The laptop in your bag is not the same asset abroad that it is at home. At home it sits behind a network you control, under laws you understand, in a building you can lock. The moment it enters an airport queue it becomes a container of your organisation's correspondence, credentials and negotiating position, held by a person with no leverage, in a jurisdiction where different rules apply and where handing it over may be the only way to complete the journey.

Most travel security advice is about the traveller. This is about the device — what you carry, how it is configured, and what you do with it when you get home.

There are three separate problems, and conflating them is why most travel policies fail. The border is a legal problem: the search is lawful, documented and usually not about you personally. The network is a technical problem: hotel and conference infrastructure is a known targeting channel. The room and the cable are physical problems: unattended devices and untrusted ports. Each needs a different answer.

The border: lawful, routine, and rising

In fiscal year 2025, US Customs and Border Protection conducted 55,318 searches of electronic devices — 41,728 involving non-US citizens and 13,590 involving citizens. That is a 17.6% increase on 2024 and 32.4% on 2023, and the third quarter of FY2025 set a single-quarter record at 14,899.1

Two features of that regime matter more than the totals. The first is that a basic search — an officer scrolling through the device by hand — requires no suspicion at all; 50,922 of the FY2025 searches were of this type. An advanced search, where the device is connected to external equipment and its contents copied and analysed, requires reasonable suspicion of a legal violation or a national security concern, plus supervisory approval.1 The second is scale in the other direction: against 419 million travellers processed, roughly 0.01% had a device searched.1

Hold both facts at once. The probability for any given trip is very low. The consequence, if it happens to the wrong person on the wrong trip, is that a complete copy of a device leaves your control permanently and lawfully. Security planning for principals is about the second number, not the first.

The United Kingdom illustrates the legal texture. Under Schedule 7 of the Terrorism Act 2000, officers at ports may examine a traveller to determine whether they are or have been involved in terrorism without needing any suspicion. The traveller can be required to provide information including passwords and PINs for their devices, and wilful failure to comply is itself a criminal offence.2 There is no equivalent of a right to silence here that carries no penalty.

The best-documented case remains David Miranda, stopped at Heathrow on 18 August 2013 and held for around nine hours while carrying encrypted material connected to the Snowden disclosures; his devices were seized. The High Court upheld the stop in 2014. The Court of Appeal, in R (Miranda) v Secretary of State for the Home Department [2016] EWCA Civ 6, held on 19 January 2016 that the Schedule 7 stop power was incompatible with Article 10 of the European Convention in relation to journalistic material, because it lacked adequate safeguards — the obvious one being independent scrutiny before confidential material is examined.3

A copy taken lawfully is still a copy. Legality is not a security control, and a favourable judgment three years later does not un-copy a hard drive.

Locked is not one state: BFU and AFU

This is the single most useful technical fact for a traveller, and almost nobody outside forensics knows it.

A modern phone has two meaningfully different locked states. Before First Unlock (BFU) is the state after a power cycle, before the passcode has been entered even once: the encryption keys are not resident in memory, and extraction recovers little more than device metadata and a narrow set of data accessible without unlock. After First Unlock (AFU) is the state after the passcode has been entered at least once since boot — the screen may be locked again, but key material is now in memory, and forensic extraction recovers substantially more.4

The operational consequence is short: a phone that has been powered off and not yet unlocked is a far worse target than a phone that has merely been locked. Power the device fully off before you join the immigration queue, not simply press the side button.

Both platforms now provide a backstop. iOS 18.1 introduced an inactivity reboot that restarts an iPhone after 72 hours locked, returning it to BFU, with no prompt and no way to interrupt it; Android added an equivalent automatic restart after 72 hours locked.5 Treat these as a safety net for a device that is already out of your hands, not as a travel strategy. Seventy-two hours is a long time.

Turn off biometrics before you cross

A face or a fingerprint can be applied to a device without your cooperation. A passcode in your head cannot. That asymmetry is practical before it is legal, and it is the reason to switch to passcode-only for the crossing itself — on iPhone, holding the side and volume buttons until the power-off prompt appears disables Face ID until the passcode is next entered; powering the device off achieves the same and more.

The legal position, at least in the United States, is genuinely unsettled. The Ninth Circuit has held that compelling a fingerprint unlock does not violate the Fifth Amendment, treating it as non-testimonial in the way a blood draw is. In January 2025 the D.C. Circuit went the other way in United States v. Brown, holding that compelling a thumbprint unlock did violate the privilege — creating a circuit split that may eventually reach the Supreme Court.6 A passcode has generally received stronger protection than a biometric across these cases.

This is context, not legal advice. Rules differ sharply by country, refusal carries real consequences — a criminal offence in the UK, denial of entry for non-citizens in most places — and anyone travelling with genuinely sensitive material should take jurisdiction-specific counsel before departure, not at the desk.

The hotel is a hostile network

The clearest documented case of executives being targeted through hotel infrastructure is the campaign Kaspersky named Darkhotel, disclosed publicly in 2014 after operating since at least 2007. Its operators compromised hotel networks in Asia and waited. When a target checked in, the hotel's own captive portal offered them what looked like a routine software update, and the malware was delivered on the way to the room.7

The detail that should change behaviour is the targeting precision. Guests authenticated to those networks with their surname and room number, and only a very small number of guests ever received the payload — researchers who deliberately stayed at affected hotels were not attacked. Victims were CEOs, senior vice presidents, sales and marketing directors and senior R&D staff.7 The attack was not fishing for whoever connected. It knew who was arriving, and when.

Your travel itinerary is therefore a security document. It is also, in most organisations, circulated by email to a dozen people, held by a travel agent, and visible to hotel staff.

The charging port is not just power

“Juice jacking” warnings were, for years, somewhat theoretical — phones ask “Trust this computer?” before allowing data over USB, and that prompt was the defence. In August 2025 researchers from Graz University of Technology presented ChoiceJacking at the USENIX Security Symposium, the first technique to defeat that mitigation. A malicious charger emulates an input device and injects the keystrokes that accept the trust prompt itself — the approval appears to come from the user, who never touched the screen. The fastest variant completes in about 133 milliseconds.8

The mitigation is trivial and absolute: carry your own power. A charger and cable you own, plugged into mains, or a power bank. Never an airport, lounge, hotel, conference or hire-car USB port. Where a shared port is unavoidable, a USB data blocker — a passthrough adapter with the data pins physically absent — costs less than a taxi fare.

What delegations from Bangladesh get wrong

Outbound travel from Bangladesh has been growing at roughly 12–15% a year, with Malaysia, Thailand, Singapore and India absorbing much of it alongside long-standing business routes to buyer markets in Europe, North America and East Asia.9 Delegations travel constantly — trade bodies, ministries, RMG executives to buyer meetings, institutions to donor and multilateral conferences. In assessments, the same five patterns recur.

  • One device carries everything. The phone that holds a decade of WhatsApp history, the personal photo library, the MFS accounts and the board correspondence is the same phone that goes through the queue. Nothing has been separated, so everything is exposed together.
  • WhatsApp is the system of record. Contracts, prices, instructions to staff and negotiating positions live in message history rather than in a controlled system. The archive travels because the app travels.
  • The airport SIM swap. Landing and putting a local SIM into the primary handset moves the number that receives every recovery code onto an unfamiliar network and an unfamiliar operator's counter process — the exact exposure covered in our piece on SIM swap fraud. Use a separate handset for local connectivity, or eSIM, and leave the number that anchors your accounts alone.
  • Delegation documents live in someone's personal cloud. Typically a junior staffer's personal Drive account, shared by link, because it was the fastest way to get the pack to everyone before the flight. That account has no MFA policy, no revocation, and no owner after the trip.
  • Nobody owns the policy. There is a physical security lead and a protocol lead. There is no device lead, so no one confiscates the unmanaged laptop, checks that remote wipe works, or asks what happens if a bag is stolen on day two.

The clean-device model

The answer is not more caution. It is carrying less. There are three postures, and you should choose deliberately rather than default into the third.

Tier 1 — dedicated travel devices

A separate phone and laptop that exist only for travel. Minimal installed applications, no historical message archive, no local document store, no saved personal accounts. Work is reached through a remote session or a tightly scoped cloud workspace, so the data stays home and only pixels travel. The device is enrolled in management with remote wipe verified before departure, and it is re-imaged on return as a matter of routine rather than suspicion. This is the correct posture for high-risk destinations and for principals whose correspondence would be independently valuable.

Tier 2 — hardened primary device

The everyday device, prepared: archives offloaded and removed, unnecessary applications uninstalled, cloud sync paused, sensitive channels signed out, disk encryption confirmed, a strong alphanumeric passcode replacing a six-digit PIN, and biometrics disabled at each crossing. Appropriate for routine business travel to lower-risk destinations. Cheaper than Tier 1, and materially better than nothing.

Tier 3 — travel as normal

What almost everyone actually does. Defensible for a short trip carrying nothing sensitive. Indefensible for a delegation carrying a negotiating position, and the reason a Tier 1 handset — a modest one-off cost, reused across every trip for years — is one of the better-value controls available to an organisation of any size.

For the highest-risk principals there is one more lever. Apple's Lockdown Mode sharply reduces the attack surface for people facing targeted mercenary spyware. Apple states it is not aware of any successful mercenary spyware attack against a device with Lockdown Mode enabled, and Citizen Lab has confirmed cases where it actively blocked attacks in progress.10 It costs some convenience — link previews, some attachment types, some connections. For a principal on a sensitive trip, that is a good trade.

Before departure

  • Decide the tier for each traveller and each device, in writing, and name who owns it.
  • Strip the device: archives off, unused apps removed, cloud sync paused, sensitive accounts signed out.
  • Confirm full-disk encryption and replace short PINs with a long alphanumeric passcode.
  • Test remote wipe and remote location on the actual device — not the policy document that says it is enabled.
  • Back up fully before departure, so wiping the device on the road costs nothing but time.
  • Rotate credentials that will be used abroad, and ensure recovery does not depend on the phone number that is travelling.
  • Move authentication to hardware keys or an authenticator app, and remove SMS fallback where the platform permits.
  • Agree an out-of-band contact channel and a duress signal within the delegation, and confirm both work before the flight.
  • Pack your own charger, cable and power bank. Add a data blocker.
  • Brief everyone — including junior staff and interpreters — on what to do if a device is retained, and give them a phone number that will answer.

In country

  • Power devices fully off before immigration. Not standby — off.
  • Never leave a device unattended, including in a room safe. A room safe defeats an opportunist, not a professional, and it conveniently gathers all your valuables in one predictable place.
  • Do not use hotel or conference Wi-Fi for anything sensitive. Use a mobile hotspot on a data-only SIM, with an always-on VPN — after checking whether VPN use is restricted where you are going.
  • Decline software update prompts that appear on arrival or after joining a network. Update over your own connection, or not at all until you are home.
  • Assume meeting rooms, cars and hotel rooms are not private for sensitive conversations, and hold those conversations elsewhere.
  • Report a lost or retained device immediately, not at the end of the day.

On return, treat the device as suspect

This is the step organisations skip, and it is the one that determines whether a travel compromise stays contained or becomes a network compromise.

  • Do not plug a returning device into the core network before it has been checked. A travelled device belongs in an isolated segment until cleared — the same logic set out in our piece on segmentation.
  • Re-image Tier 1 devices unconditionally. Not if something looked wrong. Always. The point of a disposable posture is that you never have to make a judgement call.
  • Rotate every credential used during the trip, and review sign-in logs for sessions from unexpected locations or times.
  • Treat any device that left your sight as compromised until proven otherwise, particularly one retained at a border or returned by hotel staff.
  • Debrief. Anything unusual — a prolonged secondary inspection, a device taken out of view, a room entered, a persistent new contact — is intelligence for the next trip.

The trade you are actually making

None of this is about paranoia at the airport. It is about deciding, before you pack, what you are willing to lose — and then not carrying anything else. A delegation that travels with a clean phone, a remote workspace and a written procedure is not more cautious than one that does not. It is simply carrying less, so a search, a theft or a compromised network costs it less.

The organisations that handle this well are rarely the ones with the largest budgets. They are the ones where somebody was made responsible for the devices before the tickets were booked.

Sources

  1. US Customs and Border Protection, border search authority for electronic devices and FY2025 enforcement statistics — cbp.gov, CBP Enforcement Statistics FY2025; on the basic/advanced distinction and supervisory approval, DHS, Border Searches of Electronic Devices at Ports of Entry
  2. Schedule 7, Terrorism Act 2000, and the accompanying Code of Practice — Counter Terrorism Policing; on the requirement to provide passwords and the offence of wilful non-compliance, Open Rights Group
  3. R (Miranda) v Secretary of State for the Home Department [2016] EWCA Civ 6, 19 January 2016 — Press Gazette, Liberty
  4. Device lock states in mobile forensics, Before First Unlock and After First Unlock — Teel Technologies, DigForCE Lab, Dakota State University
  5. iOS 18 inactivity reboot after 72 hours locked — Magnet Forensics, Hexordia; equivalent Android automatic restart after 72 hours — Cyber Press
  6. Compelled biometric unlocking and the Fifth Amendment — on the D.C. Circuit's January 2025 decision in United States v. Brown, Arnold & Porter; on the resulting circuit split, Center for Democracy & Technology
  7. Kaspersky Lab, The Darkhotel APTSecurelist, Kaspersky threat definition
  8. Draschbacher et al., ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade ago, 34th USENIX Security Symposium, 2025 — usenix.org; summary via Kaspersky
  9. Growth in outbound travel from Bangladesh, Bangladesh Tourism Board figures as reported — Aviation Express
  10. Apple, Lockdown Mode — Apple Newsroom, Apple Support; on independently confirmed blocked attacks, 9to5Mac

Figures are quoted as published by the sources listed above and reflect the period each covers. Border powers, device inspection practice and VPN legality differ substantially between countries and change frequently — confirm the position for your destination before you travel.