Most people get compromised through the same few doors: a reused password, a missed update, a convincing fake email. Close those doors and you've handled the overwhelming majority of real-world risk. Here's the short list that actually matters.
Passwords & logins
- Use a password manager. One strong master password, unique passwords everywhere else. This alone fixes the biggest risk.
- Turn on two-factor authentication (2FA) on email, banking, and social accounts. An app or hardware key beats SMS.
- Protect your email above all. It's the master key — whoever controls your email can reset everything else.
Phishing & scams
- Slow down on urgent messages. "Act now or lose access" is the oldest trick there is.
- Check the real sender address and hover links before clicking. When unsure, go to the site directly instead of via the link.
- No legitimate company asks for your password or a 2FA code by phone or email. Ever.
The two habits that do the most work: a password manager and 2FA on your email. If you only do two things from this list, do those — together they block the attacks that hit ordinary people hardest.
Devices & data
- Keep everything updated. Auto-update your phone, computer, and browser — most attacks exploit flaws that were already patched.
- Back up what you'd cry to lose. A copy in the cloud plus one offline beats any ransomware.
- Lock your screen and encrypt your disk (FileVault on Mac, BitLocker on Windows) so a lost laptop isn't a data breach.
Get the full printable checklist
The Personal Cybersecurity Checklist is the complete, tick-the-box version — every step above plus account recovery setup, privacy settings, and a simple monthly routine to stay safe. Instant download.
Get the checklist →