CYBER WELFARE

Protect your Digital Privacy

Impact of leaving your screen unlocked: what is reachable

There is an important difference between this unit and the one on the unlock code, and it is worth making clear straight away.

The code protects against people who do not know it. A screen left unlocked protects against nobody: whoever is standing in front of the device at that moment has exactly the access you have. They have nothing to get past, nothing to guess, nothing to know.

It is the only scenario in this series where the exposure is total and instant. This post looks at what that means concretely, across the three aspects by which the security of any information is measured.

It expands on the recommendation screen lock timeout.

The factor that governs everything: duration

Before the impacts, the variable that determines them — and it is the only one in this series measured in seconds.

Lock timeWhat it allowsHow often the scenario applies
Immediate / 15 secondsPractically nothing: the window closes before anybody sits downThe window exists but is unusable
1–2 minutesReading messages, opening an app, looking at photosIt covers a coffee break
5 minutesSending messages, changing settings, installing somethingIt covers a short meeting, a step out of the office
15 minutes or moreEverything you could do, unhurriedIt covers any ordinary absence

The progression is not gradual: past two minutes you move from reading to acting. Below that threshold somebody can look at something; above it, they can do something.

1. Confidentiality: what becomes readable

Confidentiality is the guarantee that information stays accessible only to those entitled to it.

A practical example

The computer stays unlocked in a shared space while you go for a coffee. The mail is open, the password vault is unlocked, work documents are on the screen.

What the incident looks like

Nothing technical is needed: looking is enough. And in a few seconds a great deal gets read — the subject lines of visible emails, the names of open documents, the conversations under way, the calendar.

With a few seconds more, the password vault opens, which on an unlocked device is often reachable with no further prompt. At that point the exposure no longer concerns the device: it concerns every account it holds.

What to watch for

  • the device found in a different position from how you left it;
  • open applications you do not remember using;
  • messages showing as read that you did not open;
  • the screen still on when it should have gone dark.

What to do

A very short lock, and manual locking every time you get up. On a computer it is a keyboard shortcut: learning it is worth more than any automation.

2. Integrity: what can be done in your name

Integrity is the guarantee that nobody alters your data or acts in your place.

A practical example

An email goes out from your address from an open computer. It is not a forged message: it is genuinely yours, with your signature, from your account, inside a conversation already under way.

What the incident looks like

This is where the two-minute threshold shows. With the device open, somebody can:

  • send messages and emails in your name;
  • change your accounts’ security settings;
  • install an application or an extension;
  • turn on an automatic forwarding rule on your mail;
  • link the account to another device.

The last three are the most serious, because they produce access that outlives the moment: after you have picked the device back up and locked it, that configuration stays active.

What to watch for

  • sent messages you did not write;
  • extensions or applications that appeared;
  • forwarding rules on your mail that you did not create;
  • a new device linked to your accounts.

What to do

If the device has been left open and unattended, locking it is not enough: check the sent mail, the installed apps and the forwarding rules.

3. Availability: when your access is taken away

Availability is the guarantee of being able to use your own data when you need it.

A practical example

From an open device, an account’s password is changed, or a recovery method is added.

What the incident looks like

It is the least immediate impact and the longest-lasting. An unlocked device allows credentials to be changed without them being known: many services do not ask for the current password if the session is already active.

And since the device is also where verification codes arrive, the second factor offers no protection in this scenario: it is in the same place.

What to watch for

  • passwords that stop working;
  • notifications of changes to recovery details;
  • being unable to reach a service you used shortly before.

What to do

A short lock is the only preventive measure. Afterwards, the response is the same as for a lost device: start from the main email.

AspectWhat an open screen allowsTime threshold
ConfidentialityReading everything visible and openableA few seconds
IntegrityMessages, installations, forwarding rules, linked devicesOne or two minutes
AvailabilityChanging credentials and recovery detailsA few minutes

Why every other protection is suspended

This is the point that makes this unit different from the others, and it deserves stating in full.

Recommendations R1–R6 build a layered defence. Every one of them assumes the device is closed:

ProtectionWhat it assumesWhat happens with an open screen
Unique, long passwordsThat they have to be typedThe sessions are already open: they are not needed
A password vaultThat the store is lockedOn an unlocked device it is often already reachable
A second factorThat the code reaches youIt arrives on the device sitting right there, open
An unlock codeThat it gets requestedIt is not requested: the device is already open
Data encryptionThat the device is lockedThe keys are in memory: the data is in the clear

None of these protections works during that window. That is why a setting that seems minor — a time in seconds — actually determines how many minutes a day everything else is suspended.

Not all contexts weigh the same

ContextExposureWhy
A shared workspaceVery highMany people, frequent and predictable absences
An office open to the publicVery highA constant flow of strangers
A cafe, canteen, waiting roomHighThe device sits on the table for minutes
Home with other peopleMedium, and underestimatedTrust is high, but privacy is still a subject
Home aloneLowVisitors remain the case to consider
Public transportHigh for readingThe screen is visible without the device being touched

The last row deserves a note: on a train or the underground nobody even has to pick the device up. A screen that is on and not locked is readable by whoever is sitting beside you.

The impact that stays afterwards

It is worth isolating, because it is what separates a short window from a long one.

What gets read in that window stays read, but ends there. What gets configured, on the other hand, keeps producing effects:

  • a forwarding rule on your mail keeps copying messages for months;
  • an installed application stays installed;
  • an account linked to another device stays linked;
  • a session opened elsewhere stays valid even after you have locked up.

That is why, after even a brief exposure, the right check is not “is anything missing?” but “has anything been added?”

The multiplier nobody works out

There is a way of looking at this impact that makes it far more concrete: do not count the single window, count how many times a day it opens.

An ordinary working day contains a surprising number of brief absences from the desk: the coffee, the printer, a question to a colleague, the bathroom, a meeting in another room, lunch.

Absences in a day30-second timeout5-minute timeout15-minute timeout
10 short ones (2-3 min)~5 minutes exposed~25 minutes exposed~25 minutes exposed
3 medium ones (15 min)~1.5 minutes~15 minutes~45 minutes
1 long one (lunch)30 seconds5 minutes15 minutes
Daily total~7 minutes~45 minutes~85 minutes

The numbers are indicative and vary a great deal from person to person, but the order of magnitude holds: with a long timeout you go from a few minutes to more than an hour a day of an open device in a shared space.

Put another way: across a working year, a fifteen-minute timeout produces the equivalent of several weeks of an open desk. Not because somebody takes advantage — in the great majority of cases nothing happens — but because the protection depends entirely on nobody walking past.

That is what separates a security measure from a hope: a measure works even when the conditions are unfavourable.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that during that window every other protection is suspended
SkillsRecognising the threshold past which reading turns into acting
Secure BehaviourChecking what has been added, not what is missing

Reference level: FL2 — Beginner. This is the level at which the lock time stops being a preference and becomes a measure.

Summary

  • An open screen requires nothing to be got past: the access is total and instant.
  • Under two minutes somebody can read; over it, they can act — and that is the threshold that counts.
  • Every protection from the earlier recommendations is suspended during that window.
  • What gets configured in those minutes outlives the device being closed.

One thing to do today. Check the lock time on the computer you use for work. If it is more than two minutes, you are above the threshold separating reading from acting.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.