6 checks · Cyber Hygiene
Getting Started
This checklist is long on purpose - it covers everyone from someone who just wants fewer spam calls to someone with a genuine reason to fear a well-resourced adversary. Almost nobody should do all of it. Before working through the sections, spend ten minutes deciding what you are protecting and from whom. That single decision is what turns a list of 272 suggestions into a plan you can finish.
0 out of 6 (0%) complete, 0 ignored
| Done? | Advice | Level | Details |
|---|---|---|---|
Essential | Security advice only makes sense once you know what it is defending. Write down the handful of things that would genuinely hurt to lose: access to your email, your photos, your money, your home address, your medical history, a conversation staying private. Most people find the list is shorter than they expected, and that a few accounts - email above all - hold the keys to everything else. Those are where your effort belongs. | ||
Essential | The defences that stop an opportunistic criminal are not the ones that stop an abusive ex-partner, and neither is what stops a government. Be specific: automated attacks and credential stuffing affect everyone; targeted attention from someone who knows you is a different problem, and often needs physical and human measures more than technical ones; a state adversary changes almost every answer in this checklist. The EFF's Surveillance Self-Defense walks through this properly, and is worth reading before you change any settings. | ||
Essential | Almost all real-world account compromise comes down to a handful of causes: a reused password exposed in someone else's breach, a phishing page, an unpatched device, or a phone number used as a recovery method. If you do nothing else, do these four - a password manager with unique passwords everywhere, phishing-resistant 2FA on your email and financial accounts, automatic updates turned on, and your account recovery options tightened. Everything marked Essential in the sections that follow is chosen on the same basis. | ||
Essential | A measure you abandon in a fortnight offers no protection, and the effort spent on it is gone. Security that fights you every day gets worked around - the password policy that produces sticky notes, the encrypted messenger nobody you know will install, the VPN switched off because streaming broke. Choose the strongest option you can live with indefinitely rather than the strongest option that exists, and raise the bar later, once the current setup has become habit. | ||
Optional | The goal is not invulnerability; it is being a harder target than the attacker's next option, and limiting the damage when something does get through. This is why the later sections put as much weight on backups, compartmentalisation and recovery as on prevention. Treating a breach as something that may eventually happen, and planning for it, is more realistic and more useful than trying to make one impossible. | ||
Optional | Your accounts, devices and circumstances change, and so do the defaults of every service you use - a privacy setting you chose two years ago may have been reset, renamed, or quietly given a new meaning by a terms update. Put a recurring reminder in your calendar, once or twice a year, to walk back through the sections you have completed. Your progress is saved in this browser, so you can see what you did last time. |