You know that sinking feeling when you realize your phone is missing.
That happened to a friend of mine. She panicked. Her life revolved around her phone. She posted pictures to Instagram, texted friends all day, and made videos for TikTok. More importantly, her phone stored personal photos she never intended to be public, and she used apps for her bank account, credit cards, utilities, and everything else. For more, see The Art of Invisibility and practical home computer security.
Worst of all, she got tired of entering a PIN and never set up biometrics. Her phone was wide open to anyone.
Someone drained her bank account and credit cards, dropped her personal photos on explicit websites, and deleted her social media accounts. Just like that, her life changed for the worse.
Stories like hers are galling, because every piece of it was preventable with settings that take ten minutes. Writers worry me in particular. Plenty of them guard a manuscript like it’s their firstborn and then leave the phone holding it unlocked on a coffee shop table.
What She Did Wrong
Two-factor prompts are less inconvenient than a drained bank account and your private photos posted online.Share on X
She didn’t practice basic phone and internet security. For more, see qr codes for authors 2025. She didn’t protect her phone with a PIN or biometrics.
For more, see AI writing prompts that actually work (and why yours don’t). Her apps used simple passwords. She set her phone as the source for two-factor authentication when she used it at all. Every online account had easy-to-guess passwords. She didn’t back up her phone data or her social media accounts. The list goes on.
None of it was exotic. Every one of those mistakes is common, and the thief who picked up her phone didn’t need any skill to take advantage of it.
Why Does Phone Security Matter for Writers?
Writers store more sensitive material on their phones than most people realize.
Notes, outlines, drafts, client communications, interview recordings, manuscript files, contract details. For ghostwriters, the stakes are higher because you’re holding client information and unpublished work that isn’t yours to lose. If I lost a client’s interview material to a thief, I’d have to call that client and explain it, and I can’t think of a call I’d hate making more.
I spent over twenty years in IT operations, including managing security compliance for a major retailer. The security principles that protect corporate networks are the same ones that protect your phone. Most people don’t follow them because they seem inconvenient. They’re less inconvenient than having your bank account drained and your private photos posted online.
What phone security basics do most people skip?
Heard elsewhere
The preparedness argument behind all of this, and why cloud backup is the step people most often skip, is the subject of Richard’s conversation on the Dr. Briar Lee Mitchell Show.
Lock your phone. Use a PIN, passcode, or biometric lock. Fingerprint and facial recognition take less than a second. There’s no excuse for leaving your phone unlocked. This is the single easiest security measure that prevents the most damage.
Use strong, unique passwords for every app. Every app on your phone that stores data or connects to an account needs its own password. Not your dog’s name. Not your birthday. Not the same password you use for everything else. Use a password vault like Sticky Password or 1Password to manage them. You remember one master password and the vault handles the rest.
Turn on two-factor authentication everywhere. Platforms like Gmail, Facebook, WordPress, and most banking apps offer two-factor authentication. It means that even if someone cracks your password, they still need a second verification to get in. Use an authenticator app instead of SMS for the second factor, because SMS can be intercepted through SIM swapping.
Update everything. Operating system updates and app updates include security patches for newly discovered vulnerabilities. Delaying updates because they’re annoying is like leaving your front door unlocked because locking it takes two seconds. Update your phone. Update your apps. Do it when prompted.
Back up your data. Use cloud services like Google Drive, Dropbox, or iCloud for regular backups. If your phone is lost, stolen, or destroyed, your drafts, manuscripts, notes, and client files should exist somewhere other than on that device. Backup isn’t optional for anyone who stores work on their phone.
In August 2012, hackers tore apart the digital life of Mat Honan, a Wired writer, in about an hour. They were after his Twitter handle, @mat. They found his home address in domain registration records, got Amazon’s support staff to expose the last four digits of his credit card, and gave those digits to Apple support, which reset his iCloud password for them.
With iCloud in hand, they remotely wiped his iPhone, his iPad and his MacBook, then got into his Gmail and took over his Twitter account. The MacBook had no current backup, so irreplaceable family photos went with it. Honan later walked NPR through the whole attack.
Honan was a technology writer, and an ordinary backup would have saved those photos. I think about his story whenever a writer tells me a manuscript exists only on a phone. A stranger who wanted a Twitter handle wiped out a family’s pictures to get it. That is vile.
The Threats Most Writers Don’t Think About
Phishing. Emails and texts that look legitimate but are designed to steal your credentials. They’ll pose as your bank, your email provider, or a client. The message creates urgency: “your account has been compromised, click here immediately.” I have nothing but contempt for the people who write these. They go after panic because a panicked person clicks before thinking. Don’t click. Go directly to the website or app instead. If the alert is real, you’ll see it there.
Public Wi-Fi. Coffee shop Wi-Fi, hotel Wi-Fi and airport Wi-Fi are all insecure. Anyone on the same network can potentially intercept your data. If you work in public spaces, use a VPN. It encrypts your connection so that even on an open network, your data stays private.
Juice jacking. Public USB charging stations at airports and hotels can be used to inject malware or steal data from your phone. The charging cable is also a data cable. Use your own charger plugged into a wall outlet, or carry a portable power bank. For more on scams, passwords, and staying safe online, hear Richard on Aging Info Radio. If you must use a public USB port, a USB data blocker prevents data transfer while allowing the charge.
Bluetooth. Turn it off when you’re not using it. Bluetooth connections can be exploited to access your phone without your knowledge. If you’re not actively connected to headphones or a speaker, there’s no reason to leave it on.
What should be on a writer’s phone security checklist?
Print this out or screenshot it. Go through it today and fix anything that isn’t done.
Set your phone to unlock with a PIN, passcode, or biometrics. Lock your screen when not in use. Keep your operating system and all apps updated. Install security updates immediately. Back up your data to cloud storage or external devices. Enable Find My Phone or the equivalent so you can locate or remotely wipe a lost device. Download apps only from official app stores. Calls get a rule from me too. If you call from a bare number and don’t leave a voicemail, you don’t get a call back, and if you do it twice, you get blocked. It’s amazing how much junk that’s stopped. Only a couple of my customers ever called me that way, and I told them not to, though if I know who’s calling, I’ll treat it differently.
Don’t fall for phishing attempts in texts or emails. Log out of banking and payment sites after use. Don’t leave your phone unattended in public. Install a call screening app like Robokiller to reduce spam calls. Don’t charge your phone using public USB ports. Enable two-factor authentication on every account that supports it. Turn off Bluetooth when not in use. Don’t jailbreak or root your device. Use a VPN on public Wi-Fi. Use a password vault like Sticky Password or 1Password for all your credentials.
For Ghostwriters
Ghostwriters carry client information that goes beyond their own work. Interview recordings, manuscript drafts, emails with confidential details, non-disclosure agreements: all of it lives on your phone or is accessible through it. A security breach lands on your client, your professional reputation, and your legal liability along with you.
Treat client data with the same seriousness a lawyer treats privileged communications. Encrypt sensitive files. Use secure messaging for confidential discussions. And make sure your phone security is tight enough that if your device disappears, you can wipe it remotely before anyone gets through your lock screen.
A ghostwriter who loses a client’s unpublished story to a stolen phone has broken the promise the whole job rests on. I’d consider that unforgivable in my own practice, and I’d expect any client to see it the same way.
Frequently Asked Questions
Cybersecurity Ghostwriting
I spent 33 years in enterprise security before writing about it. If your security expertise belongs in a book, I ghostwrite it with the field time to get it right. Explore Cybersecurity Ghostwriting.
