New Laptop or Phone? Complete Cybersecurity Checklist Before You Go Online (2026)

You just unboxed your new laptop or phone. The screen is pristine. The battery is at 80%. You're excited to set it up, install your apps, and get back to work. Stop. The next 30 minutes are the most important security window this device will ever have. Every setting you accept, every account you connect, and every app you install during initial setup creates a security baseline that will persist for the entire life of the device.  Get it wrong now, and you'll spend months patching holes you didn't know you created. Get it right, and this device will be more secure than 90% of the machines on your network. This is a sequential checklist. Follow it in order, during your first setup session, before you connect to any untrusted network or install any non-essential software. Each step takes 1–5 minutes. The entire process takes roughly 30–45 minutes. For the foundational concepts behind these steps (why passwords matter, how phishing works, what MFA does), see our Cybersecurity for Beginners guide. This article focuses purely on the hands-on setup process. Phase 1: Before You Connect to the Internet These steps happen during the out-of-box experience (OOBE), before your device touches the internet. This is critical because an unpatched device connected to a network is immediately discoverable by automated scanners. Step 1: Inspect the Physical Device and Packaging Before powering on, verify that the packaging seal was intact when you received it. If the shrink wrap was broken, the box was resealed, …

TechVash infographic: A digital checklist for securing a new device, with shields, a padlock, a laptop, and a phone.

You just unboxed your new laptop or phone. The screen is pristine. The battery is at 80%. You’re excited to set it up, install your apps, and get back to work.

Stop.

The next 30 minutes are the most important security window this device will ever have. Every setting you accept, every account you connect, and every app you install during initial setup creates a security baseline that will persist for the entire life of the device. 

Get it wrong now, and you’ll spend months patching holes you didn’t know you created. Get it right, and this device will be more secure than 90% of the machines on your network.

This is a sequential checklist. Follow it in order, during your first setup session, before you connect to any untrusted network or install any non-essential software. Each step takes 1–5 minutes. The entire process takes roughly 30–45 minutes.

For the foundational concepts behind these steps (why passwords matter, how phishing works, what MFA does), see our Cybersecurity for Beginners guide. This article focuses purely on the hands-on setup process.

Phase 1: Before You Connect to the Internet

These steps happen during the out-of-box experience (OOBE), before your device touches the internet. This is critical because an unpatched device connected to a network is immediately discoverable by automated scanners.

Step 1: Inspect the Physical Device and Packaging

Before powering on, verify that the packaging seal was intact when you received it. If the shrink wrap was broken, the box was resealed, or the device shows signs of prior activation, return it. Supply chain tampering, where malicious hardware or firmware is inserted before the device reaches you, is rare for consumer purchases but increasingly documented in 2026, particularly for devices ordered from third-party marketplace sellers rather than authorized retailers.

Action: Buy directly from the manufacturer or an authorized retailer. If the packaging looked suspicious, don’t risk it.

Step 2: Power On and Decline Data Sharing Prompts

During initial setup, both Windows 11 and macOS will ask you to enable telemetry, diagnostics, and “personalized experiences.” Android and iOS will prompt you to share usage data with Google or Apple.

Decline all of them. You can always enable specific features later if needed. The default “yes to everything” approach sends device identifiers, usage patterns, location data, and crash reports to the manufacturer and their partners before you’ve had a chance to evaluate what you’re sharing.

Windows 11: Choose “No” on the diagnostic data screen. Select “Basic” if “No” isn’t available.
macOS: Uncheck “Share Mac Analytics” and “Share with App Developers” in System Settings > Privacy & Security.
Android: Skip “Help improve Android” and decline Google’s personalized ad ID during setup.
iOS: Choose “Don’t Share” when prompted for analytics sharing.

Step 3: Create a Local Account First (Laptops)

Windows 11 aggressively pushes you to sign in with a Microsoft account during OOBE. While a Microsoft account enables cloud sync and some convenience features, it also links your device identity to your online profile and enables data synchronization before you’ve configured your security settings.

Recommended approach: Create a local account first. Complete all security configurations. Then, if you want Microsoft account integration, sign in afterward with your security settings already in place.

How to bypass the Microsoft account requirement in Windows 11 (2026):
During the network connection screen, press Shift + F10 to open Command Prompt. Type OOBE\BYPASSNRO and press Enter. The device will restart and offer a “I don’t have internet” option, allowing local account creation.

macOS: Apple allows local account creation by default during setup. Simply create your user account without signing into iCloud initially.

Step 4: Set a Strong Device Passcode or Password

Your device’s login credential is the first line of defense against physical access. If someone steals your laptop or phone, this is the only thing standing between them and your data.

Laptops: Set a password of at least 14 characters. Use a passphrase (four random words separated by spaces or hyphens) rather than a complex string you’ll forget. Do not use your Microsoft or Apple account password.

Phones: Set a 6-digit PIN minimum. An alphanumeric passcode is stronger but less practical for frequent unlocking. Avoid pattern locks on Android — they’re easily observed and replicated from smudge marks on the screen.

Critical: Do this before enabling biometrics. Biometrics (fingerprint, face recognition) are a convenience layer on top of your passcode, not a replacement. Your device will require the passcode after restarts, after 72 hours of inactivity, and during security-sensitive operations.

Phase 2: First Connection and Updates

Step 5: Connect to a Trusted Network Only

Connect to your secured home Wi-Fi — not a public network, not a hotel network, not a coffee shop. Your device is about to download gigabytes of updates, and you want that traffic on a network you control.

If you’re setting up the device away from home, use your phone’s cellular hotspot instead of public Wi-Fi. The cellular connection is encrypted and far more difficult to intercept.

Step 6: Run All Operating System Updates Immediately

Before installing any apps, connecting any accounts, or configuring any settings, update the operating system to the latest available version.

Why this is step one: Your new device may have been manufactured weeks or months ago. The OS version installed at the factory likely has known vulnerabilities that have since been patched. Connecting to the internet with an unpatched OS exposes you to exploits that automated scanners actively probe for.

Windows 11: Settings > Windows Update > Check for updates. Install everything, restart, and repeat until no updates remain. This may require 2–3 restart cycles.
macOS: System Settings > General > Software Update. Install all available updates.
Android: Settings > System > Software update. Note that Android update availability depends on your device manufacturer and carrier — some budget phones ship with OS versions that are already 6–12 months behind.
iOS: Settings > General > Software Update. iPhones typically ship with relatively current iOS versions, but always verify.

Do not skip this step. Everything else on this checklist is less effective if your OS has unpatched vulnerabilities.

Step 7: Update All Pre-Installed Applications

After the OS is current, update every pre-installed application. Laptops ship with OEM software (Dell SupportAssist, HP Support Assistant, Lenovo Vantage) and bundled utilities that often have their own update mechanisms. Phones ship with carrier apps and manufacturer overlays that may have known vulnerabilities.

Windows: Open the Microsoft Store > Library > Get updates. Then open each OEM utility and check for firmware and driver updates.
macOS: Open the App Store > Updates. Also check for firmware updates in System Settings > General > Software Update.
Android/iOS: Open the Play Store or App Store > Manage apps > Update all.

Phase 3: Security Configuration

Step 8: Enable Full-Disk Encryption

Full-disk encryption ensures that if your device is lost or stolen, the data on its storage drive is unreadable without your passcode. Without encryption, a thief can remove the storage drive, connect it to another computer, and read all your files.

Windows 11:

  • BitLocker (Pro/Enterprise editions): Search “BitLocker” in the Start menu and enable it for your system drive. Save the recovery key to a secure location (your password manager or a printed copy stored in a safe — not a text file on the same device).
  • Device Encryption (Home edition): Settings > Privacy & Security > Device encryption. This is a simplified version of BitLocker that’s available on most modern Windows 11 Home devices with a TPM 2.0 chip.

macOS: System Settings > Privacy & Security > FileVault. Turn it on. This encrypts your entire startup disk. Save the recovery key securely.

Android: Encryption is enabled by default on all devices running Android 10+. Verify in Settings > Security > Encryption & credentials. If it says “Encrypted,” you’re covered.

iOS: Encryption is automatic when a passcode is set. No additional action required.

Step 9: Enable Biometric Authentication

Now that your passcode and encryption are configured, enroll your biometrics for convenience.

Windows 11: Settings > Accounts > Sign-in options. Set up Windows Hello Face (if your laptop has an IR camera) or Windows Hello Fingerprint (if your device has a fingerprint reader).

macOS: System Settings > Touch ID & Password. Enroll at least two fingerprints.

Android: Settings > Security > Biometrics. Enroll your fingerprint and/or face unlock. Note that face unlock on many Android devices uses the front camera (2D) rather than a depth sensor, making it less secure than fingerprint. Use fingerprint as your primary biometric.

iOS: Settings > Face ID & Passcode (or Touch ID & Passcode). Complete enrollment.

Important: Biometrics are convenient but not infallible. Your passcode remains the master credential. Law enforcement in many U.S. jurisdictions can compel biometric unlocking (fingerprint or face) but cannot legally compel you to reveal a passcode. If this concerns you, disable biometrics before crossing borders or entering sensitive legal situations.

Step 10: Configure the Built-In Firewall

Windows 11: Windows Defender Firewall is enabled by default, but verify it’s active for all network profiles (Domain, Private, Public). Search “Windows Defender Firewall” in the Start menu and confirm all three profiles show “On.” Set your home network to “Private” and all other networks to “Public” by default.

macOS: The built-in firewall is disabled by default. Enable it in System Settings > Network > Firewall. Turn on “Block all incoming connections” for maximum protection, or use the default “Automatically allow built-in software to receive incoming connections” for a balance of security and convenience.

Android/iOS: Mobile operating systems handle firewall functions at the OS level. No user configuration is needed.

Step 11: Set Up Find My Device and Remote Wipe

If your device is lost or stolen, you need the ability to locate it, lock it, or erase its data remotely.

Windows 11: Settings > Privacy & Security > Find my device. Turn it on. This requires a Microsoft account linked to the device.

macOS: System Settings > Apple ID > iCloud > Find My Mac. Enable it. This requires an Apple ID.

Android: Settings > Security > Find My Device. Ensure it’s enabled and linked to your Google account.

iOS: Settings > Apple ID > Find My > Find My iPhone. Enable “Find My network” (allows location tracking even when the device is offline or powered down on iPhone 11 and later) and “Send Last Location” (sends the device’s location to Apple when the battery is critically low).

Critical: After enabling Find My Device, test the remote lock feature from another device or a web browser. Verify that you can actually locate and lock the device before you need it in an emergency.

Phase 4: Account and App Setup

Step 12: Install a Password Manager Before Creating Any Accounts

Before you start signing into email, cloud storage, social media, and work tools, install your password manager. This ensures that every account you set up on the new device gets a unique, strong password from the start — rather than defaulting to reused passwords out of convenience.

If you don’t have a password manager yet, see our Best Free Cybersecurity Tools for Small Business guide for recommendations. Bitwarden is free and works across all platforms.

Action: Install the password manager app and browser extension. Log in with your master password. Verify that autofill is working in your browser before proceeding.

Step 13: Enable MFA on Every Account You Connect

As you sign into each account on your new device, enable multi-factor authentication if it isn’t already active. Prioritize these accounts:

  1. Email (your master key to password resets)
  2. Cloud storage (OneDrive, Google Drive, iCloud)
  3. Financial accounts (banking, payment apps)
  4. Work tools (Slack, Microsoft 365, CRM)
  5. Social media

Use an authenticator app or passkeys rather than SMS codes.

Step 14: Audit App Permissions Before Installing

When you install apps on your new device, each one will request permissions — camera, microphone, location, contacts, storage, notifications. The default impulse is to tap “Allow” on everything to get past the prompts quickly. Resist this.

The principle of least privilege: Grant each app only the permissions it needs to function. A calculator app doesn’t need access to your contacts. A weather app doesn’t need your precise location 24/7. A note-taking app doesn’t need microphone access.

Android: Settings > Privacy > Permission manager. Review each permission category and revoke access for apps that don’t need it. Use “Allow only while using the app” for location and camera permissions whenever possible.

iOS: Settings > Privacy & Security. Review each permission category. iOS 17+ provides a visual indicator (colored dots in the status bar) when an app is using your camera or microphone.

Windows 11: Settings > Privacy & Security. Review app permissions for camera, microphone, location, and file system access.

macOS: System Settings > Privacy & Security. Review which apps have access to Full Disk Access, Accessibility, Screen Recording, and other sensitive permissions.

Step 15: Remove Bloatware and Unnecessary Pre-Installed Apps

New devices ship with pre-installed software you didn’t ask for and don’t need. On Windows laptops, this includes trial antivirus programs (McAfee, Norton), manufacturer utilities, promotional apps, and browser toolbars. On Android phones, it includes carrier apps, manufacturer overlays, and sponsored games.

Why this matters: Every installed application is a potential attack surface. Bloatware runs background processes, consumes system resources, and may contain vulnerabilities that attackers can exploit. In 2026, several pre-installed Android apps from major manufacturers were discovered to contain adware and data-harvesting code that operated without user consent.

Windows 11: Settings > Apps > Installed apps. Uninstall everything you don’t recognize or need. Pay special attention to trial antivirus programs — they often conflict with Windows Defender and create security gaps during the transition period.

macOS: Open Finder > Applications. Drag unnecessary apps to Trash. macOS ships with relatively little bloatware, but check for third-party utilities you don’t need.

Android: Settings > Apps. Disable or uninstall carrier and manufacturer apps you don’t use. Some pre-installed apps can’t be fully removed without rooting the device, but you can disable them to prevent background activity.

iOS: Long-press app icons and remove apps you don’t need. iOS has minimal bloatware, but remove any pre-installed apps you won’t use (Stocks, Tips, Podcasts, etc.) to reduce the attack surface.

Phase 5: Ongoing Security Habits

Step 16: Configure Automatic Updates for Everything

You updated the OS and apps during setup. Now ensure they stay updated automatically going forward.

Windows 11: Windows Update is automatic by default. Verify that “Receive updates for other Microsoft products” is enabled in Advanced options. Set active hours so updates don’t restart your device during work.

macOS: System Settings > General > Software Update > Automatic Updates. Enable “Install macOS updates” and “Install application updates from the App Store.”

Android: Settings > System > Software update > Auto download over Wi-Fi. Also enable auto-update for apps in the Play Store.

iOS: Settings > General > Software Update > Automatic Updates. Enable both “Download iOS Updates” and “Install iOS Updates.” Enable App Store auto-updates in Settings > App Store.

Step 17: Set Up Your Backup

Configure your backup solution during initial setup while your device is still clean and organized. Waiting until you’ve accumulated months of data means your first backup will take hours and you’ll have no recovery point if something goes wrong in the meantime.

Step 18: Create a Recovery Key and Store It Securely

Your device encryption, password manager, and cloud accounts all have recovery keys or backup codes. If you lose access to your primary authentication method, these keys are the only way to recover your data.

Action: Write down or print the following recovery keys and store them in a physical safe or a secure offline location:

  • BitLocker/FileVault recovery key
  • Password manager master recovery code
  • MFA backup codes for your email and primary accounts
  • Apple ID or Google Account recovery codes

Do not store these keys on the device they protect. Do not store them in a cloud note that requires the same account to access. A printed copy in a fireproof safe is the most reliable option.

Quick-Reference Checklist

Print this or screenshot it for your next device setup:

#StepTime
1Inspect packaging and device1 min
2Decline data sharing prompts2 min
3Create local account first2 min
4Set strong device passcode1 min
5Connect to trusted network only1 min
6Run all OS updates10–20 min
7Update pre-installed apps5 min
8Enable full-disk encryption2 min
9Enroll biometrics2 min
10Configure firewall2 min
11Set up Find My Device2 min
12Install password manager3 min
13Enable MFA on all accounts5–10 min
14Audit app permissions3 min
15Remove bloatware3 min
16Configure automatic updates2 min
17Set up backup5 min
18Store recovery keys securely5 min
Total~45 min

Frequently Asked Questions

Should I install a third-party antivirus on my new Windows laptop?

Not immediately. Windows Defender is active by default and provides strong baseline protection. Installing a third-party antivirus alongside Defender can cause conflicts and performance issues. If you decide to use a paid security suite, uninstall any trial antivirus that came pre-installed (McAfee, Norton) first, then install your chosen solution. For a detailed comparison, see our Is Free Antivirus Enough? guide.

Is it safe to restore from a backup of my old device?

It depends on the security state of your old device. If your previous device was well-maintained with current updates and no known infections, restoring from its backup is generally safe. If your old device was compromised, outdated, or loaded with bloatware, you’re importing all those problems onto your clean new device. When in doubt, set up the new device fresh and selectively transfer only the files you need.

Should I enable cloud sync during initial setup?

Delay cloud sync until after you’ve completed this checklist. Enabling OneDrive, iCloud, or Google Drive sync during OOBE means your device immediately begins uploading files to the cloud before you’ve configured encryption, permissions, and security settings. Set up cloud sync as the final step after everything else is locked down.

How do I securely dispose of my old device after setting up the new one?

Perform a factory reset with data erasure. On Windows, use “Reset this PC” with the “Remove everything” and “Clean the drive” options. On macOS, use Erase All Content and Settings (Apple Silicon) or Disk Utility to securely erase the drive (Intel). On Android, use Factory Data Reset with the “Erase all data” option. On iOS, use Erase All Content and Settings. Remove the device from your Find My Device account and revoke its access tokens from your password manager and MFA settings.

Do I need to repeat this process for every new device?

Yes. Every new device — whether it’s a replacement laptop, a new phone, a tablet for your child, or a work-issued machine — should go through this checklist. The specific steps vary slightly by operating system, but the principles are identical: update first, encrypt, lock down, then connect.

About TechVash

Your go-to source for the latest in technology,
AI, gadgets, cybersecurity and digital trends.
Fast news. Deep insights.

Share the post

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *