Cybersecurity › Module 6 › Lesson 3
Physical Security Basics
Locks, shoulders, and stolen drives
Opening
Twenty digital controls die to one open laptop
You can use long passwords, MFA, VPNs, patched browsers, and encrypted messengers — and still lose everything if someone walks away with your unlocked device or reads your screen on a train. Physical access often bypasses remote defenses that security marketing loves to brag about. Physical security is not paranoia. It is locking the screen every time you stand up, watching for shoulder surfing, securing devices in public, and enabling full disk encryption so theft of hardware does not equal a readable data dump. Defend YOUR gear. Never practice by bypassing other people's locks or planting trackers.
1. The unattended screen — seconds are enough
A bathroom break, a coffee refill, or a hallway chat is enough time for a stranger to send email as you, change a password, plug a malicious USB, photograph open documents, or walk off with the laptop. Build muscle memory: lock every time you stand up — even for "just a second." Win+L on Windows, Control+Command+Q on macOS, and a short auto-lock on phones turn intention into habit. Disable auto-login on shared or travel laptops so a stolen boot does not land on your desktop wallpaper.
Cable locks, bag loops around chair legs, and never leaving devices unattended in cafés sound basic because they work. Hotels and conferences are high-loss environments: label devices, use lockable bags, and do not advertise expensive hardware on social posts with room numbers. If a device is stolen, your next moves combine Module 6 backups, account password resets from a clean device, and Find My / device-locate features you configured in advance on YOUR accounts.
2. Shoulder surfing, privacy filters, and notification leaks
Not every attacker writes malware. Some watch you type a PIN on a bus, read confidential slides on a flight, or film a one-time code over your shoulder. A privacy-filter screen protector darkens side angles. Angle your body. Be careful with banking and password-manager screens in crowds. On phones, hide sensitive notification previews on the lock screen so OTPs and message contents are not public signage on the table.
ATM and payment-terminal skimming / camera overlays are cousins of the same physical theme: inspect the hardware you touch, cover the keypad when you can, and prefer chip/tap or official apps over mystery card readers. Still — this course does not teach skimmer construction. Recognition and personal caution only.
3. Full disk encryption (FDE) — stolen drive ≠ open files
If a thief steals a powered-off laptop without full disk encryption, they may remove the drive and read files on another machine — skipping your fancy login wallpaper entirely. BitLocker (Windows), FileVault (macOS), and built-in device encryption on modern phones scramble the disk so stolen hardware does not equal readable documents. Encryption at rest is a confidentiality control for physical loss; it does not stop an attacker who already sits at your unlocked session.
Turn FDE on where supported, store recovery keys offline in a place you control (not a sticky note on the laptop), and test that you know how recovery works before you need it. Firmware passwords / BIOS passwords add another speed bump against casual boot-from-USB tricks on YOUR machines. Combine with strong lock-screen credentials — not 1234 or a birthday — and biometrics as convenience layered on a real PIN/password, not as the only factor you understand.
Lock reflex
Every stand-up: Win+L / macOS lock / phone button. Auto-lock ≤ 1–2 minutes.
Shoulder surfing defense
Privacy filter, body angle, hide lock-screen previews for OTPs and mail.
FDE
BitLocker / FileVault / device encryption so a stolen drive is ciphertext.
4. Wrong vs right: café table
Worked failure — same espresso stop with YOUR laptop:
Wrong
Leave the laptop unlocked "for two minutes," screen facing the room, notification banners showing OTPs, disk encryption never checked, auto-login enabled. A passerby reads payroll email or walks off with the device and mounts the clear drive at home. You also posted a story showing the café table and sticker-covered lid — easy to spot.
Right
Win+L / lock shortcut every stand-up, lid closed, bag looped around a chair leg or device kept on your person, FDE enabled with recovery key stored offline, sensitive apps locked or closed in public, notification previews hidden. If the device vanishes, you wipe/locate from YOUR account and restore from 3-2-1 backups.
5. Practical: lock + encryption check on YOUR gear
Physical security quick checks (YOUR devices)
# Lock shortcuts (muscle memory) Windows: Win + L macOS: Control + Command + Q Phone: set auto-lock to 30 seconds / 1 minute Hide sensitive notification previews on lock screen # Full disk encryption status Windows: Settings → Privacy & security → Device encryption (or search "BitLocker") — save recovery key OFFLINE safely macOS: System Settings → Privacy & Security → FileVault Phone: modern devices usually encrypt when a lock is set — still use a strong PIN/password # Public place kit - Privacy filter (optional but powerful on flights/trains) - Never leave devices unattended - Disable auto-login - Cable lock in high-risk shared offices/hotels if appropriate - Prefer bag / body carry over "quick table trips" # USB hygiene (physical + malware crossover) - Do not plug in found USBs - Prefer "charge only" cables when borrowing power in public - Disable AutoPlay on Windows where you can # If stolen (prep now, act later) 1. Use official Find My / device locate on YOUR accounts 2. Change critical passwords from a CLEAN device 3. Restore from tested 3-2-1 backups 4. Report to police/carrier as appropriate — no vigilantism # NEVER - Bypass someone else's lock "for practice" - Plant trackers on people without consent - Shoulder-surf strangers to "prove the lesson" - Share BitLocker/FileVault recovery keys in chat
Mission: lock reflex + disk check
1) Practice locking your laptop/phone three times today when you stand up. 2) Confirm screen auto-lock is short and lock-screen previews are not leaking OTPs. 3) Check whether BitLocker/FileVault/device encryption is on for YOUR device. 4) If it is off and the device supports it, turn it on (save recovery keys offline safely). 5) Decide your café rule: lock + never unattended.
Stuck? Ask Cyberlium AI Mentor
Ask: "Hint only: why does a login password fail if someone removes an unencrypted hard drive?" Or: "Hint only: where do I check FileVault/BitLocker on MY computer?" Stay on defense — never ask how to bypass others' locks, crack PINs, or defeat someone else's encryption.
Physical habits guard digital secrets that software alone cannot. Next — AI-Powered Scam Awareness — because cloned voices and synthetic documents attack trust and urgency, not just unattended laptops. That lesson is already deep; keep going.
Knowledge Check
APPLY: What primarily stops a thief from reading files after removing your laptop drive?
Multiple choice
Knowledge Check
APPLY: Best habit before walking away from a work laptop for coffee?
Multiple choice
Knowledge Check
APPLY: True or False: Shoulder surfing can steal secrets without any malware installed.
True or False