Guide
How to actually lock down your digital life
Good digital security starts with a simple map. You need to know which account, device, phone number or physical object can reset everything else.
For many Australians, that root is an Apple Account or Google Account, a phone number, and the password manager holding every other password. Secure those first. Adding email aliases, extra phones or safes around an exposed root gives you more work without fixing the central weakness.
Every control in this guide moves risk. A hardware key moves risk away from a phishable code and into a physical object plus the service's recovery process. A separate login number moves risk away from your public number and into another handset and a carrier account. An encrypted backup moves risk away from theft and into the place where you keep its decryption secret.
For each control, this guide names the failure mode. Do not add a control until you can live with that failure, or have written down how you will recover.
DSRA receives no money, commission, free product or other benefit from any vendor named here. Names appear only where needed to act.
Start with personal safety
If a partner, ex-partner or family member may be monitoring your device, do not begin by changing settings on that device. A sudden password, location-sharing or account change can be visible to the other person and may increase danger. The eSafety Commissioner advises making a safety plan first and, where possible, using a phone or computer the other person cannot access.
Use a trusted person's device, a work or library computer, or a separate safe phone to seek help. 1800RESPECT can help you make a safety plan. Call 1800 737 732, text 0458 737 732, or use its online chat. The service is available 24 hours a day. In an emergency, call 000. See 1800RESPECT safety planning and eSafety's domestic violence guidance.
Failure mode: A security change can alert the person whose access you are removing. Timing, a safe device and a support plan come before the setting change.
What this page will not do
This page cannot tell you whether your device is compromised. A warm phone, a flat battery or an unfamiliar login can have several causes. It also cannot make a device safe while another person knows its passcode, controls the account that manages it, or can force you to unlock it.
It will not promise complete protection. Updates cannot fix an unpublished flaw. A security key cannot protect a service that lets an attacker recover the account through a weaker route. A remote safe cannot help if you cannot reach it. A backup cannot restore data that was never included or a key you cannot find.
If you have evidence of targeted spyware, stalking, unauthorised financial access, or an active account takeover, preserve evidence where safe and get specialist help. Avoid experimenting on the affected device before you understand what evidence may be lost.
Build your map before buying anything
Write down your important accounts. Include email, Apple or Google, banking, government, telecommunications, cloud storage, social media and your password manager. For each one, record:
- How you sign in.
- Where a password reset goes.
- Which phone number or email is used for recovery.
- Which devices are already trusted or signed in.
- What happens if you lose every normal sign-in method.
Do not put passwords or recovery codes in this map. It is an inventory of dependencies. Keep it private because it still tells another person where to apply pressure.
Draw an arrow from each account to anything that can recover it. The thing with the most arrows pointing to it is a root of trust. Your primary email often has more power than your bank login because it receives reset links for many other accounts.
Failure mode: The map itself reveals valuable relationships. Store it separately from public papers and shared household accounts. In a family violence situation, do not place it in a home or shared cloud account the other person can reach.
The three-tier ladder
You can stop after any tier. Tier 1 done carefully is stronger than Tier 3 maintained badly.
Tier 1: free, one afternoon
Tier 1 uses controls already built into supported phones and accounts. It addresses common password reuse, many password-only takeovers, known software flaws, unwanted sharing and ordinary device theft. The Australian Cyber Security Centre says MFA protects against the majority of password-related attacks. It does not publish a defensible percentage of all attacks stopped by these steps, and no single percentage would cover scams, malware, physical coercion, account recovery and targeted exploits at once.
This is the honest coverage:
- A unique password for every account. What it covers: Credential stuffing that depends on replaying the same password. What remains: Phishing, malware, a weak recovery path and a compromised device.
- MFA. What it covers: The majority of password-related attacks, according to ACSC. What remains: Real-time phishing of codes, session theft, recovery abuse and forced access.
- Automatic updates. What it covers: Flaws fixed in the update you install. What remains: Unknown flaws, unsafe sharing and social engineering.
- Sharing and session review. What it covers: Access you find and remove. What remains: Hidden access outside the reviewed service and later re-entry.
- A tested backup. What it covers: Loss or corruption of data that is actually present and restorable. What remains: Account takeover and missing or unreadable backup data.
1. Update and lock your devices
Install current operating system and app updates. On iPhone, use Settings > General > Software Update > Automatic Updates, then enable automatic installation and system file updates. Apple calls keeping software current one of the most important steps for product security. Android menus vary by maker, so search Settings for System update and Google Play system update.
Use a device passcode that another person does not know. Do not reuse a banking PIN. If someone has watched you enter an iPhone passcode, enable Stolen Device Protection at Settings > Face ID & Passcode > Stolen Device Protection. Choose Always under Require Security Delay if the extra delay at home and work is acceptable. It requires biometrics without a passcode fallback for some sensitive actions and delays certain account changes. Apple lists iOS 17.3 or later, Face ID or Touch ID, Apple two-factor authentication, Find My and Location Services as requirements.
Failure mode: Updates sometimes change behaviour, and Stolen Device Protection can delay your own urgent changes. A passcode is also vulnerable if it is shared, observed or coerced. Keep a tested backup before major updates and know how to contact the vendor from another device.
2. Use unique passwords and choose a password manager
Give every account a different generated password. Remember one strong, unique password or passphrase for the vault. ACSC describes a passphrase as four or more random words and says it should be long, unpredictable and unique. Do not store the only copy of the vault password inside that same vault.
A password manager becomes a root of trust. Choose one that:
- supports all the devices you actually use
- supports FIDO2 or passkeys for vault sign-in or MFA
- has a documented recovery or emergency process
- can create a portable encrypted export
- publishes a clear security design and incident history
- lets you test an export before you depend on it.
Bitwarden, 1Password and Apple's Passwords app are reasonable products to assess, not automatic recommendations. Bitwarden supports FIDO2 WebAuthn for two-step login and encrypted exports. Some of its passkeys can also unlock a vault when the browser and authenticator support the required PRF feature. 1Password combines an account password with a Secret Key and provides an Emergency Kit. Apple Passwords is built into current Apple platforms and synchronises through iCloud Keychain, which makes the Apple Account and trusted devices especially important.
LastPass needs separate treatment. LastPass confirmed that an attacker copied backups of all customer vault data in 2022. Sensitive fields were encrypted, while URLs and some other metadata were not. The stolen encrypted copies can be attacked offline, and later password changes cannot recall them. Public investigations have linked a pattern of cryptocurrency thefts to people who had stored wallet material in LastPass, but that linkage was not a court finding about each theft. LastPass says it has since changed its systems. That does not remove the older stolen copies.
If you used LastPass during the incident, prioritise changing credentials for email, banking, cloud storage, cryptocurrency and other high-value accounts that were in the old vault. Move only after you have tested the new manager and export. Deleting the old account before confirming the new copy can create a self-inflicted lockout.
Failure mode: Losing the vault password, its security key and every recovery method can lock you out of everything at once. A compromised unlocked device may expose the open vault. Keep a sealed recovery record outside the vault, protect the vault with the strongest supported factor, and make a tested encrypted export.
3. Turn on the strongest MFA each service offers
Use this order when available:
- A device-bound FIDO passkey or physical FIDO2 security key.
- An authenticator app code.
- SMS or a voice call.
Use SMS when it is the only option. It is still a second factor. Its weaknesses include poor reception, delivery to the same phone as the login, and number theft through a port or SIM swap. Authenticator codes can also be captured by a convincing phishing site and replayed immediately. FIDO credentials are tied to the real site's identity, which prevents that replay against the real account.
Download recovery codes where offered. Store them outside the account they recover. Remove weaker fallback methods only after you have tested the stronger method and its recovery route.
Failure mode: A lost phone, deleted authenticator entry or unavailable number can stop your login. A recovery code stored only on that phone does not solve the problem. Keep a protected offline copy and test a normal sign-in before closing the setup session.
4. Harden the accounts that reset other accounts
Start with primary email, Apple or Google, your password manager and your telco account. Change any reused password. Turn on the strongest MFA offered. Check the recovery phone and email. Remove devices and sessions you do not recognise.
For Google, open your Google Account and use Security & sign-in, then review Your devices, Recovery phone, Recovery email, Passkeys and security keys, and recent security events. Google advises using a recovery phone that belongs only to you and a separate recovery email that you use regularly. Changes to recovery information can take time to become trusted, and previous information may still receive codes for seven days.
For Apple, review devices at Settings > your name. On iPhone with iOS 16 or later, Settings > Privacy & Security > Safety Check can review people, apps, devices and trusted numbers. In a family violence situation, use this only after safety planning because stopped sharing can be noticed.
Failure mode: Recovery information is another login path. A weak recovery email or shared number can undo strong MFA. Removing a trusted device too early can also remove your only working recovery route. Verify the replacement route before removal.
5. Make and test one backup
Back up the files whose loss would matter. A cloud copy is useful, but it is not offline. For an offline copy, connect an external drive, make the backup, safely eject it, then disconnect it from devices and networks. ACSC warns that malware and ransomware can reach connected drives and synchronised storage.
Restore a selection of photos, documents and an important archive into a new folder. Open the restored files. Record the date, source, backup used, files restored and result. A successful copy message is not a restore test.
Failure mode: A backup can be stale, incomplete, corrupt or encrypted with a missing key. Keep the decryption secret outside the account or device being backed up. If the only copy of the secret is in the failed system, the backup is unusable.
Tier 2: about the cost of two hardware keys
Tier 2 strengthens the root accounts most exposed to phishing. Buy two compatible FIDO-certified keys. Fingerprint readers are optional.
FIDO2, WebAuthn, U2F and passkeys in plain English
WebAuthn is the web standard that lets a site use a public-key credential. FIDO2 combines WebAuthn with the protocol used to communicate with an authenticator, including an external key. U2F is the older FIDO protocol for using a key as a second factor. A passkey is a FIDO credential that may be device-bound or synchronised by a passkey provider.
During registration, the authenticator creates a private key and the service keeps the matching public key. During sign-in, the service sends a fresh challenge. The authenticator signs it only for the site identity for which the credential was created. A fake site cannot ask your key to sign in to the real site. A six-digit code has no such knowledge of the destination. If you type it into a fake page, the attacker can immediately type it into the real page.
This origin binding is the main security benefit. It does not make the account's recovery process phishing-resistant.
Failure mode: A service may retain SMS, email or support recovery even after you add a key. Check every listed sign-in and recovery method. The weakest accepted route still matters.
Choose keys for your devices and services
Check connector and transport support before buying. USB-C plus NFC is flexible across many current phones and computers. The YubiKey Bio Series is USB-A or USB-C only and is primarily a desktop key. Yubico directs people who need NFC to its YubiKey 5 Series.
As checked on 29 August 2026, the retail YubiKey Bio FIDO Edition supports FIDO2/WebAuthn and U2F. It does not provide the broader OTP, OpenPGP or Smart Card/PIV functions of multi-protocol products. The Bio Multi-protocol Edition adds Smart Card/PIV but is offered through YubiKey as a Service's Compliance tier, rather than ordinary retail. Product lines change, so verify the current Yubico page before buying.
The fingerprint provides local user verification. You must set a FIDO2 PIN before enrolment, because the key needs that PIN as a fallback whenever it cannot read your fingerprint. On a FIDO2 site the browser can prompt you for the PIN, so a failed fingerprint is a minor annoyance. U2F has no concept of a PIN, so a U2F-only site cannot prompt you for one. If your fingerprint stops working there, you have to unblock biometrics separately using the Yubico Bio start page, Yubico Authenticator or the ykman tool, which in practice means finding a computer. Avoiding routine PIN entry reduces the opportunity for someone to observe it. The fingerprint does not strengthen the public-key cryptography. Resetting the FIDO2 application removes its stored fingerprints and passkeys.
Failure mode: A key can have the wrong connector, lack NFC, or lack a protocol an older service expects. A damaged biometric reader may force PIN use. Check FIDO certification, transports and the exact service documentation. Keep the PIN outside the key and away from anyone who holds it.
Enrol both keys in the same sitting
Open the security settings for each root account. Register Key A, then register Key B before closing the session. Give them clear labels. Test both in a private browser window. Store service recovery codes only after confirming they are current.
Apple requires at least two FIDO-certified keys and permits up to six. Google recommends a primary and at least one backup key for Advanced Protection. Other services vary. GitHub passkeys can satisfy password and 2FA together, while a security key added as a 2FA method remains one of several methods. Microsoft personal accounts can use a FIDO2 key for passwordless sign-in. Bitwarden supports FIDO2 as two-step login and has a separate, more limited passkey-to-unlock path.
Do not describe any service as "key only" until you have inspected its recovery options. Apple still accepts the Apple Account password plus either a key or a nearby trusted Apple device. Google Advanced Protection still has a delayed account recovery process. Recovery is part of the authentication system.
Failure mode: If you enrol one key and postpone the second, losing the first may force account recovery before you can add a replacement. Enrol and test both while the known-good session remains open.
Carry one and store one elsewhere
Carry Key A if you need new-device sign-ins while away. Store Key B at a genuinely separate, reachable location. A labelled key does not need to name the account holder. Review the storage location when you move, separate, travel for a long period or change who can enter the property.
If one key is lost, use the other or a trusted session. Add a replacement first. Test it. Then remove the lost key from every account. Keep a list of accounts on which the keys are enrolled, without storing passwords in that list.
Failure mode: Two keys kept in the same bag can be lost together. A key in a former home or inaccessible safe is not a backup. A carried key can also be taken with an unlocked phone. Physical separation and a tested replacement procedure matter more than fingerprint branding.
Tier 3: separation for a small high-risk group
Most people do not need Tier 3. Consider parts of it if your work or circumstances make you a specific target, such as investigative journalism, human rights or political activity, administration of unusually valuable systems, credible stalking, or a documented history of targeted account attacks. A specialist may recommend a different design.
The purpose is separation. The cost is another handset, another service, more charging and updates, more recovery dependencies, missed codes, compatibility work and a second object that can be lost or found.
Use a separate login number only where it helps
A number used only for account recovery is less exposed than a number printed on forms and shared with contacts. Put it on a separate, supported phone if compromise of your everyday phone is a realistic part of your threat model. Do not give the number out socially.
An eSIM removes the removable card. A thief cannot pull that card from your phone and insert it into another handset. An eSIM does not stop a carrier from issuing a replacement SIM or eSIM, or another carrier from porting the number after failed identity checks. ACMA distinguishes those carrier-side attacks as SIM swaps and unauthorised ports.
Australian telcos must use multi-factor identity checks for high-risk transactions under the Telecommunications Service Provider (Customer Identity Authentication) Determination 2022. ACMA says high-risk transactions include SIM swaps and that telcos must offer extra fraud-mitigation protections to customers who believe they are at risk.
Ask your carrier to mark you as at risk, explain which transaction notifications it can enable, and ask for the strongest account or port restriction available. Record the answer and date because products change.
- Telstra currently documents a Telstra PIN and Account Lock. In My Telstra use Profile > Security and safety > Advanced security settings > Account Lock. It requires a passkey and blocks certain assisted-channel changes while active. You can unlock it in the app. If your phone is lost, Telstra says it can verify you another way.
- TPG currently says you can request an account passcode by phone. It also says it sends a verification code to the affected number for a port and can reverse an unauthorised port.
- DSRA could not verify a current public Optus or Vodafone page offering an optional, non-bypassable port lock. Ask each carrier directly whether it offers an account passcode, an at-risk flag and a port or SIM-replacement block. Do not assume a handset SIM PIN is an account PIN. A handset SIM PIN only protects use of that SIM on a device.
If the eSIM phone is lost or dead, automatic transfer may need the old device. Google says compatible Pixel transfers require both devices, current Google Play services and a screen lock. If automatic transfer fails, contact the carrier. Plan for carrier identity verification without relying on the missing phone.
Failure mode: The secret number and handset become a concentrated availability risk. A port, carrier account takeover, dead battery, expired service or inaccessible phone can block several accounts. Keep non-SMS recovery for root accounts, pay the service on time, update the phone and rehearse the lost-phone call with the carrier.
Choose the second phone for separation first
A supported stock Android phone or second iPhone provides the main architectural benefit: important authentication is not on the everyday phone. No primary source supports a claim that this is exactly 90 percent of the benefit. The remaining benefit depends on the attack.
GrapheneOS adds exploit mitigations, attack-surface reductions, hardened sandboxing, stronger controls and sandboxed Google Play without special system access. That can matter for a person facing sophisticated device exploitation. It also asks you to install and maintain a different operating system.
GrapheneOS currently recommends Pixel 8 and later generations because they have seven years of minimum support from launch and hardware memory tagging. At the check date, Pixel 8 support runs to at least October 2030, Pixel 8a to May 2031, the Pixel 9 family to 2031 or 2032 depending on model, and the Pixel 10 family to 2032 or 2033 depending on model. Pixel 6 and 6 Pro reach their minimum support end in October 2026 and should not be a new purchase for this job. Recheck the GrapheneOS device support table before buying.
Buying new is useful for a clean ownership history and a long support window. It is not required for verified boot. A compatible used Pixel can be unlocked, wiped, installed from the official GrapheneOS installer, relocked, and checked against the project's verified boot key hash. Relocking the bootloader is required for the full verified boot protection. Avoid a carrier model whose bootloader cannot be unlocked.
App compatibility is a real cost. Most apps work after sandboxed Google Play is installed. Some banking and other apps enforce Google certification or Play Integrity and may refuse to run. RCS can work with Google Messages and sandboxed Google Play under documented conditions. Wi-Fi calling and other carrier features can vary. Test every essential app and carrier function before moving the only login number.
Failure mode: A beautifully hardened second phone that is flat, months behind on updates or unable to run an essential app is a poor authenticator. Put it on a charging and monthly update routine. Keep it reachable but separate. Test calls, SMS, mobile data, Wi-Fi calling, RCS if needed, security keys and account recovery.
Keep a Google identity account off phones only for a clear reason
You can keep a Google account off every phone and use it through a computer browser for Gmail, Drive, Docs, Calendar and Sign in with Google. This reduces the number of mobile devices carrying its session, synchronised data and phone-based passkeys.
It also removes useful functions. Adding a Google account to Android normally synchronises email, contacts, calendar and other account data. An account kept off the phone cannot provide those account-bound phone features. You also lose that phone as a trusted signed-in recovery point. Some Google Play purchases, backups and app workflows require the relevant account on the Android device.
Google's Advanced Protection Program is often a more balanced control. It is free, although physical keys cost money. It requires a passkey or security key, restricts sensitive account data to verified third-party apps, strengthens download checks, blocks app passwords and tightens recovery. A passkey can sign in without the password. If you choose the password route, Advanced Protection requires a security key.
Before enrolling, set a recovery email and phone you control. Google recommends a primary and backup key. If you lose all keys or passkeys and have no signed-in session, recovery takes a few days and Advanced Protection must be enabled again. Advanced Protection accounts cannot use Google's recovery contacts, although normal personal accounts can add them.
An extremely long generated Google password stored only on the separate phone creates a circular failure. If that phone is gone, you need the password to reach the account that may help restore the phone. Keep a sealed offline route to the password or a tested recovery method.
Failure mode: Keeping the account off phones trades exposure for availability. You may miss security alerts and lose a trusted recovery signal. Decide whether the account is an identity-only root or an everyday Google account. Do not impose the rule on an account whose mobile services you need.
Use Apple's advanced controls in the right order
Start with a supported, fully updated iPhone. The latest model and direct Apple purchase are not general requirements for a secure iPhone. Updates, account security and recovery design do more day-to-day work.
Turn on Stolen Device Protection as described in Tier 1. Then consider these controls.
Security Keys for Apple Account. Apple requires two to six FIDO-certified keys. On iPhone use Settings > your name > Sign-In & Security > Two-Factor Authentication > Security Keys. Keys replace the six-digit verification code, but your password and a nearby trusted Apple device remain valid parts of sign-in. Losing all trusted devices and all keys can permanently lock you out.
Advanced Data Protection for iCloud. This is available through Apple's Australian support flow. Use Settings > your name > iCloud > Advanced Data Protection. It applies end-to-end encryption to the majority of iCloud data, including iCloud Backup, Photos and Notes. Apple then lacks the keys needed to recover that data. You must set a recovery contact or recovery key first. Web access to iCloud data is off by default and can be temporarily approved from a trusted device. Some shared content remains under standard protection.
Recovery contact. Use Settings > your name > Sign-In & Security > Recovery Contacts. The contact can give you a recovery code but cannot view the account. They need a compatible Apple device and must be available when you need them.
Recovery key. Use Settings > your name > Sign-In & Security > Recovery Key. Apple's recovery key is a 28-character secret. Enabling it disables Apple's standard account recovery. If you lack a trusted device and cannot produce the key, permanent lockout is possible. Apple says not to store it in Passwords, Photos, Notes or iCloud Drive. Keep copies in more than one suitable physical place. With Advanced Data Protection and both a contact and key configured, either can help recover the account.
Lockdown Mode. Apple says this extreme mode is for the very few people personally targeted by highly sophisticated attacks. Use Settings > Privacy & Security > Lockdown Mode > Turn On Lockdown Mode, then restart. It blocks most message attachment types and some links, restricts complex web technology, blocks some FaceTime calls and Apple invitations, removes Shared Albums from the device, tightens wired connections, disables insecure Wi-Fi joining and 2G or 3G, and blocks new configuration profiles. Ordinary calls and plain SMS continue. Websites and workflows can break or lose features.
Failure mode: These controls concentrate recovery in trusted devices, physical keys, trusted people and paper secrets. Lockdown Mode also costs functionality. Before enabling each control, name two ways back in, test both, and record which devices or people they depend on. Do not choose a recovery contact who is unsafe, controlling or likely to be unreachable.
Use Hide My Email with an exit plan
Hide My Email is an iCloud+ service. It creates random addresses that forward to an email address associated with your Apple Account. On iPhone use Settings > your name > iCloud > Hide My Email. Create one address per service and label it clearly.
This gives each service a different username and makes it easier to stop mail to one leaked address. It also reduces cross-service linking. A unique password already prevents simple replay of the password from one service to another. The alias adds separation, but it does not replace the unique password.
You can change the single destination address to another email associated with the Apple Account. You can reply through the alias without exposing that destination. New outbound messages using Hide My Email support one recipient at a time. Deactivating an alias stops forwarding and returns mail to the sender. You can reactivate it. Permanently deleting an inactive alias cannot be undone.
The dependency is Apple. You need iCloud+ to create and manage the service, and Apple says you lose access to Hide My Email when you downgrade to the free iCloud plan. Apple's public documentation does not state clearly whether existing aliases continue forwarding after that downgrade. It also does not promise that every service will accept a relay address. Test registration, password reset, support contact and replies before making an alias the only route to a critical account.
For a clean exit, change each critical service to an email address you control before cancelling iCloud+ or abandoning the Apple Account. Keep the alias inventory in your password manager and in the encrypted backup export.
Failure mode: Apple Account compromise can expose or disrupt the alias directory and forwarded mail. Lost iCloud+ access can strand account usernames. Harden the Apple Account first and maintain an alias migration list.
Build offline backups that you can restore
Use the 3-2-1 rule as a starting point: keep three copies of important data, on two types of media, with one copy offsite. At least one copy should be offline, meaning disconnected from devices and networks. Cloud storage is offsite but connected to an account and service, so it is not an offline copy.
Encrypt removable backups. Store the decryption passphrase or recovery key separately. It must remain available if the phone, Apple Account, Google Account and password manager are all unavailable. Two sealed paper copies in different suitable locations may be simpler than another cloud dependency.
For a personal system, DSRA suggests this practical cadence:
- run the backup monthly, or more often if important data changes faster
- every three months, restore a sample from each copy and test the password manager export
- once a year, perform a full restore to a spare device, new user profile or clean temporary environment
- repeat the relevant test after changing devices, encryption, backup software or account recovery.
The quarterly cadence is DSRA's operational recommendation, not a regulator's fixed rule. ACSC says to test restores regularly. Its organisational guidance says to test at initial implementation, annually and after infrastructure changes.
Your restore log should record the date, backup identifier, device or environment used, files and accounts tested, decryption method, result, missing items and next action. Include photos, documents, contacts, an old and recent file, one large file, password manager export, recovery inventory and any application data you cannot recreate.
Choose safes for the media inside them. A fire rating has a tested internal temperature class and time. UL tests use different conditions for paper and electronic media, and burglary is tested separately. Check the certification label and verify the rating for electronic media, not only documents. Check water protection separately rather than assuming a fire label covers it.
Offsite means a different building you can still reach after fire, evacuation, relationship breakdown or hospitalisation. A safe in the home you have fled is unavailable. For family violence, choose the location with a support worker as part of a safety plan. Do not record the new location in a shared calendar, account or note.
Failure mode: Fire, water, theft and loss of access can affect both copies if the locations share the same event or person. Encryption can turn surviving media into unreadable material. Test each copy and each decryption route from outside the normal account.
Reject the 14-day iPhone rotation
Replacing an iPhone with different hardware can remove a compromise that persists only on that handset. It does not repair a compromised Apple Account, phone number, recovery method, trusted device or password manager. Restoring the same cloud state may also carry risky configuration or account access into the replacement.
Apple Australia's change-of-mind policy permits a return or exchange with a receipt within 14 days of receiving an Apple Store product, in original condition with all included parts, accessories and packaging. Apple may inspect the return and may refuse it if activated security features cannot be disabled. This is a voluntary retailer policy. Australian Consumer Law remedies apply to product failures and other consumer guarantees, but the ACCC says a business does not have to provide a remedy merely because a consumer changed their mind.
Repeatedly buying, using and returning a sound phone is disproportionate for a normal reader and uses a policy outside its sensible purpose. It also consumes time while leaving the main account and recovery risks untouched.
Keep iOS and apps current. Use Lockdown Mode if your threat model fits Apple's narrow audience. Restart regularly. ACSC advises business leaders to turn mobile devices off and on daily because this can remove many strains of persistent malware. Current iOS also has an automatic restart mechanism after a device remains locked for a prolonged period. A restart does not remove every implant.
If you have credible evidence of device compromise, get specialist advice. ACSC says a factory reset is the best removal method for most phone or tablet malware, while warning that backed-up files may need professional review. For a serious targeted case, rebuild the replacement as new where practical and restore only reviewed data. Remediate the Apple Account, carrier, recovery routes and other trusted devices at the same time.
Failure mode: A replacement can create false confidence while the attacker keeps an account session or recovery path. Treat device replacement as one part of incident response, not a fortnightly ritual.
Plan for loss, illness and death
Write a short recovery plan that another trusted person can follow if you are alive but unable to act. It should identify who to contact, where sealed recovery material is held, which bills keep the login number active, and what must not be disclosed. It does not need to give that person immediate access.
For Apple, add a Legacy Contact at Settings > your name > Sign-In & Security > Legacy Contact. Apple says the contact needs the access key and a death certificate to request eligible account data. Purchased media and data in iCloud Keychain, including passwords and passkeys, are excluded.
For Google, Inactive Account Manager can notify up to ten people or share selected data after a chosen inactivity period. This is separate from login recovery. For a password manager, compare documented emergency access. Bitwarden offers a trusted-contact workflow on eligible plans. 1Password Families supports family recovery, and its Emergency Kit records the information needed for access.
Test the human part. Confirm the contact has accepted, can find their key or instructions, understands the waiting period and knows whom to call. Review the plan yearly and after separation, bereavement, moving home or changing providers.
Failure mode: A trusted person can become unavailable, unsafe or technically unable to help. A death plan may expose more data than intended. Use the minimum access needed, name an alternate where the service permits it, and keep legal estate planning aligned with the digital plan.
Your stopping point
Finish Tier 1 before spending money. Add Tier 2 if phishing-resistant sign-in for root accounts is worth the cost and you can maintain two keys. Select individual Tier 3 controls only when they answer a named threat and you can support their failure path.
Do not measure your safety by the number of products you own. Measure it by whether your root accounts have unique credentials and strong MFA, whether recovery is harder to abuse but still survivable, and whether you have restored your backup successfully.