There is an important difference between this unit and the one on the unlock code, and it is worth making clear straight away.
The code protects against people who do not know it. A screen left unlocked protects against nobody: whoever is standing in front of the device at that moment has exactly the access you have. They have nothing to get past, nothing to guess, nothing to know.
It is the only scenario in this series where the exposure is total and instant. This post looks at what that means concretely, across the three aspects by which the security of any information is measured.
It expands on the recommendation screen lock timeout.
The factor that governs everything: duration
Before the impacts, the variable that determines them — and it is the only one in this series measured in seconds.
| Lock time | What it allows | How often the scenario applies |
|---|---|---|
| Immediate / 15 seconds | Practically nothing: the window closes before anybody sits down | The window exists but is unusable |
| 1–2 minutes | Reading messages, opening an app, looking at photos | It covers a coffee break |
| 5 minutes | Sending messages, changing settings, installing something | It covers a short meeting, a step out of the office |
| 15 minutes or more | Everything you could do, unhurried | It covers any ordinary absence |
The progression is not gradual: past two minutes you move from reading to acting. Below that threshold somebody can look at something; above it, they can do something.
1. Confidentiality: what becomes readable
Confidentiality is the guarantee that information stays accessible only to those entitled to it.
A practical example
The computer stays unlocked in a shared space while you go for a coffee. The mail is open, the password vault is unlocked, work documents are on the screen.
What the incident looks like
Nothing technical is needed: looking is enough. And in a few seconds a great deal gets read — the subject lines of visible emails, the names of open documents, the conversations under way, the calendar.
With a few seconds more, the password vault opens, which on an unlocked device is often reachable with no further prompt. At that point the exposure no longer concerns the device: it concerns every account it holds.
What to watch for
- the device found in a different position from how you left it;
- open applications you do not remember using;
- messages showing as read that you did not open;
- the screen still on when it should have gone dark.
What to do
A very short lock, and manual locking every time you get up. On a computer it is a keyboard shortcut: learning it is worth more than any automation.
2. Integrity: what can be done in your name
Integrity is the guarantee that nobody alters your data or acts in your place.
A practical example
An email goes out from your address from an open computer. It is not a forged message: it is genuinely yours, with your signature, from your account, inside a conversation already under way.
What the incident looks like
This is where the two-minute threshold shows. With the device open, somebody can:
- send messages and emails in your name;
- change your accounts’ security settings;
- install an application or an extension;
- turn on an automatic forwarding rule on your mail;
- link the account to another device.
The last three are the most serious, because they produce access that outlives the moment: after you have picked the device back up and locked it, that configuration stays active.
What to watch for
- sent messages you did not write;
- extensions or applications that appeared;
- forwarding rules on your mail that you did not create;
- a new device linked to your accounts.
What to do
If the device has been left open and unattended, locking it is not enough: check the sent mail, the installed apps and the forwarding rules.
3. Availability: when your access is taken away
Availability is the guarantee of being able to use your own data when you need it.
A practical example
From an open device, an account’s password is changed, or a recovery method is added.
What the incident looks like
It is the least immediate impact and the longest-lasting. An unlocked device allows credentials to be changed without them being known: many services do not ask for the current password if the session is already active.
And since the device is also where verification codes arrive, the second factor offers no protection in this scenario: it is in the same place.
What to watch for
- passwords that stop working;
- notifications of changes to recovery details;
- being unable to reach a service you used shortly before.
What to do
A short lock is the only preventive measure. Afterwards, the response is the same as for a lost device: start from the main email.
| Aspect | What an open screen allows | Time threshold |
|---|---|---|
| Confidentiality | Reading everything visible and openable | A few seconds |
| Integrity | Messages, installations, forwarding rules, linked devices | One or two minutes |
| Availability | Changing credentials and recovery details | A few minutes |
Why every other protection is suspended
This is the point that makes this unit different from the others, and it deserves stating in full.
Recommendations R1–R6 build a layered defence. Every one of them assumes the device is closed:
| Protection | What it assumes | What happens with an open screen |
|---|---|---|
| Unique, long passwords | That they have to be typed | The sessions are already open: they are not needed |
| A password vault | That the store is locked | On an unlocked device it is often already reachable |
| A second factor | That the code reaches you | It arrives on the device sitting right there, open |
| An unlock code | That it gets requested | It is not requested: the device is already open |
| Data encryption | That the device is locked | The keys are in memory: the data is in the clear |
None of these protections works during that window. That is why a setting that seems minor — a time in seconds — actually determines how many minutes a day everything else is suspended.
Not all contexts weigh the same
| Context | Exposure | Why |
|---|---|---|
| A shared workspace | Very high | Many people, frequent and predictable absences |
| An office open to the public | Very high | A constant flow of strangers |
| A cafe, canteen, waiting room | High | The device sits on the table for minutes |
| Home with other people | Medium, and underestimated | Trust is high, but privacy is still a subject |
| Home alone | Low | Visitors remain the case to consider |
| Public transport | High for reading | The screen is visible without the device being touched |
The last row deserves a note: on a train or the underground nobody even has to pick the device up. A screen that is on and not locked is readable by whoever is sitting beside you.
The impact that stays afterwards
It is worth isolating, because it is what separates a short window from a long one.
What gets read in that window stays read, but ends there. What gets configured, on the other hand, keeps producing effects:
- a forwarding rule on your mail keeps copying messages for months;
- an installed application stays installed;
- an account linked to another device stays linked;
- a session opened elsewhere stays valid even after you have locked up.
That is why, after even a brief exposure, the right check is not “is anything missing?” but “has anything been added?”
The multiplier nobody works out
There is a way of looking at this impact that makes it far more concrete: do not count the single window, count how many times a day it opens.
An ordinary working day contains a surprising number of brief absences from the desk: the coffee, the printer, a question to a colleague, the bathroom, a meeting in another room, lunch.
| Absences in a day | 30-second timeout | 5-minute timeout | 15-minute timeout |
|---|---|---|---|
| 10 short ones (2-3 min) | ~5 minutes exposed | ~25 minutes exposed | ~25 minutes exposed |
| 3 medium ones (15 min) | ~1.5 minutes | ~15 minutes | ~45 minutes |
| 1 long one (lunch) | 30 seconds | 5 minutes | 15 minutes |
| Daily total | ~7 minutes | ~45 minutes | ~85 minutes |
The numbers are indicative and vary a great deal from person to person, but the order of magnitude holds: with a long timeout you go from a few minutes to more than an hour a day of an open device in a shared space.
Put another way: across a working year, a fifteen-minute timeout produces the equivalent of several weeks of an open desk. Not because somebody takes advantage — in the great majority of cases nothing happens — but because the protection depends entirely on nobody walking past.
That is what separates a security measure from a hope: a measure works even when the conditions are unfavourable.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Understanding that during that window every other protection is suspended |
| Skills | Recognising the threshold past which reading turns into acting |
| Secure Behaviour | Checking what has been added, not what is missing |
Reference level: FL2 — Beginner. This is the level at which the lock time stops being a preference and becomes a measure.
Summary
- An open screen requires nothing to be got past: the access is total and instant.
- Under two minutes somebody can read; over it, they can act — and that is the threshold that counts.
- Every protection from the earlier recommendations is suspended during that window.
- What gets configured in those minutes outlives the device being closed.
One thing to do today. Check the lock time on the computer you use for work. If it is more than two minutes, you are above the threshold separating reading from acting.
Related content
- Screen lock timeout — the recommendation this expands on
- Consequences of an unattended device — the concrete effects on work and relationships
- Signs someone used your device — what to check when you get back
- How to set up automatic locking — the configuration that closes the window
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



