Additional resource for the lesson “Automatic Screen Lock: Setting the Timeout” — Online Security course
A strong passcode protects nothing during the minutes your phone sits unlocked on a table. The automatic screen lock decides how long that window stays open — and it works together with a second setting that most people have never opened.
A. Why this matters
You set a good passcode. You use it several times a day. And in between, the phone sits unlocked — on the desk, on the café table, in a meeting room — for as long as the timeout allows.
That interval is where most realistic exposure lives. Not a determined attacker breaking your code, but an unattended device that has not locked itself yet.
There is a second setting underneath it, and it is the one that decides security: how soon after the screen turns off the phone actually requires the passcode again. On some devices the two are the same moment. On others there is a grace period, and that period is the real size of the gap.
The key idea: the passcode decides whether someone can get in. The timeout — and the grace period after it — decide how often they would not need it at all.
B. Key concepts
Six ideas about the gap between using the phone and it locking itself.
Automatic screen lock
The setting that locks the device after a period without interaction.
Why it matters to you: It is the only protection that works when you are not thinking about it — which is precisely when devices are left behind.
The inactivity timeout
How long the phone waits without interaction before the screen turns off. An iPhone ships set to thirty seconds; Android varies by manufacturer, commonly thirty seconds to two minutes.
Why it matters to you: The defaults are short. The long gaps are almost always ones people created themselves, raising the timeout so the screen would stop dimming while they read.
The unattended moment
The desk you walk away from, the table at a café, the phone passed to someone to look at a photo.
Why it matters to you: These are ordinary situations, not incidents. The timeout is what makes them uneventful.
Shoulder surfing
Someone observing you enter the code.
Why it matters to you: A short timeout means you enter the code more often, which is a real trade-off — and the reason the companion resource on where you unlock is worth reading alongside this one.
Smudge attacks
Reconstructing an unlock pattern or PIN from the marks left by your fingers on the screen.
Why it matters to you: It works best against patterns, which leave a continuous trace. Another practical reason to prefer a PIN or passcode over a drawn shape.
Balancing security and convenience
A very short timeout on a device you use constantly can become genuinely annoying.
Why it matters to you: Being honest about this matters: a setting people revert after a week protects nothing. Thirty seconds on the phone, a little longer on a laptop at home, is a sustainable compromise.
C. A practical example: the timeout you changed yourself
You put the phone down and go to another room for three minutes.
- With a five-minute timeout, the phone is unlocked the entire time you are away. Anyone passing has an open device.
- With a thirty-second timeout, it locks itself before you have reached the other room.
The password, the encryption, the second factors — none of them changed. What changed was whether the protection was active during the window that mattered.
The same setting, on a laptop
A laptop in a shared office with no lock on the screensaver is the same situation with more data attached. The setting is usually under the screen or power options, and it is often set generously by default.
This is the rare security setting where the protection is entirely automatic. You change it once and it works during exactly the moments you are not paying attention.
D. Try it yourself: set the timeout on every device
Five minutes, across all your devices rather than just the phone.
Step 1 — Find the current setting
- On the phone it is usually under Display or Lock screen: ‘screen timeout’ or ‘auto-lock’.
- Note what it says now. Most people are surprised.
Step 2 — Set it short
- Phone: thirty seconds to one minute.
- Tablet: one to two minutes.
- Laptop: five minutes, with the lock-on-sleep option enabled.
Step 3 — Learn the manual lock
- Every device has a way to lock it immediately — a button, a key combination.
- Using it when you stand up makes the timeout a backstop rather than your first line of defence.
Step 4 — Live with it for a week
- If a setting turns out to be genuinely unworkable, lengthen it slightly rather than turning it off.
- A one-minute timeout you keep is worth more than a thirty-second one you disable.
Step 3 is the habit that makes the rest painless: locking manually when you stand up means you rarely notice the timeout at all.
E. Videos, articles and further resources
Independent and institutional sources in English.
NCSC (UK) — Cyber security advice for you and your family
Device protection guidance for individuals from the UK national authority.
https://www.ncsc.gov.uk/section/advice-guidance/you-your-family
FTC — How to protect your phone from hackers
Practical steps for protecting the phone, including access settings.
https://consumer.ftc.gov/articles/how-protect-your-phone-hackers
CISA — Secure Our World
The US cyber security agency’s public programme: four basic actions, explained for people who are not IT professionals.
https://www.cisa.gov/secure-our-world
NCSC (UK) — Top tips for staying secure online
Six short pieces of advice from the UK’s national cyber security authority. A good starting point if you want the essentials without the jargon.
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online
EFF — Keeping your data safe
Why the lock and the encryption behind it are part of the same protection.
https://ssd.eff.org/module/keeping-your-data-safe
NCSC (UK) — What to do if your account is hacked
Steps to take when you lose control of an account. Worth reading before you need it.
https://www.ncsc.gov.uk/section/respond-recover/hacked-accounts
Links checked in August 2026. The exact menu path differs by device; the manufacturer’s support pages document it for your model.
F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior
This lesson sits on the Secure Behavior pillar at level FL1. It is one setting, and it works without further attention.
Skills
- Finding and changing the auto-lock timeout on a phone, tablet and computer.
- Using the manual lock shortcut as a habit.
- Recognising why patterns are particularly exposed to smudge reconstruction.
For professionals and organizations
- Setting a maximum timeout centrally on devices with access to company data.
Awareness
- Understanding that the timeout defines the window where no protection is active.
- Recognising that the realistic risk is an unattended device rather than a broken code.
- Knowing that a shorter timeout means entering the code more often, which has its own trade-off.
For future instructors and ambassadors
- Asking people to check their current timeout live. The answer is usually longer than they expect, and that does the work.
Secure Behavior
- Keeping the phone’s timeout at thirty seconds to a minute.
- Locking the device manually when standing up.
- Enabling lock-on-sleep on laptops.
For organizations
- Enforcing the timeout through device management rather than asking people to set it themselves.
G. Questions to sit with
- What is your phone’s timeout set to right now? Go and look — the answer is often surprising.
- How often is your phone lying somewhere while you are doing something else?
- Do you lock your laptop when you leave the desk, or rely on it locking itself eventually?
- If a shorter timeout would annoy you, what is the shortest one you would actually keep?
H. What to do now
The recommendations (R) and security measures (MS) from the Cyber Welfare database for device access.
The timeout
- R7 — Set the screen lock to the shortest interval you can live with.
- R5 — Have a six-digit PIN at minimum behind it, so the lock means something.
- MS4 — Use an alphanumeric passcode of 8 characters or more where the device holds credentials.
Minimum commitment: Thirty seconds to a minute on the phone. Then lock manually when you stand up, and the timeout becomes a backstop.
Around it
- R6 — Keep the device updated, with automatic updates on.
- MS3 — Prefer a passcode over a pattern, which also removes the smudge problem.
In short
- The timeout defines the window in which none of your other protections are doing anything.
- Check what yours is set to rather than assuming: the default is short, but it is a setting people often lengthen.
- Smudge reconstruction works best on patterns — another reason to use a PIN or passcode.
- Locking manually when you stand up is the habit that makes a short timeout painless.
Related resources in this course
The rest of the device cluster:
- Device Lock: The Barrier Everything Else Sits Behind
- Phone Passcode Security: Choosing the Right Unlock Method
- Shoulder Surfing: Protecting Your Phone as You Unlock It
Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.
If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.




Leave a Reply