If you’re at higher risk, you should consider taking the most stringent measures available. Check the following criteria to see if they apply:
- You work in the financial, legal, medical, or government sector: If you use Apple hardware for work, you are likely subject to regulatory requirements and have been briefed on them. (You might even have had to take a course on compliance!) You may be required to engage additional security, like using a VPN, blocking ports for USB/Thunderbolt and SD Cards (see the Mac settings worth changing), enabling FileVault on a Mac, and turning on Advanced Data Protection in iCloud. You may also need to enable hardware security keys for your Apple Account. If you don’t take these steps, and it’s discovered, your devices are lost or data intercepted, or online accounts are compromised, you could be sanctioned, fired, fined, or even charged with a crime, depending on the employer and locality.
- Your device contains unusually sensitive data: This could be old love letters you don’t want your partner to see, confidential business information from your employer (even if they’re not in the financial, legal, etc., categories above), records of a delicate medical condition, or anything else that could cause you serious problems (like loss of your job, insurance, or marriage) if it were to get out.
- You’re famous: Congratulations! You already know the price of this on social media and when dining, traveling, or walking around, depending on how well-known you are. But you’re also more of a target online, because of the obsession so many sites and people have with secrets about people who are seen to be famous.
- You’re a journalist: Sadly, reporters are frequently targeted by criminals, people they’re writing about, and governments. For instance, Ronan Farrow reported that Harvey Weinstein hired an Israel-based private-intelligence firm to dig up dirt on him while he was researching his watershed story on Weinstein’s history of alleged and proven sexual crimes.
- Wealthy in real terms or cryptocurrency: People with more than a little money are regular targets, especially if they have significant Bitcoin or other cryptocurrency holdings. Having an expensive house doesn’t mean much in the current real-estate market; it’s more likely that you have elevated risk if there’s coverage or securities filings that disclose your wealth, stock grants, or other assets.
- Rough travel: You frequent any of the internet’s seedier neighborhoods, such as sites that traffic in online gambling, porn, or pirated content (like software, television shows, or movies).
- Secret or pseudonymous identity: You have an online identity, separate from your real-life identity, that you need to keep private. A number of times in recent years, someone whose job or political position has prevented them from having a public persona have been outed for writing under another, typically fictitious name.
- Heated online interactions: You engage in controversial discussions that might result in people being exceptionally angry with you.
- Careless co-users (Mac): Specific to a Mac, you share it with less-sophisticated family members who may not be as careful as you would be about downloading files from unknown sites, clicking links in email messages, and using good passwords. While you can set them up with their own macOS accounts—you should!—some of their actions can affect the entire Mac and your online accounts.
- People in particular professions and of genders other than male: It’s a sad fact of modern life that being a responsible journalist, being an advocate for vulnerable people, believing the Earth is round and evolution legitimately established in the fossil record, or having the temerity to be a gender that someone else has chosen to be angry about online can cause reactionary individuals and groups to target you.
- You live in a country that has reduced privacy protections: Various countries have fought with Apple over allowing back-door access to iCloud data. The United States asserts the right to login to examine incoming tourists’ and students’ social media and other accounts. Many countries now think that any checkpoint, traffic stop, or other incidental encounter gives them carte blanche to demand all your data.
Now for the good news! A decade ago, my advice to you would have likely been far more extensive and stringent than for the average user. These days, however, Apple’s and other companies’ baseline security is more accessible, easier to use, and more effective.
My general advice is to do everything suggested here as the baseline, and build a bit from there.
Take a hard look at Lockdown Mode
Some people are pinpoint targeted by spyware, software that can hijack their devices, often without a single click, using previously unknown exploits. These attacks are worth a lot of money and thus typically deployed in a targeted fashion by governments and criminal syndicates against journalists, members of minority groups in a given country, human-rights activists, and opposition politicians.
To help counter these kinds of intrusions, Apple offers a Lockdown Mode you can invoke that highly restricts many forms of inbound messages and traffic. For the full rundown, see how to turn on Lockdown Mode and who needs it.
If you fall into the above categories, your biggest risks will come from how your Mac is set up, rather than your iPhone or iPad. Here’s how you could improve your Mac security:
- Upgrade your Mac to Golden Gate: Golden Gate supports all Apple silicon Macs. A few older Intel models can upgrade to the previous release, macOS 26 Tahoe, which you should do. If you can’t run Tahoe or Golden Gate, you’re not getting the latest and best security. Consider upgrading your Mac if that’s important to you. (See which Macs can run it.)
- Allow FileVault: Apple enables FileVault by default when you upgrade to macOS 26 or 27 and on new computers running it. Leave it on (see FileVault). Also, power down your Mac whenever it’s not in use; never leave it idle and running for more than a brief period. (A FileVault-like feature is part of iOS/iPadOS and cannot be disabled or configured.)
- Block device and card insertion: Thunderbolt and USB devices and SD Cards plugged into your Mac can be blocked from interacting with the operating system without authentication. See the Mac settings worth changing.
- Never make local, unencrypted copies of your data: All local copies should be on encrypted volumes that are unmounted after backup or shutdown when you regularly shut your Mac down; all hosted backups, if any, should only be with firms that offer strong, user-owned encryption. Time Machine lets you set up backups on an encrypted drive or add an encryption key for networked backups. All online backup services worth considering put the encryption key for your archived data solely in your hands.
