Is Your Smartwatch a Security Risk? What Businesses Need to Know
First Contact is a managed IT service provider (MSP) based in Whitefield, Manchester, founded in 2001, offering IT support, cybersecurity, Microsoft 365 and device management for growing businesses.
You're in a client meeting. Your wrist buzzes. You glance down, and so does the person opposite you. Now you both know your sign-in code, that your boss wants a word, and that the pay rise email has landed.
Smartwatches are brilliant. They count your steps, nag you to stand up and save you from digging your phone out every thirty seconds. They also carry a surprising amount of your working life around on a screen the size of a digestive biscuit.
If you've only got a minute: A smartwatch is a small computer strapped to your wrist, connected to your phone, your email and often your work accounts. The real risks are simple ones: messages and codes on display, lost watches that still work, and cheap gadgets that don't look after your data. Hide notification content, lock the watch, approve sign-ins on your phone, keep it updated and add wearables to your device policy.
The snitch on your wrist: what a smartwatch actually knows
In our recent post on the LG smart TV controversy, researchers said the TVs they tested could spot the other devices on a home network, including phones and smartwatches. That's a handy reminder that your watch isn't jewellery. It's a connected device, and other devices can see it.
Think about what yours has access to. Your messages, your calendar, your contacts, your location, your email previews and, for a lot of people, the prompts that approve sign-ins to work accounts. All of it lives on something you take to the gym, leave on the bedside table and occasionally drop in a car park.
Security researchers have been poking at smartwatches for years. Back in 2015, a study by HP found the popular models it tested had weak logins, insecure connections and a habit of passing data on to third parties. The same year, researchers at the University of Illinois showed a watch's motion sensors could be used to guess what its wearer was typing. Things have improved since, but the principle hasn't changed: anything that knows a lot about you is worth protecting.
Tiny screen, big leaks: the three real risks
Forget Hollywood hacking. For most businesses, the realistic problems are much more ordinary:
Notifications on display. Two-factor codes, client emails and HR messages pop up on a screen anyone across the table can read. Nobody needs to hack anything. They just need to look.
Lost watch, open door. A watch without a passcode, or one that stays unlocked when it's taken off, can keep showing messages and even approving sign-ins for whoever finds it.
Company data on a mystery gadget. Work email synced to a bargain watch from a brand nobody has heard of is company data sitting on a device you know nothing about, and it probably isn't covered by your device policy.
None of these need a criminal mastermind. They need a busy person, a quick glance and a bad day.
Not panic, just housekeeping: five sensible fixes
Hide the message content. Set the watch to show an alert without the preview. You still know something's arrived. The person opposite doesn't get to read it.
Lock it properly. Turn on a passcode and wrist detection, so the watch locks the moment it comes off.
Approve sign-ins on your phone. A tap on a tiny screen makes it far too easy to approve a request you didn't make. Do it where you can see the details.
Stick to brands that get updates. Reputable makers keep fixing security problems. Cheap no-name watches often never get a single update.
Put wearables in your device policy. If a watch shows work email, it's handling company data. Say what's allowed, how it's secured and what to do if one goes missing.
Coming soon to a face near you: smart glasses, which add a camera to the mix. That's a post for another day.
Key takeaway
Your smartwatch isn't the enemy. It's just another computer, and it happens to live on your wrist, where everyone can see it. Give it the same basic care as your phone or laptop: a lock, sensible settings and a place in your device policy. Then the only thing it will be telling people is that you've hit your step count.
FAQs
Is a smartwatch a security risk for a business?
It can be. Smartwatches display messages and sign-in codes, stay connected to your phone and accounts, and are easy to lose. They are not dangerous in themselves, but they need the same basic settings and care as any other device that touches company data.
Can someone see my messages on my smartwatch?
Yes, if your watch shows full message previews. Anyone near you can glance at an email, text or two-factor code as it pops up. Most watches let you hide message content so only a simple alert appears.
Should I approve work sign-ins on my smartwatch?
It is safer to approve sign-ins on your phone, where you can see more detail about who is signing in and from where. A quick tap on a tiny screen makes it easier to approve a request you did not make.
Should smartwatches be included in a company device policy?
Yes. If staff receive work email, messages or sign-in prompts on a watch, it is handling company data. A good device policy covers passcodes, notification settings, approved brands and what to do if a watch is lost.
Can First Contact help manage staff devices and security?
Yes. First Contact is a Manchester-based managed IT provider that helps growing businesses set up device policies, secure sign-ins and Microsoft 365 security, so phones, laptops and wearables stay useful without becoming a risk.