CYBER WELFARE

Protect your Digital Privacy

Set a six digit passcode on your phone: the protection everybody takes for granted

Your phone is probably the object holding more information about you than any other: messages, photos, email, accounts, documents, and the already open sessions of dozens of services.

And yet the protection separating it from anyone who picks it up is often the most neglected of all: four digits chosen in a hurry during setup, or a date that means something.

Recommendation R5 asks for one simple step: at least six digits, and not a sequence anyone could trace back to you. It is a setting you change once, and it protects everything else.

What this recommendation says

Recommendation R5 establishes that mobile devices — phone and tablet — should be protected with a passcode of at least six digits, chosen so as not to be predictable.

The passcode is the code that unlocks the device. It is also, on almost every system, the code required when biometric recognition does not work, after a restart, or after a few hours of inactivity. Fingerprint and face are shortcuts: the passcode is the real key.

Why six and not four. Every extra digit multiplies the number of possible combinations by ten. Going from four digits takes you from ten thousand combinations to a million — and on a device that limits attempts, the difference is decisive.

What it is not. It is not a request to give up your fingerprint or face recognition: those remain convenient and should be used. The passcode is what sits underneath, and it comes into play precisely in the moments where biometrics are not enough.

How it relates to the Security Measures. Six digits are the baseline threshold. Anyone wanting to go further will find more advanced guidance in the programme’s Security Measures — a longer alphanumeric passcode, for instance. The recommendation sets the minimum that works for everyone; the measures refine it.

Scope. Phone, tablet, and every mobile device that holds personal data or stays connected to your accounts.

Why it matters

An unlocked phone is not “a device”: it is a sign-in already completed to everything running inside it.

Whoever opens it has no password to guess: the sessions are already open. Mail, cloud, social networks, chats, often the banking app. And above all — this is the point that most often escapes notice — the phone is where verification codes arrive. Whoever holds it can receive the second factor for every other account.

What the passcode protectsWhy it counts
The already open sessionsNo password to guess: the accounts are already in
Incoming verification codesThe phone is the second factor for almost everything else
Personal photos and messagesPrivate content, often other people’s too
The authenticator appA store of second factors, unless separately protected
Saved documentsCopies of ID documents, contracts, receipts
The ability to act in your nameMessages sent to your contacts, with your credibility

There is also a difference from the other digital risks: here physical proximity counts. A phone gets lost on a train, left on a table, taken in a crowded place. No technical skill is needed to open it, if the code is a date.

A concrete example

Sarah loses her phone on the underground. The passcode was 0512: the day and month of her son’s birthday, information that appears in her public posts.

Whoever finds it has nothing to force. They open the photos, the mail, the chats. They see a bank account confirmation in the mailbox. They start a password recovery: the verification code arrives on the same phone they are holding.

With six digits not traceable to her, the same person would have had an object in their hands and nothing more.

That is the difference between losing a phone and losing access to your digital life.

When to apply it

  • When setting up a new device. That is the moment when the code gets chosen in a hurry: thirty seconds are worth spending.
  • Right now, if you have four digits today. Changing the passcode takes a minute and has no consequences.
  • If your code contains a date. Birthdays, anniversaries, years: they are the first combinations tried.
  • On the devices you carry around. The more a device moves, the more physical protection counts.
  • On devices shared in the family. Even a household tablet holds accounts and open sessions.
  • Before a trip. Crowded settings, public transport, temporary accommodation: they increase the chances of losing it.
  • When somebody has seen your code. A passcode typed in front of others should be changed, without any drama.

How to apply it

  1. Go into the device’s security settings. Look for “Screen lock”, “Face ID and passcode”, “Security” or “Lock screen”.
  2. Choose a passcode of at least six digits. Some systems still offer four digits as the default: look for “passcode options” or “change passcode type” to move to six or more.
  3. Avoid predictable sequences. Dates of birth, anniversaries, years, repeated digits, ascending or descending sequences, geometric shapes on the number pad.
  4. Choose something not written down anywhere about you. It should not derive from information present on your profiles or your documents.
  5. Turn biometric recognition on as well. Fingerprint or face make daily unlocking quick, and reduce the occasions where you type the passcode in front of others — which is a security advantage, not just a convenience.
  6. Shorten the automatic lock time. A strong passcode on a phone that stays unlocked for half an hour protects very little. That is the subject of recommendation R7.
  7. Check that remote lock and wipe are enabled. The main systems have a function to locate, lock or erase the device remotely: it needs enabling before it is needed.

The most frequent objections

“I use my fingerprint anyway, I never type the passcode.”

That is exactly the point: the passcode is asked for in the moments where biometrics do not apply — after a restart, after a few hours, before changing security settings. Those are exactly the moments when somebody else might have the device in their hands.

“Six digits are awkward to type.”

With biometric recognition enabled, you type them perhaps once a day. The awkwardness you imagine concerns a situation that hardly ever occurs.

“If it gets stolen they will just wipe it and resell it.”

It happens, and it is the least damaging scenario. But before wiping it, an open device gets looked through — and it is in those minutes that messages to contacts and account recoveries start.

“There is nothing important on my phone.”

That is almost never true, and not because of the content: the phone is where the codes protecting your bank, your mail and your cloud arrive. Even an “empty” device is a key.

Common mistakes to avoid

  • Four digits left there out of habit. It is the default on many devices, and it stays for years.
  • A date as the code. Birthdays and anniversaries are the first combinations tried, and they are often public.
  • Repeated or sequential digits. 000000, 123456, 111111: they top every list.
  • A geometric shape on the keypad. Codes that draw a shape are easy to reconstruct by watching the hand move.
  • Typing the passcode in crowded places without care. On public transport, typing is more visible than it seems.
  • The same code as your bank card. If one of the two is observed, the other is compromised.
  • Relying on biometrics alone. The passcode is still requested after a restart or after a few hours: if it is weak, biometrics do not compensate.
  • Not enabling remote lock. It is the only thing you can do once the device is no longer in your possession.

How this connects to the Cyber Welfare Framework

PillarHow it contributes
SkillsKnowing how to configure a mobile device’s lock correctly
AwarenessUnderstanding that the phone is the key to everything else, not one object among many
Secure BehaviourChoosing a code not traceable to you, and protecting it as you type it

Digital maturity levels.

  • FL1 — Basic. Four digits, or a code tied to a personal date.
  • FL2 — Beginner. At least six digits, not traceable to personal information.
  • FL3 — Autonomous. Six digits or more, a short automatic lock, remote lock and wipe enabled.
  • FL4 — Skilled. An alphanumeric code where the context calls for one, attention to typing in public, deliberate control over what appears on the lock screen.
  • FL5 — Expert-Guide. You help others configure their own devices, starting with those least at ease with them.

R5 is one of the quickest steps from FL1 to FL2: a minute of configuration, an effect covering everything the device holds.

How to check you are applying it correctly

  1. Does my unlock code have at least six digits?
  2. Does it contain a date, a year or a sequence somebody could connect to me?
  3. If I lost my phone right now, could I lock it remotely?

Quick checklist

  • ☐ The unlock code has at least six digits
  • ☐ It contains no dates, years or repeated digits
  • ☐ It is not the same code I use for my card
  • ☐ Biometric recognition is enabled for daily unlocking
  • ☐ Automatic screen lock is set to a short time
  • ☐ Remote lock and wipe are enabled
  • ☐ I know what appears on the lock screen without unlocking the phone

For an overall measure of where you stand, you can take the digital resilience self-assessment.

In short

Your phone holds more personal information than any other object, and it is also the device most easily lost. The protection separating it from anyone who picks it up is the unlock code.

Six digits not traceable to you, biometric recognition for daily use, a short automatic lock and remote lock enabled: four settings, a minute in total.

Something to think about. If your phone ended up in a stranger’s hands right now, how long would it take them to open it — and what would they find already open?

Explore this recommendation

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.