Liscairn
← Back to guide
Security & legacy

Devices: security and digital legacy

Modern devices are designed to be secure — which is exactly what makes them hard for anyone else to access after you die. This guide covers the best practices for phones, computers, encryption, two-factor authentication, and what your executor actually needs.

The tension you need to understand

Every security feature on your devices — PIN locks, disk encryption, two-factor authentication, biometrics — makes your data safer while you are alive and harder to access after you die. These are not flaws; they are working exactly as designed.

The answer is not to weaken your security. It is to document your security in a way that your executor can use, stored in a way that only they — and no one else — can access.

Strong PIN
Prevents unauthorised access to your phone
Executor cannot unlock your phone or access your authenticator apps
Disk encryption
Your files are unreadable if your laptop is stolen
Without the recovery key, your executor cannot read your drive — even with your login password
Two-factor authentication
Prevents account takeover even if your password is stolen
Your executor has your password but cannot log in without the second factor

Solution: keep the security. Document the keys. Store them safely, separately, and in a way only your executor can find.

Your phone

Your phone is probably the most information-dense device you own — photos, messages, banking apps, email, health data, and the authenticator apps that protect your other accounts. It is also the hardest thing for an executor to access without your PIN.

The PIN problem

If someone does not know your PIN, a locked iPhone or Android phone is essentially unbreakable. Apple and Google have both designed their devices so that even they cannot extract data from a locked phone — this is a deliberate security feature that becomes a serious problem after death. Police forces, governments, and law firms have all failed to access locked phones belonging to deceased people.

Important

Store your phone PIN with your will or in your password manager's emergency access. Without it, your executor cannot access the photos, messages, or authenticator apps on your phone — even with your other passwords in hand.

What to document for your phone

  • Your PIN or passcode (not just biometrics — fingers and face ID may not work after death)
  • The Apple ID or Google account email and password associated with the phone
  • Whether you have a SIM PIN enabled (a second PIN required to use the SIM card)
  • Which authenticator apps are installed and which accounts they protect
  • Where your phone backup is stored (iCloud, Google, or local computer)

Phone backups

A current phone backup stored somewhere accessible is a safety net. If your phone is lost, stolen, or damaged before your death, a backup means your photos and data are not gone forever. After your death, a backup may be easier to restore than unlocking the device itself.

  • iPhone: Settings → [Your Name] → iCloud → iCloud Backup → Back Up Now. Or connect to a Mac/PC and back up with Finder/iTunes.
  • Android: Settings → System → Backup → Back up to Google Drive.
  • Check when your last backup was — it should be within the last 24 hours if automatic backup is enabled.
  • Make sure your executor knows your iCloud or Google account credentials to access the backup.

Medical ID

Both iPhone and Android allow you to set a Medical ID that is visible on the lock screen without unlocking the phone. This is primarily for emergencies — first responders can see your blood type, conditions, and emergency contacts. It can also display a note for whoever finds your phone. Consider adding a note: "In case of my death, contact [executor name] at [phone number]."

Tip

iPhone: Health app → your profile photo → Medical ID → Edit. Android: Emergency information is usually in Settings → About Phone → Emergency information.

Computers

Your computer likely contains documents, photos, creative work, downloaded files, and locally stored emails that do not exist anywhere else. If the hard drive is encrypted and no one knows the recovery key, this content is permanently inaccessible — encryption is designed to be that way.

Disk encryption

Modern operating systems encrypt their hard drives by default. On a Mac, this is FileVault. On Windows, it is BitLocker. On both, encryption is transparent while you are using the computer — you do not notice it. After death, it becomes critical: without either your login password or the encryption recovery key, the drive is unreadable.

Important

Both FileVault (Mac) and BitLocker (Windows) generate a recovery key when encryption is first set up. Most people dismiss this screen and never store the key. If you do not know yours, retrieve it now and store it with your will. Without it, your encrypted drive cannot be accessed by anyone — including data recovery specialists.

Finding your encryption recovery key

  • Mac / FileVault: System Settings → Privacy & Security → FileVault → click the info icon. If you stored the key with Apple (via iCloud), your executor can retrieve it with your Apple ID and password.
  • Windows / BitLocker: Settings → Update & Security → Device Encryption, or search for BitLocker in Control Panel. Recovery keys may be stored in your Microsoft account at account.microsoft.com/devices/recoverykey.
  • If you do not have either, generate a new recovery key now and store it with your will.
  • Write the key down physically — do not store it only on the encrypted drive itself.

Login passwords

Your computer login password is separate from the disk encryption recovery key. Your executor needs both the login password (to use the computer normally) and the encryption recovery key (to access the drive if the computer cannot be started normally). Store both in your password manager or with your will.

What to do about old computers

Old computers are often forgotten. A laptop from five years ago sitting in a drawer may contain photos, documents, or emails that do not exist anywhere else. Before donating or recycling any device, review its contents and either transfer what matters or securely erase it. Tell your executor about any old devices before disposing of them.

Tip

Mac: use Disk Utility → Erase before donating. Sign out of iCloud first (System Settings → [Your Name] → Sign Out). Windows: Settings → System → Recovery → Reset this PC → Remove everything.

Two-factor authentication (2FA)

Two-factor authentication is one of the most important security tools available — and one of the most overlooked problems in digital legacy planning. It protects your accounts while you are alive and can make them completely inaccessible after you die.

The 2FA paradox

When you enable 2FA on an account, you require a second form of verification in addition to your password. The most common forms are: a code sent to your phone number, a code generated by an authenticator app on your phone, or a physical security key. Your executor may have your password — but without the second factor, they cannot log in.

Important

If you use an authenticator app (Google Authenticator, Authy, Microsoft Authenticator) and your executor cannot unlock your phone, they cannot generate the codes needed to log in to any account that requires it — even with your username and password. This can block access to email, banking, social media, and everything else simultaneously.

SMS-based 2FA

SMS codes are sent to your phone number. After death, your phone number will eventually be deactivated by your network provider — typically within 30–90 days of the bill going unpaid. If your executor has not accessed the accounts before then, SMS-based 2FA codes will stop arriving. Most accounts have an account recovery process for lost phone numbers, but this can take weeks.

  • Tell your executor which phone number is linked to your accounts before the number is deactivated
  • Consider delaying cancellation of your phone contract until your executor has accessed all important accounts
  • For each critical account, document the phone number used for SMS 2FA in your account inventory

Authenticator apps

Authenticator apps generate time-based codes that change every 30 seconds. The codes are generated on your device and never sent over the network — making them more secure than SMS. But they are also more fragile in a legacy context: they exist only on one phone, and access requires the phone PIN.

  • Authy is the most legacy-friendly authenticator: it supports multi-device sync and cloud backup. If you use Authy and your executor has your Authy password and phone access, they can recover codes.
  • Google Authenticator (older versions) and Microsoft Authenticator do not have cloud backup by default — codes exist only on the phone.
  • Export your authenticator app data (where the app allows it) and store the backup encrypted with your will.
  • Consider switching critical accounts from authenticator-app 2FA to a method your executor can more easily access — such as a hardware security key stored with your will.
Tip

Authy: Settings → Accounts → Enable Multi-Device. This allows you to add Authy to additional devices. If a trusted person has access to your Authy-linked phone number and your Authy backup password, they can recover all your 2FA codes.

Recovery codes

When you set up 2FA on most services (Google, Facebook, GitHub, banking apps), you are offered a set of single-use backup recovery codes. These codes let you access the account even without your 2FA method — they are designed for situations exactly like this.

  • Google: myaccount.google.com → Security → 2-Step Verification → Backup codes
  • Facebook: Settings → Security and Login → Two-Factor Authentication → Recovery Codes
  • Apple: Recovery Key is set up via Apple ID settings — separate from your iCloud backup
  • For banking accounts: call your bank and ask about the account recovery process for a deceased account holder
Important

Recovery codes are extremely valuable for your executor. Most people see them once during setup and never save them. Download and store your recovery codes for every important account and keep them with your will or in your password manager's emergency access. If you no longer have them, you can usually regenerate them in your account's security settings.

External storage and old devices

External hard drives, USB sticks, old phones, and forgotten laptops often contain content that exists nowhere else — and their existence is often known only to their owner.

Label everything

External hard drives rarely have labels. A box in the attic might contain drives with irreplaceable family photos — or completely empty drives from a decade ago. An executor sorting through a home has no way to know which is which without opening each one.

  • Label every external drive clearly: "Family photos 2010–2018", "Work backups (can delete)", "Important — tax records 2015–2023"
  • Include external drives in your account inventory: location, what they contain, and your wishes for them
  • Consider encrypting important external drives — but store the encryption password with your will

Old phones and tablets

Old phones often contain photos that were never transferred to a computer or cloud service. The photos from five years ago on an old phone may be the only copy that exists — and the phone may be locked with a PIN you no longer remember.

  • Do not discard old phones without checking their contents first
  • If you find photos on an old device you want to preserve, transfer them to your current backup system now
  • If an old phone is locked and you cannot remember the PIN, factory reset it before discarding — do not leave it in a drawer for someone else to deal with
  • List the location of old devices in your account inventory or a physical note with your will

Secure disposal

Devices you are done with should be securely erased before disposal or donation — they contain far more personal information than most people realise: login credentials cached by browsers, photos, documents, emails, contact information, and potentially financial data.

  • iPhone: Settings → General → Transfer or Reset iPhone → Erase All Content and Settings
  • Android: Settings → General Management → Reset → Factory Data Reset
  • Mac: Shut down, hold Cmd+R on restart to enter Recovery Mode → Disk Utility → Erase, then reinstall macOS
  • Windows: Settings → Update & Security → Recovery → Reset this PC → Remove everything → Cloud download
  • For old hard drives: a free tool like DBAN (PC) or Disk Utility Secure Erase (Mac) overwrites data multiple times. Or physically destroy the drive platter if the data is sensitive enough.

Smart home and connected devices

Smart speakers, connected doorbells, thermostats, health trackers, and other IoT devices are rarely thought about in digital legacy planning — but they can complicate the administration of an estate.

Smart speakers and hubs

Devices like Amazon Echo and Google Nest are tied to an Amazon or Google account. After death, the device stops working when the account is closed — which may be an issue if a partner or family member still lives in the house and relies on it. Planning note: if smart home devices are shared with someone who will continue using them, make sure the account and any associated subscriptions are in a name that will continue.

  • List smart home accounts in your account inventory
  • Note which devices are shared with other household members
  • Consider whether subscriptions (Amazon Prime, Google One, Apple One) affect others in the household and should be transferred rather than cancelled

Health and fitness trackers

Health data from wearables (Apple Watch, Fitbit, Garmin, Oura Ring) may be medically significant for family members — for example, a history of a genetic condition. Some services allow data export; others delete it when the account is closed.

  • If your health data is medically significant, check whether your tracking service allows data export
  • Apple Health: you can export all health data as an XML file from the Health app — share it with your GP or include it in your archive
  • Consider whether any health data should be shared with blood relatives (for hereditary conditions) and express this wish in your Digital Wishes document

Security cameras and smart locks

Smart doorbells (Ring, Nest) and security cameras are tied to online accounts and may store footage in the cloud. Smart locks may be accessible only via app. These systems need to be addressed when administering an estate — particularly if others need to access the property.

  • Include security camera and smart lock accounts in your account inventory
  • Note the PIN or physical key backup for any smart locks
  • Be aware that cloud-stored doorbell footage is typically deleted when the account is closed — if any footage is relevant to an ongoing matter, preserve it before closing the account

What to tell your executor

Your executor needs a practical briefing on your devices — not just your accounts. A single "Device Information" document stored with your will can save weeks of frustration.

Your Device Information document

Create a physical or encrypted digital document with the following information for each device you own:

  • Device type and location (iPhone in bedside drawer; MacBook Pro in home office; external drive labelled "Photos" in spare room wardrobe)
  • Login PIN / password for each device
  • Disk encryption recovery key (FileVault / BitLocker) for each computer
  • Whether the device has 2FA on its associated account and where recovery codes are stored
  • What the device contains and whether the content is backed up elsewhere
  • What should be done with the device: keep, transfer, factory reset and donate, or discard
Tip

Keep this document updated. Any time you buy a new device, change a PIN, or enable disk encryption, update the document. Review it annually alongside your will.

Physical access

Digital access is only part of the challenge. Your executor also needs to physically locate your devices. A home with a home office, spare room, attic storage, and multiple drawers can take days to search systematically. Make it easy:

  • Tell your executor where your devices are kept — in conversation, not just in a document
  • Label storage boxes and drawers that contain technology
  • Keep a note in your will of the physical location of any device that contains content not backed up elsewhere
  • If your executor does not live with you, consider giving them a key or the door code if appropriate

Device checklist — quick reference

Critical
  • Store your phone PIN with your will or password manager emergency access
  • Find and store your disk encryption recovery key (FileVault / BitLocker)
  • Store 2FA recovery codes for all important accounts with your will
  • Tell your executor which authenticator app you use and where it is
High
  • Enable automatic phone backup to iCloud or Google
  • Store your computer login password with your will or password manager
  • Check when your phone last backed up (should be daily)
  • Document your phone number and note which accounts use SMS 2FA
Medium
  • Label all external hard drives with contents and importance
  • List all external drives and old devices in your account inventory
  • Review old phones — transfer any photos that exist nowhere else
  • Add a "find my devices" note to your executor briefing
Lower
  • Set up Medical ID on your phone with executor contact information
  • Review smart home accounts and note which are shared with household members
  • Document any health tracker data that may be medically significant
  • Add device disposal instructions to your Digital Wishes document