18 checks · Cyber Hygiene
Human Aspect
Many data breaches, hacks and attacks are caused by human error. The following list contains steps you should take, to reduce the risk of this happening to you. Many of them are common sense, but it's worth takin note of.
0 out of 18 (0%) complete, 0 ignored
| Done? | Advice | Level | Details |
|---|---|---|---|
Essential | Emails can be easily spoofed. Verify the sender's authenticity, especially for sensitive actions, and prefer entering URLs manually rather than clicking links in emails. | ||
Essential | Fake pop-ups can be deployed by malicious actors. Always check the URL before entering any information on a popup. | ||
Essential | Unattended devices can be compromised even with strong passwords. Use encryption and remote erase features like Find My Phone for lost devices. | ||
Essential | Protect against camfecting by using webcam covers and microphone blockers. Mute home assistants when not in use or discussing sensitive matters. | ||
Essential | Use privacy screens on laptops and mobiles to prevent others from reading your screen in public spaces. | ||
Essential | Be cautious of phishing attempts. Verify URLs, context of received messages, and employ good security practices like using 2FA and not reusing passwords. | ||
Essential | Only download software from legitimate sources and check files with tools like Virus Total before installation. | ||
Essential | Ensure all personal data on devices or in the cloud is encrypted to protect against unauthorized access. | ||
Essential | When sharing documents, obscure personal details with opaque rectangles to prevent information leakage. | ||
Essential | HTTPS does not guarantee a website's legitimacy. Verify URLs and exercise caution with personal data. | ||
Optional | Remove yourself from public databases and marketing lists to reduce unwanted contacts and potential risks. | ||
Optional | Do not provide additional personal information when opting out of data services to avoid further data collection. | ||
Optional | Many apps and services default to data sharing settings. Opt out to protect your data from being shared with third parties. | ||
Optional | Data brokers compile and sell dossiers (addresses, relatives, phone numbers, employment) assembled from public records and purchased datasets. These profiles are what social engineers and stalkers use, and they are what makes answering "security questions" honestly so dangerous. Most brokers are legally obliged to honour deletion requests, and several jurisdictions (the EU under GDPR, California under CCPA/CPRA, and a growing list of US states) give you an enforceable right to demand it. Work through the major brokers one by one, or use a removal service if the volume is unmanageable. Expect to repeat this: profiles are commonly rebuilt within a year. | ||
Advanced | Keep different areas of your life on separate identities: separate email addresses, usernames and payment methods for banking, shopping, work and social accounts. If one is breached or linked back to you, the others aren't. This is the human counterpart to isolating programs and data on your computer. | ||
Advanced | Use WhoIs Privacy Guard for domain registrations to protect your personal information from public searches. | ||
Advanced | Use a PO Box or forwarding address for mail to prevent companies from knowing your real address, adding a layer of privacy protection. | ||
Advanced | Opt for anonymous payment methods like cryptocurrencies to avoid entering identifiable information online. |