What to Do With Your Phone Before You Cross a Border
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Travelling changes your risk profile in specific, predictable ways: you carry everything you own digitally into places with different laws, use networks you do not control, and are more likely to have hardware lost or stolen.
Most of this is handled by preparation before you leave rather than caution while away.
Before you go
Update everything and back up. Both for the obvious reason and because a device lost abroad is much less painful when a current backup exists at home.
Turn on full-disk encryption if it is not already. Phones do this by default; laptops often do not. Without it, a stolen laptop is an open filing cabinet.
Check what is actually on the device. Old tax documents, client files, saved passwords in a browser. Travel is a good prompt to remove what does not need to travel with you.
Know your recovery path. If your phone is stolen on day one, can you still reach your accounts? Two-factor codes on a stolen phone, with no backup codes, leave you locked out of everything at the worst possible moment. Print backup codes and carry them separately from the device.
Border inspections
Many countries assert the right to inspect electronic devices at the border, and the rules differ sharply — including on whether you can be compelled to provide a password, and what happens if you decline.
The honest position is that this is jurisdiction-specific and consequential. Refusing can mean denial of entry for a visitor, device seizure, or in some places arrest. If you are travelling somewhere this genuinely concerns you, look up that country's current rules rather than relying on general advice, and understand that your rights differ substantially depending on your citizenship.
Two things are broadly true and worth knowing:
- Biometrics and passcodes are treated differently in some legal systems. In several jurisdictions compelling a fingerprint or face has been treated differently from compelling a memorised passcode. Powering a device fully off before a border generally means a passcode is required on next unlock rather than biometrics.
- A travel device is the robust answer. If your work involves confidential material and you cross borders where inspection is likely, a clean device carrying only what the trip needs solves the problem without any legal argument. Employers with genuine exposure often mandate exactly this.
For most leisure travellers this is not a realistic concern and the preparation above is sufficient.
While you are there
Hotel and café Wi-Fi is fine for ordinary browsing. Nearly everything uses HTTPS, so the old advice about open networks is largely obsolete. A VPN adds a worthwhile layer where the network operator is unknown, and it helps with services that behave oddly abroad.
Be wary of the network name. The realistic Wi-Fi attack is a fake hotspot named plausibly for the venue. Ask staff for the actual network name rather than picking whichever one looks right.
Avoid public USB charging points, or use a charge-only cable or a power bank. The risk is low and the mitigation costs nothing.
Turn off automatic connection to open networks, so your phone stops silently joining anything with a familiar name.
If a device is lost or stolen
Act in this order:
- Remotely lock and locate it through your platform's find-my-device service. Do not erase immediately if there is a realistic chance of recovery — locate first, erase if it is clearly gone.
- Change your email password from another device, then anything financial.
- Contact your mobile provider to suspend the SIM, which prevents both call charges and a SIM-swap follow-up.
- Report it locally. A police report is usually required for insurance and useful if the device resurfaces.
- Then erase it remotely once recovery looks unlikely.
A worked example of the thing that actually goes wrong
Day two of a two-week trip. A bag goes at a station: phone, and with it everything.
Consider what a phone was doing for you. It held your authenticator app, so it generated the codes for your email, your bank and your cloud storage. It held your SIM, so it received the text codes for everything else. It held your boarding passes, your hotel confirmations and your card in a payment wallet.
You borrow a laptop and try to reach your email to find the hotel address. Your password is correct. It asks for a code. The code comes from an app on the phone that was stolen, or by text to a number now in someone else's pocket.
You try account recovery. Recovery sends a code to the same phone. You try your bank, to cancel the cards. Same wall. You are abroad, without money, without documents, and locked out of everything by security measures that are working exactly as designed.
Nobody read anything on a hotel Wi-Fi network. The entire disaster is a single point of failure that happened to fit in a coat pocket.
The fix is not complicated, which is what makes it worth doing before you leave:
- Print backup codes for email, banking and cloud storage, and carry them in your luggage, separate from the phone.
- Install your authenticator on a second device if the app supports it, or leave one at home you can reach remotely.
- Write down the international number for your bank's lost-card line on paper. It is not printed on a card you no longer have.
- Store copies of your passport, tickets and reservations somewhere reachable from any browser with credentials you can access without the phone.
- Know your device's serial number, which insurers and police both ask for and nobody remembers.
- Carry a second payment card kept in a different bag entirely.
The counter-argument on public Wi-Fi
Travel security advice has traditionally been dominated by warnings about hotel and café networks, and that emphasis is now largely misplaced.
Nearly all web traffic is encrypted in transit, and browsers warn loudly when it is not. The scenario the old advice was built around — someone on the same network quietly reading your banking session — is no longer the easy attack it was. Meanwhile the things that genuinely ruin trips are theft, loss, being locked out and card fraud, and none of those care what network you used.
That is not an argument against using a VPN abroad, which remains worthwhile: it keeps your browsing away from an unknown network operator, and it helps with services that behave strangely from an unfamiliar country. It is an argument about proportion. If you spend your preparation on network security and none on the lockout problem, you have prepared for the smaller risk.
The one network attack still worth genuine caution is the fake hotspot named after the venue, because it can present a convincing login page. Ask staff for the real network name, and never enter account credentials on a page that a Wi-Fi network pushed at you. Our guide to public Wi-Fi safety goes into the detail.
Coming home
Change passwords you typed on networks you did not control if anything felt off, check your accounts for unfamiliar sessions, and revoke access for any device you no longer have.
Remove hotel and airport networks from your saved list, so your phone stops automatically connecting to anything using the same name months later in a different city. Check whether any app you installed for the trip — a transit app, a local delivery service — still holds permissions or a payment method it no longer needs.
If you set up a temporary travel device, wipe it before storing it rather than leaving a configured device with saved sessions sitting in a drawer. Wiping a phone properly covers the order that avoids locking yourself out in the process.
Where this fits
The lockout scenario above is the same failure that makes SIM swap attacks so damaging, and the fix is the same: do not let one device be the only key to everything. Before travelling, confirm your backups are current and restorable, and make sure two-factor authentication is set up with recovery codes you actually hold. For the connectivity side of a trip — keeping a data plan and a VPN working across borders — our sister site VPNTex covers travel eSIM and VPN together. The device software itself is covered in our shortlist of security tools.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Continue reading
privacy
The Video Call Was Fake and So Was Everyone On It
Synthetic video has moved from novelty to fraud tool. Where it is actually being used, why detection advice ages badly, and the process controls that work regardless.
privacy
An Ad Blocker Is a Security Tool
Blocking ads is usually framed as a preference. Malicious advertising has delivered real attacks to mainstream sites, which makes a content blocker part of your defences.
guides
NordPass Review 2026: Fast, Modern Password Manager
An in-depth NordPass review for 2026: who this password manager suits, how its security model and usability hold up, and how it compares to rivals.
