements that make Bluetooth much safer than it was years ago.
However, if you aren’t using Bluetooth, turning it off reduces unnecessary wireless exposure and can also help conserve battery life.
Now, whenever I finish using wireless earbuds or another Bluetooth device, I simply switch Bluetooth off.
It takes only a second.
Security Mistake #5 — I Had Been Ignoring Security Updates
This was probably the mistake I was most embarrassed about.
My phone had several pending security updates.
I had ignored them because I kept thinking:
“I’ll install them later.”
Sound familiar?
Many people postpone updates because they don’t want to restart their phones or worry that an update will take too long.
The problem is that updates often include fixes for known security vulnerabilities.
Installing them helps protect your device against issues that have already been discovered.
After completing my audit, I installed every available update.
It took less than twenty minutes.
I had delayed it for weeks.
A Simple Habit That Makes a Big Difference
One thing I now recommend is enabling automatic updates where appropriate.
That way, your device receives important security fixes without relying on you to remember every time.
Cybersecurity doesn’t always require expensive tools.
Sometimes it simply requires keeping your software up to date.
By this point, my phone was already much more secure than when I had started the audit.
But there were still two more mistakes waiting to be discovered.
One involved public Wi-Fi.
The other could have turned a lost phone into a much bigger problem than simply replacing the device.
Those final two mistakes completely changed how I think about smartphone security.
Security Mistake #6 — My Phone Automatically Connected to Old Public Wi-Fi Networks
The sixth mistake surprised me more than anything else.
While reviewing my Wi-Fi settings, I noticed my phone had saved dozens of wireless networks.
Coffee shops.
Hotels.
Restaurants.
Airports.
Shopping malls.
Conference centres.
Even a few networks I couldn’t remember connecting to.
Then I noticed something even worse.
Some of those networks had Auto-Join enabled.
That meant if I walked past one of those locations again, my phone might automatically reconnect without me even realizing it.
Why This Matters
Public Wi-Fi isn’t automatically unsafe.
Many businesses provide legitimate wireless internet for customers.
However, public networks also present additional risks because you don’t control who else is connected or how the network is configured.
Cybercriminals sometimes create fake Wi-Fi hotspots with names that resemble legitimate ones.
For example, instead of:
CoffeeShop_WiFi
They may create:
CoffeeShop_Free
or
CoffeeShop_Guest
If your phone automatically connects without you noticing, you could end up on the wrong network.
That’s why I reviewed every saved Wi-Fi network.
What I Changed
I deleted every network I no longer needed.
Then I disabled automatic connection for public Wi-Fi.
Now, whenever I visit a café, hotel, or airport, I connect manually after confirming I’m using the correct network.
It takes only a few extra seconds.
But those few seconds are worth it.
Whenever I use public Wi-Fi for anything sensitive, I avoid logging into banking or other critical accounts unless I have another trusted connection available.
Security Mistake #7 — I Didn’t Have a Proper Recovery Plan if My Phone Was Lost
This turned out to be the most important discovery of the entire audit.
I asked myself one simple question.
“If my phone disappeared today… what would I do in the first five minutes?”
Honestly…
I didn’t have a complete answer.
Most people think about replacing the phone.
Cybersecurity professionals think about protecting the data.
A stolen phone can contain:
- Banking applications
- Email accounts
- Authentication apps
- Password managers
- Private photographs
- Business documents
- Personal conversations
The physical phone can be replaced.
Your digital identity is much harder to recover.
Building a Recovery Plan
I immediately checked several important settings.
Find My Device
I confirmed that my phone’s built-in location service for finding a lost device was enabled.
This can help locate, lock, or erase a lost phone remotely, depending on the circumstances.
Device Backup
I verified that my contacts, photos, and important files were being backed up.
A backup doesn’t stop theft.
But it can make recovery much easier if the device is permanently lost.
Screen Lock
I reviewed my screen lock settings.
Using a strong PIN, passcode, or biometric authentication makes it much harder for someone else to access your phone if they find it.
The Smartphone Security Checklist
After finishing my audit, I created a simple checklist that I now review every few months.
✔ Review app permissions.
✔ Remove apps you no longer use.
✔ Delete saved passwords for forgotten accounts.
✔ Use unique passwords for important services.
✔ Enable Multi-Factor Authentication.
✔ Install operating system updates promptly.
✔ Remove old public Wi-Fi networks.
✔ Disable automatic connection to unfamiliar networks where appropriate.
✔ Enable Find My Device.
✔ Back up important data.
✔ Use a strong screen lock.
✔ Review your security settings regularly.
These habits don’t require expensive software.
They simply require a few minutes of attention.
Final Thoughts
When I started this audit, I expected to confirm that my smartphone was already secure.
Instead…
I discovered seven mistakes that had quietly accumulated over time.
None of them looked serious by themselves.
But together, they created unnecessary risk.
The biggest lesson wasn’t that my phone was insecure.
The biggest lesson was this:
Cybersecurity isn’t something you do once. It’s something you practice continuously.
Attackers don’t always rely on sophisticated hacking tools.
Sometimes they simply wait for people to ignore basic security habits.
Don’t wait until your phone is lost.
Don’t wait until someone steals your account.
Take twenty minutes today.
Audit your own smartphone.
You may be surprised by what you find.
About the Author
Jackson Godwin is a Cybersecurity Consultant specializing in Vulnerability Assessment and Penetration Testing (VAPT), Governance, Risk and Compliance (GRC), ISO/IEC 27001, PCI DSS, Cloud Security, AI Security, and Digital Risk Management.
With extensive experience helping organizations identify vulnerabilities, strengthen security controls, and improve compliance, Jackson is passionate about making cybersecurity simple, practical, and accessible for everyone.
Through JacksonTechnology.com.ng, he publishes expert cybersecurity tutorials, ethical hacking guides, cloud security insights, compliance resources, and real-world security awareness stories that help individuals and businesses stay protected against evolving cyber threats.
Visit JacksonTechnology.com.ng for practical cybersecurity articles, penetration testing resources, AI security insights, ISO 27001 guidance, PCI DSS knowledge, and security awareness content designed to help you stay safe in today’s digital world.







