Setting the next column
CCSetting the next column
CCHow To / Strong
CISA's mobile security guidance covers more than a screen lock: a carrier PIN to block SIM swapping, phishing-resistant sign-in, and an app-permission review most people never do. The order matters as much as the steps.

The argumentCISA's mobile security guidance treats a new phone setup as a sequence, not just a checklist: update the software first, secure the account you're signing into before restoring anything, set a carrier PIN to block SIM-swapping, and review app permissions after the fact rather than accepting whatever an app requests by default. Doing these out of order (like restoring apps before securing the account) can carry old weaknesses forward onto the new device.
I just got a new phone. Beyond setting a passcode, what should I actually do before I start using it normally?
CISA recommends setting a PIN directly with your mobile carrier (a Telco PIN), a step most people never take, specifically to block SIM-swapping attacks where someone hijacks your phone number to intercept SMS codes.
Update software before restoring apps and data, since out-of-date software can carry known, exploitable vulnerabilities onto the new device from the first minute it's active.
Review app permissions after setup rather than accepting default requests; CISA specifically flags location, camera, and microphone access as the categories worth checking first.
Most new-phone setup advice stops at "set a passcode." CISA's actual mobile security guidance goes considerably further, and includes at least one step that catches most people off guard: contacting your mobile carrier directly to set an account PIN, separate from your phone's own lock screen. That step exists because of a specific attack, SIM swapping, that a screen lock cannot defend against at all.
Out-of-date software can carry known, exploitable vulnerabilities onto the new device from the first minute it's active, per CISA's guidance on app and OS updates.
Enable a strong sign-in method (a passkey where supported, or app-based multifactor authentication) on your primary account before restoring anything to the new phone.
Contact your mobile carrier to set a PIN or passcode on the account itself, which CISA specifically recommends to block SIM-swapping, where an attacker convinces a carrier to transfer your number to a device they control.
Restoring a full backup carries forward every app permission and setting from the old phone, including ones you may not have reviewed in years.
Check location, camera, and microphone access specifically for each app, rather than accepting whatever was granted by default or carried over from the old device.
SIM swapping is worth explaining directly, since it's the reason the carrier-PIN step exists at all. An attacker who has gathered enough of your personal information can call or contact your mobile carrier, impersonate you, and convince a representative to transfer your phone number to a SIM card they control. Once that happens, any account that uses SMS text messages for account recovery or two-factor authentication is exposed, because the attacker is now receiving those texts, not you. A carrier account PIN adds a second piece of information an attacker needs beyond what's typically available through basic impersonation, which is exactly the gap CISA's guidance is closing.
The account-before-device sequencing matters for a related reason. A new phone is not a fresh start if the account it signs into is still using a weak recovery method, a reused password, or SMS-only two-factor authentication. CISA's guidance recommends phishing-resistant authentication (passkeys or hardware security keys) specifically because it removes the SMS interception risk entirely, not just the SIM-swap variant of it. Setting this up on the account before restoring anything to the new device means the new phone inherits the stronger setup, instead of temporarily reactivating the weaker one during the transfer.
Before restoring apps or signing into accounts.
Do this before, not after, restoring the new phone from backup.
This is separate from your phone's screen lock and specifically blocks SIM-swap attempts.
Check Settings > Privacy on both iOS and Android rather than accepting defaults.
A factory reset should follow, not precede, transferring everything you need off it.
A carrier account PIN, set directly with your mobile provider, is a specific CISA recommendation that blocks SIM-swapping in a way a phone's own screen lock cannot.
Secure your accounts (phishing-resistant sign-in) before restoring the new device, so the phone inherits the stronger setup rather than temporarily reactivating a weaker one.
Review app permissions, especially location, camera, and microphone, after setup rather than accepting whatever carried over from the old phone.
No. A carrier PIN is set directly with your mobile provider (over the phone or through their app/website) and protects your account with the carrier itself, including changes like SIM transfers. Your phone's lock screen passcode only protects the device.
The carrier PIN and account-security steps are relevant regardless of whether it's a new line or a device upgrade on an existing number, since SIM-swapping targets the phone number and account, not the specific hardware.
Sources and further reading
CISA's primary mobile device security guidance document, source for the carrier PIN, software update, and phishing-resistant authentication recommendations.
CISA's specific guidance on reviewing and restricting app permissions, particularly location, camera, and microphone access.
About the byline
Sources, review method, and commercial relationships appear with each story. Reach the desk at editorial@culturecolumn.com.