Most business phone risk doesn’t come from hackers — it comes from
default settings nobody ever changed. Out of the box, a phone is
configured for consumer convenience, not business security:
auto-connecting to any Wi-Fi it recognises, backing up company data to
personal cloud accounts, showing message contents on the lock screen,
quietly broadcasting over Bluetooth. Each one is minor on its own.
Across a fleet of dozens or hundreds of handsets, they add up to a
standing exposure. This is a practical checklist of the settings worth
switching off — or locking down — on every business phone, what each one
risks, and how to fix it. None of it needs technical skill; most take
seconds per device, and if you use mobile device management you can
enforce the lot centrally.

Why default
phone settings are a business risk

Consumer defaults optimise for one thing: making the phone effortless
for its owner. That means it trusts networks readily, shares freely, and
keeps everything visible and backed up. For a personal phone, fine. For
a device holding client data, email, and access to your systems, those
same defaults hand small openings to anyone who wants them — a stranger
reading a notification over someone’s shoulder, a rogue Wi-Fi network,
company files syncing into a personal iCloud. The fixes below cost
nothing and close most of the gaps.

Lock
screen: stop your messages leaking in plain sight

By default, phones show the content of messages and emails on the
lock screen — visible to anyone glancing at the device on a desk, a
train, or a counter. For a business handset, set notification previews
to show only when the phone is unlocked (iPhone: Settings →
Notifications → Show Previews → When Unlocked; Android: Settings →
Notifications → hide sensitive content). While you’re there, make sure
the lock screen itself is protected by a strong passcode, not just a
swipe — biometrics like Face ID or a fingerprint are only as strong as
the passcode behind them.

Wi-Fi and
Bluetooth: close the doors you’re not using

Auto-join is the quiet culprit here. A phone set to join known
networks automatically can be tricked into connecting to a rogue hotspot
using a familiar name — a well-known route to intercepting traffic. Turn
off auto-join for anything but your trusted networks, and switch on “ask
to join networks” so nothing connects silently. Bluetooth is similar:
left discoverable and auto-connecting, it’s an unnecessary attack
surface. Encourage staff to keep it off when it’s not actively in use,
and to be wary of pairing requests they didn’t initiate.

Company data and
personal cloud accounts

This is the big one. If a phone is signed into a personal iCloud or
Google account, company photos, documents, and even message history can
quietly sync out to an account your business doesn’t control — and can’t
wipe. Ideally business devices use managed or company Apple/Google
accounts; at minimum, review what’s set to back up and turn off syncing
of anything work-related to personal cloud storage. It’s both a security
risk and, under UK GDPR, a data-handling one — you’re responsible for
where personal data your business holds ends up.

Tracking,
location and the data your phone quietly collects

Phones gather a surprising amount in the background — location
history, advertising identifiers, app analytics — much of it on by
default. Beyond the privacy question, it’s data you may not want leaving
the business. Turn off advertising tracking, limit location access to
“while using” for apps that genuinely need it, and switch off
system-level location history where it isn’t required. (We went deep on
just how much your fleet’s phones log in a separate piece — worth a read
if this surprises you.)

The settings to leave ON

Switching things off is only half the job — a few defaults are worth
keeping, or turning on. Leave Find My / device location
enabled at the fleet level: it’s your best route to locating or remotely
wiping a lost handset. Turn on USB Restricted Mode
(iPhone) or the equivalent, so a locked phone can’t have its data pulled
through the charging port — the “juice-jacking” risk at public charging
points. And keep automatic security updates on: an
unpatched phone is a far bigger risk than any setting on this list, so
the one thing you never want disabled is the flow of security fixes.

FAQs

What’s the single most important setting to change on a
business phone?
Signing devices out of personal cloud accounts
(or using managed ones), so company data can’t sync somewhere you don’t
control. It’s both the biggest security and the biggest GDPR
exposure.

Can these be enforced across a whole fleet at once?
Yes — with mobile device management (MDM) you can set and lock these
configurations centrally, so they don’t rely on each employee
remembering. Without MDM, a short setup checklist for new devices does
most of the job.

Do biometrics make a passcode unnecessary? No. Face
ID and fingerprint unlock sit on top of the passcode — if the passcode
is weak, so is the device. Use a strong six-digit-plus passcode
underneath.

Is turning off tracking bad for the phone’s
performance?
Not at all — it affects advertising and analytics,
not how the phone runs. If anything, fewer background processes is
marginally better for battery.

What about when a device leaves the business? That’s
when settings stop mattering and secure erasure takes over — a factory
reset alone isn’t enough under GDPR. Certified wiping to a recognised
standard, with a record of it, is what protects you.

Retiring devices from your fleet?

The last setting that matters is making sure the data is truly gone. Every device through iGo Trade In is erased to the NIST SP 800-88 standard with an ADISA-certified wipe and a Device History Report per unit — so you can evidence it. Recover the value and the compliance in one step.

Start a trade-in →