Guide · Updated October 5, 2026

Small business Android security checklist

A small business Android security checklist starts with a 6-digit PIN and short auto-lock, required encryption, security updates under 90 days old, Google Play Protect always on, and apps from outside Google Play blocked. Then block USB file transfer and developer options, protect data and websites, add factory reset protection, give admins the least access they need, review the audit log, and offboard leavers the same day.

This checklist is written so an IT consultant can hand it to a small business client, or an owner can work through it alone. It covers company-owned Android phones and tablets. Each item says what to set, why it matters and where it lives in NounDesk.

Most items are already set in NounDesk’s Standard Business policy template. Where the template leaves something off, the item says so. The full list of options is in the policy settings reference.

Device settings

1. Screen lock and auto-lock

Set: a 6-digit PIN or stronger, with auto-lock after 5 minutes or less. For phones holding sensitive data, use a strong password (Android 12+) and 2 minutes.

Why: a lost phone without a lock gives the finder your email, customer list and every signed-in app.

In NounDesk: Security card of the policy. Standard Business sets a 6-digit PIN and 5 minutes. See security policies.

2. Storage encryption

Set: encryption required.

Why: encrypted storage cannot be read by removing the memory chip or connecting the phone to a computer.

In NounDesk: on by default in every template. Device Trust checks it on each phone. See Device Trust.

3. Security updates and patch age

Set: system updates installed in an overnight maintenance window (for example 01:00 to 05:00), and a monthly check of patch age.

Why: most Android attacks use flaws that already have a fix. A phone more than 90 days behind is exposed to them.

In NounDesk: Updates card of the policy, and the patch age chart in reports. Device Trust warns when a phone’s security update is over 90 days old. Some phones stop receiving updates from the manufacturer; replace those. Background: how to keep company Android phones updated.

4. Google Play Protect

Set: always on.

Why: Play Protect scans installed apps for known harmful behavior. Employees should not be able to turn it off.

In NounDesk: Security card, “Always on (recommended)”. Device Trust checks it.

5. Apps from unknown sources

Set: apps from outside Google Play blocked.

Why: most Android malware arrives as a downloaded file or from another app store, often after a convincing message.

In NounDesk: Security card, blocked in every template. Install work apps through managed Google Play instead. See also how fake Play installs work.

6. USB data transfer

Set: file transfer blocked at minimum. On Android 12 or newer, block all data transfer so the cable only charges.

Why: a USB cable is the simplest way to copy files off an unlocked phone, or onto it.

In NounDesk: Security card. Standard Business blocks file transfer; Maximum Security blocks all data transfer.

7. Developer options and USB debugging

Set: developer options blocked.

Why: developer options include USB debugging, which can be used to install apps and copy data around your policy.

In NounDesk: Security card, blocked in every template. Device Trust checks both developer options and USB debugging.

8. Factory reset by employee

Set: blocked.

Why: a phone reset from Settings drops out of management and loses its policy.

In NounDesk: Security card, blocked in every template.

Data and web

9. Data protection: printing, storage and screenshots

Set: for phones that handle customer or patient data, block printing (Android 9+), SD cards and USB drives, and screenshots.

Why: these are the everyday ways data leaves a phone without anyone meaning harm: a screenshot shared to the wrong chat, a file copied to a memory card.

In NounDesk: Security card. Maximum Security turns them all on. See data protection.

10. Website filtering in Chrome

Set: block a list of risky or off-task sites, or allow only the sites staff need (up to 1,000). Keep Incognito off and other browsers blocked so the rules cannot be bypassed. For whole categories such as adult or gambling sites, add Private DNS filtering (Android 10+).

Why: many phishing pages and malware downloads start in the browser.

In NounDesk: Website filtering card. Filtering applies in Google Chrome, not in other apps. See website filtering.

Theft and recovery

11. Factory reset protection

Set: add up to 10 trusted company Google accounts to each policy.

Why: without this, a thief can factory-reset a stolen phone from the recovery screen and use or sell it. With it, the phone will not set up until one of your accounts signs in.

In NounDesk: Security card. The Standard Business template leaves the list empty, so add your accounts. When you erase from NounDesk, keep “Keep factory reset protection” ticked. See factory reset protection.

12. Lost mode

Set: a written process: who staff call, and how fast lost mode is turned on. Set location services to always on in the policy so a lost phone can report where it is.

Why: the first hour decides whether a phone is returned, recovered or erased.

In NounDesk: Lost mode locks the screen with your message and number and reports location only while the phone is in lost mode. See lost-device recovery and employee lost a work phone?

People and access

13. Roles and least privilege

Set: one or two Owners. Give office staff who lock and reboot phones the Operator role, which cannot erase devices or change policies. Give an accountant or outside consultant Viewer (read-only).

Why: the fewer people who can erase every phone at once, the smaller the damage from a mistake or a compromised password.

In NounDesk: four roles, enforced on the server as well as in the screen. See team and roles and who should have admin access.

14. Audit log

Set: a monthly review of the audit log, and a CSV export kept with your records.

Why: you should be able to answer “who erased that phone?” or “who changed the policy?” without guessing.

In NounDesk: the audit log records every meaningful action: who, when, what it affected and whether it worked. See reports and audit log.

15. Offboarding

Set: collect the phone on the last day, deactivate the employee and choose reassign, keep unassigned, retire or erase. Remove their NounDesk access if they had a role.

Why: former staff with a working company phone, or admin access, are one of the most common gaps in small businesses.

In NounDesk: nothing happens automatically; you choose each step. See retire and offboard and groups and employees.

16. Phishing basics for staff

Set: a five-minute talk, repeated twice a year, covering four rules:

  • Never install an app from a link in a text, email or chat. Work apps arrive by themselves.
  • Never type a work password into a page you reached from a message. Open the site or app directly.
  • A message that is urgent, about money or about a locked account is a reason to call the sender back on a known number.
  • Report a strange message or a lost phone straight away. Nobody gets in trouble for reporting.

Why: settings stop most attacks, but a convinced employee can still hand over a password.

In NounDesk: device management cannot stop a person typing a password into a fake page. Blocking unknown sources and filtering websites removes two of the easiest routes. For how to introduce the rules, see how to explain device management to employees.

Check the result

After you publish the policy, open the dashboard. Each phone gets a Device Trust rating of Trusted, At risk, Not trusted or Not reported yet, with the reason and the fix in plain English. The rating updates every time the phone checks in. It reports problems; it does not block a phone from signing in to apps. See Device Trust.

For the rest of the device lifecycle, use the Android device management checklist. For how NounDesk handles your own data, see security. NounDesk is $1.50 per device per month with every feature on this list included; see pricing.

More guides

Frequently asked questions

What is the most important Android security setting for a small business?

A required screen lock with a short auto-lock time. Most real-world incidents start with a lost or unattended phone, and a lock stops casual access to email, customer data and saved passwords.

How old can a phone's security update be?

Treat anything over 90 days as at risk. NounDesk's Device Trust check warns after 90 days, and the patch age report shows which phones are behind.

Can I enforce these settings without an IT department?

Yes. Every setting on this list is a choice in a NounDesk security policy, written in plain English. Start from the Standard Business template and change only what your business needs.

Does this checklist cover personal phones?

No. It is written for company-owned Android phones and tablets. NounDesk does not manage personal (BYOD) phones or work profiles today.

Ten phones. Ten minutes. Protected.

Start a 14-day free trial, no card required. Or load a sample fleet in demo mode first.