Privacy and Security Runbook

1. Start Here

1. Start Here

1.1 Overview

This is a plain‑English, step‑by‑step runbook introducing general security and privacy concepts and providing guidance on how to protect your computers, phones, and yourself from common threats such as scams, stolen passwords, malware, and lost devices. The focus is on a safe default mindset and simple choices without requiring any advanced knowledge.

This guide is for anyone who wants practical protection without having to become a cybersecurity expert, install large amounts of additional software, or make complicated configuration tweaks.

The scope is on Windows, macOS, and Linux operating systems, iPhone and Android mobile devices, and identity safety processes for US citizens.

All abbreviations are spelled out the first time you encounter them, with full definitions provided in the appendix. This runbook also contains a set of checklists to get started and playbooks if you find your security or privacy has been compromised.

1. Start Here

1.2 Core Concepts

Everything in this guide flows from these four concepts. Keep them in mind and most day‑to‑day decisions get simpler.

Protect Yourself

Protect Your Data

Minimize Your Exposure

Have a Recovery Plan

1. Start Here

1.3 How to Use This Guide

There is a lot of information in this runbook, and at first glance, it might be intimidating. Take it piece-by-piece. This runbook is laid out in a series of topics dealing with a specific security and privacy area, prioritized based on risk, and tiered into:

Plan to dedicate some time each week; it doesn’t have to be much, just 30 minutes will go a long way. I recommend that you go topic-by-topic on your first pass, read the general topic information and apply The Basics. Then go back through and apply Better Protection wherever possible. Finally, take a final pass and apply any Extra Credit you are comfortable with. Don’t worry if you aren’t able to apply everything, every little bit counts. You can always reach out to me if you have any questions. If you’re holding this runbook then you know how to get hold of me.

2. Accounts and Identity

2. Accounts and Identity

2.1 Authentication (passwords, MFA, passkeys, biometrics)

Core Concepts: Protect Yourself, Protect Your Data

When you log into a computer or website with a User ID and password, you are authenticating; proving you are who you claim to be. Get this topic right and you block 90% of account compromises.

2.1.1 Understanding Authentication

Authentication answers the question "who are you?" A User ID is your unique identifier (often an email address). A password is a single verification factor paired with your User ID. Together, they prove you're the legitimate owner of an account.

2.1.2 The Basics

Use a Password Manager

A password manager stores all your login credentials, auto-fills them when you need them, and can generate secure, random passwords for each account. This means you only need to remember one password, the master password for your password manager, or vault.

Why use a password manager?

NEVER use your browser's built-in password storage. While modern browser password managers have improved, dedicated password managers offer superior security features including cross-platform sync, security audits, secure sharing, and breach monitoring. Browser-based storage also creates a single point of failure if your browser is compromised.

Important: DO NOT FORGET YOUR MASTER PASSWORD! You can share this with a friend or family member who can store it in their vault in case you forget. If you use a password manager which offers account recovery, set it up and carefully protect the recovery information.

Recommended: Bitwarden (https://bitwarden.com/). It's web-based so you can access it anywhere, has browser plugins, mobile apps, and offers both free and premium service. It includes all the features mentioned above.

If you want, you can use my self-hosted Bitwarden service at https://pass.landisfam.org. This offers the same protections as Bitwarden’s official service, but less likely to be targeted by attackers. However, I still cannot recover your account if you forget your master password.

Once enrolled, install the applications in your browsers and on your mobile devices. Enable auto-fill, and start populating your vault by logging into each email, financial, and health related accounts, since those contain your most sensitive information. When doing this, I recommend you reset each password, most password managers have a password generator, and secure them in your password manager. If you use a browser extension, most password managers prompt you to automatically add information for websites not already in the vault.

While going through this process, I also recommend you go through each site’s security settings. Review your security questions (see that topic below) and force logout of all devices. Note that afterward you will have to log in again on all devices.

Create Strong Passwords

Passwords that are easy to remember tend to be easy to guess. The solution is to make them long, using a phrase you can remember, but would take an attacker a very long time to guess or to use brute-force methods to crack your account. Follow this link and experiment with different passwords: https://www.security.org/how-secure-is-my-password/

How to Create a Strong Password:

There is an adage in Bridge (a card game for old people), “length over strength.” A long, simple password is more secure than a short, complex password. Think of a line from your favorite song, poem, or quote. Take a few words from that line, capitalize some letters, mix in numbers, and add a special character or two.

Example: From Robert Frost's "The Road Not Taken":

Email accounts deserve the highest level of protection. When you forget a password, most sites send a reset link to your email. This means if someone gains access to your email, they can potentially reset passwords for all your other accounts. I recommend 16+ characters for email passwords.

Account Type

Password Length

Password Manager

20+ characters

Email

16+ characters

Everything else

12+

Of course, if you use a password vault, you can have the best of all words, and use unique, 20+ character, complex passwords for all your accounts without ever having to worry about forgetting them. Again, just make sure the password for your password manager is also strong, and have a recovery method in case you do forget it.

Never Reuse Passwords

Use a unique password for every account. If one site gets breached, attackers will try that password on other popular sites. Reused passwords mean one breach potentially compromises all other accounts which use that same password. Your password manager, once populated, can verify that all your accounts have unique credentials.

Handle Security Questions Carefully

Security questions are a weak way to verify your identity. The answers are often public information or easy to find through social media. When forced to use them:

Your password manager likely has a “notes” section for each item in your vault, or a separate “notes” folder. You can put your security questions in one of those.

Set Up a Recovery Email

Create a secondary email account to use as a recovery address for your primary email. If you can't access your main email, you can use the recovery email to regain access to your primary email account. Keep this secondary email account highly protected too, and only use it as a recovery account; do not use it for any other purpose.

Enable Login Alerts

Turn on notifications for new logins. Most services offer this. When enabled, you'll get an email or text when someone logs into your account from a new device or location. If it wasn't you, you'll know immediately. You can typically fine this option in security settings.

2.1.3 Better Protection

Expand Password Manager Use

Once you have your critical applications vaulted (email, financial, and health-related accounts), you’ll want to go back and begin adding other important sites and applications like cloud storage (Google drive, iGloud, OneDrive, Dropbox), social media, and shopping accounts. Follow the same process to change the password using the password manager’s password generator, forcing logout of active logins, and updating security questions.

Enable Multi-Factor Authentication (MFA)

MFA adds a second step to logging in; usually a code sent to your phone or generated by an authenticator application. If you use MFA, even if someone steals your password, they can't access your account without this second factor.

Common MFA methods (from least to most secure):

Where to enable MFA:

Recommended: Google authenticator is used very broadly, is available in both android and apple app store, and has a cloud backup feature in case your device is lost, stolen, or breaks.

The option to enable MFA on a website or application is typically in security options. You will usually be offered a choice of authenticator the site supports. Select the authenticator you have installed on your phone, open that application on your phone, and scan the QR code provided by the website by clicking the `+` icon on the authenticator application.

Important: When you enable MFA, you'll receive recovery codes (usually 8-10 random codes). Store these safely, like in your password manager, as they're the backup if you lose your authenticator; phones break, can get stolen, or get lost. You can also install the authenticator application on multiple devices, such as a tablet, so if you lose one device you do not lose access. Plus it is easier to restore to a new device that way.

Use Passkeys When Available

Passkeys are a newer, phishing-resistant way to sign in. They use cryptography instead of passwords, and are built into many devices. They're easier to use than passwords and more secure than MFA. Enable them when offered. Major sites like Google, Microsoft, Apple, and others now support passkeys. To start using passkeys, enable them in the website or application, typically in security options. Once enabled, you will be prompted to generate a passkey, typically through fingerprint or facial recognition. Passkeys are device-specific, but can be linked across all your devices.

Understanding Biometrics

Fingerprints, Face ID, and other biometrics are convenient but come with trade-offs:

Pros:

Cons:

Best practice: Use biometrics as a second factor alongside passwords, not as your only authentication method. For banking apps with very sensitive data, consider using a PIN instead of biometrics for unlocking the app on your phone.

Exception - Passkeys: Passkeys are different. When you use biometrics to unlock a passkey, the biometric stays on your device and only unlocks a cryptographic key. The website never sees or stores your biometric data. This makes passkeys with biometric unlock more secure than traditional biometric-only authentication, and it's safe to use them as your primary sign-in method.

Check for Compromised Accounts

Visit https://haveibeenpwned.com every few months to see if your email addresses have appeared in recent, known data breaches. If you find your information was compromised:

2.1.4 Extra Credit

Use Hardware Security Keys

Hardware authenticators like YubiKey https://www.yubico.com are physical devices you plug into your computer or tap against your phone. They're the most secure form of MFA because they can't be phished, intercepted, or duplicated.

Hardware keys are ideal for:

Tip: Set up two keys and keep one in a safe place as a backup. That way if you lose your primary key, you'll still have access.

Use One-Time Passwords for Apps

Some services let you create app-specific passwords, or one-time passwords (OTP), instead of using your main password. This is especially useful for email accessed through desktop or mobile applications. The password only works once to connect the first device that uses it. Even if malware captures it, it's useless to an attacker.

Set these up for any critical applications that contain sensitive information. It may take a little hunting to find these settings. In Gmail, for example, “App Passwords” are within the 2-step verification settings, beneath the list of second steps. Once you generate the one-time password, log out of that application on your device, then log back in using the one-time password. Repeat this for all devices (phone, tablet, desktop, and laptop applications).

Review Account Security Regularly

At least quarterly, check your important accounts:

Separate Email for Sensitive Accounts

Consider using a separate email account exclusively for your most sensitive sites (financial and health portals) that you never use for anything else (shopping, social media, or regular communication). This makes it much harder for attackers to find or target this email, since it won't be in typical data breach lists. Ideally, you should have a total of 3 or 4 email accounts. One, primary account you use for regular communication, a secondary email for sensitive sites like financial and health portals, and a recovery email address which you use to recover your email accounts if you lose access. A fourth email can be used to split out messages from shopping, social media accounts, and so forth, since those generate the most spam.

When providing an email address to a company you can also use https://10minutemail.com. This is a service which offers disposable email accounts; they are only valid for 10 minutes by default, although you can extend 10 minutes at a time. While this account is active you can send and receive email like any other email account. Using this keeps your regular email private if you just want to try out a service but aren’t certain you want to use it long-term. Once you register this email address with any service, if you decide to keep that service, you can always change your email address to one of your others.

2. Accounts and Identity

2.2 Scam and Social Engineering Defense

Core Concepts: Protect Yourself, Protect Your Data

Humans are the weakest link in security. Even perfect technical security fails if you're tricked into handing over credentials or sending money. The good news is most scams use the same playbook, so learn to recognize the patterns.

2.2.1 Understanding Social Engineering

Social engineering is the art of manipulating people into giving up confidential information or taking actions that compromise security. Attackers exploit human psychology, our trust, fear, curiosity, and desire to be helpful, rather than technical vulnerabilities.

Common tactics attackers use:

Your defense: Slow down. Verify. Be skeptical. Trust your gut; if something feels off, it probably is.

2.2.2 The Basics

Recognize Phishing Emails and Texts

Phishing is a fake message designed to trick you into clicking a link, opening an attachment, or sharing sensitive information. Here's how to spot them:

Before clicking any link in an email or text message:

On desktop:

On mobile:

A quick note about QR codes, since those are really just links. Legitimate examples of these can be found on company advertisements, restaurant menus, business cards, etc. Scammers also sometimes use QR codes to bypass email security filters and trick you into visiting malicious sites. This is called “quishing.”

How it works:

Protection:

Never Open Unexpected Attachments

Attachments are a common way to deliver malware. Follow these rules:

Verify Unexpected Requests

If you receive an unexpected request whether by email, text, phone, or social media, pause and verify:

Example: Your bank sends a text saying your account is locked. Don't click the link in the text. Instead, call the number on the back of your credit or debit card.

Watch for Caller ID Spoofing

Scammers can make their phone number appear as any number they want on your caller ID, including your bank, the IRS, or even your own number.

Protection:

Recognize Gift Card and Wire Transfer Scams

No legitimate organization will ever ask you to pay with gift cards or wire transfers. Gift cards are untraceable, and both gift cards and wire transfers are non-refundable. That's why scammers love them. If someone asks for payment this way, it's a scam, no exceptions!

Spotting Tech Support Scams

Tech support scams come in many forms. Pop-up warnings with messages like "Your computer is infected! Call this number immediately!" These are fake. Real security warnings don’t give you a number to call. Never call this number! Close the browser tab and don’t go back. If it came from a site you think is legitimate, like your bank, notify them immediately.

Cold calls are another type of scam. Someone claiming to be from Microsoft, Apple, your internet provider, or even from the FBI or local police, stating that they have detected a problem with your computer. They usually ask for remote access to “fix” the problem. What they want is access to your computer to install malware, steal files, or extort money for fake "repairs." Never give remote access to unsolicited callers. Real tech companies don't call you unsolicited about computer problems; hang up immediately. Block the number if they keep calling back.

Watch for Impersonation on Social Media

Scammers create fake profiles impersonating:

Red flags:

Verification: If a friend messages you with an unusual request, call or text them directly (not through the suspicious message) to verify.

2. Accounts and Identity

2.3 Identity and Cloud Account Safety

Core Concept: Protect Yourself, Protect Your Data

Your identity and your cloud accounts are two of your most valuable digital assets. Your identity can be used to open accounts, file fraudulent tax returns, and ruin your credit. Your cloud accounts, Google, Microsoft, Apple, hold years of emails, photos, documents, and are often the gateway to resetting passwords for everything else.

A compromised identity or cloud account can create a cascading failure across your entire digital life. This section covers how to protect yourself.

2.3.1 Understanding the Risks

What is identity theft?

Identity theft is when someone uses your personal information, social security number, name, date of birth, address, etc, to impersonate you.

Common identity theft scenarios:

How identity theft happens:

2.3.2 The Basics

Guard Your Personal Information

Do not ever give out any information to someone who calls you! If you receive a call asking you to confirm your identity by providing personally sensitive information, explain that you do not provide this on a call you did not initiate.

Before you ever give sensitive, personal information out to anyone, ask these questions:

Review Third-Party App Access

Apps you've authorized can access your cloud account data. Review and revoke unnecessary access.

How to review:

Google:

Microsoft:

Apple:

Do this quarterly.

Configure Account Privacy Settings

Cloud providers collect extensive data about you. Limit what they collect and share. Do the same for social media accounts, such as facebook, instagram, etc.

Google:

Microsoft:

Apple:

Shred Sensitive Documents

Physical documents can reveal your identity.

Documents to shred:

Shredder type: Use cross-cut or micro-cut shredder, not strip-cut (too easy to reconstruct).

2.3.3 Better Protection

Opt Out of Pre-Approved Credit Offers

Pre-approved credit offers in the mail can be stolen and used to open accounts.

How to opt out:

This reduces mail clutter and risk of identity theft

Use Privacy Services for Online Signups

Avoid giving your real email and phone number to every website.

Email masking:

Phone masking:

Review Cloud Storage Sharing

Make sure you're not unintentionally sharing files or folders.

How to check:

What to look for:

2.3.4 Extra Credit

Opt Out of Data Brokers

Data brokers collect and sell your personal information. You can opt out, but it's tedious.

Major data brokers:

DeleteMe https://joindeleteme.com is a paid service that handles opt-outs (~$130/year)

3. Your Devices

3. Your Devices

3.1 Software and App Safety

Core Concepts: Minimize Your Exposure, Protect Your Data

Malware often disguises itself as legitimate software. A free game, a helpful utility, even a security tool can hide viruses, spyware, or ransomware. The software you install is one of the largest parts of your attack surface. Knowing what's safe to install, and what to avoid, is critical.

3.1.1 Understanding Software Risks

Every piece of software you install increases your attack surface; the number of ways someone could compromise your system. Even legitimate software can have security vulnerabilities that attackers exploit.

Common ways malicious software spreads:

Think before you install. Every piece of software is a potential security risk. Ask yourself:

When in doubt, don't install it.

3.1.2 The Basics

Never Use Pirated Software

This cannot be emphasized enough: Pirated or "cracked" software is one of the most common ways to get infected with malware.

Why pirated software is dangerous:

Alternatives to piracy:

Use Official App Stores Only

App stores vet software before allowing it in their store. While not perfect, this dramatically reduces your risk.

Mobile devices:

Desktop computers:

Avoid:

Other potentially useful software sites (use these with caution):

Verify Download Sources

When downloading directly from a website instead of an app store, make sure you’re downloading from the official publisher

Steps to verify:

Example: You want VLC media player. Search "VLC official download" and go to videolan.org (the real site), not vlc-player-download.com (fake).

Watch for Bundled Software

Some legitimate software tries to install additional programs during installation, toolbars, antivirus trials, browser plug-ins.

How to avoid unwanted software:

Understand App Permissions

Permissions tell you what an app can access on your device. Always check permissions before installing.

Ask yourself: Does this make sense?

Permissions to be extra careful about:

If permissions don't make sense for what the app does, don't install it.

3.1.3 Better Protection

Review App Permissions Regularly

Apps can request additional permissions after installation. Review these periodically:

On iPhone:

On Android:

On Windows:

On Mac:

Do this review quarterly.

Uninstall Unused Apps and Software

Software you don't use is a security risk for no benefit. Every unused app is a potential vulnerability.

Monthly cleanup routine:

How to properly uninstall:

Don't just delete the icon or folder: Use the proper uninstall process to remove all components.

Keep Software Updated

Software updates fix security vulnerabilities. Delaying updates leaves you exposed to known exploits.

Enable automatic updates for:

For software without auto-update: Check for updates monthly. Most programs have a "Check for updates" option in their menu.

Be Careful with Browser Extensions

Browser extensions have access to everything you do in your browser, every website you visit, everything you type, all your passwords.

Extension safety rules:

Red flags for extensions:

3.1.4. Extra Credit

Use a Sandbox for Unknown Software

A sandbox is an isolated environment where you can run software without it affecting your main system. If the software is malicious, it's contained.

Sandbox options:

This is advanced but very effective for testing questionable software safely.

3. Your Devices

3.2 Mobile Device Hardening

Core Concepts: Protect Your Data, Minimize Your Exposure

Your phone carries more personal data than your computer ever did, photos, messages, contacts, emails, banking apps, location history, health data, and more. It goes everywhere with you, making it vulnerable to loss, theft, and unauthorized access. It's also constantly connected to the internet, making it a target for remote attacks.

Mobile operating systems (iOS and Android) are designed with security in mind and include excellent built-in protections. The challenge is ensuring these features are enabled and properly configured.

3.2.1 Understanding Mobile Security

Mobile devices face unique security challenges:

This section covers both iPhone (iOS) and Android. Follow the instructions for your device, or both if you use multiple phones or tablets.

Mobile Security Habits

Beyond settings, develop these habits:

Your phone is your most personal computer. It knows where you go, who you talk to, what you buy, what you search for, and holds keys to your digital life. Protecting it isn't paranoia, it's common sense.

Mobile platforms are pretty secure by default. You just need to enable the right settings, review permissions regularly, and develop good habits. Start with The Basics, add Better Protection over time, and remember, the most important security feature is the lock screen. Use it every time.

3.2.2 The Basics

Set a Strong Passcode and Enable Biometrics

Your lock screen is your first line of defense.

iPhone:

Android:

Biometrics are convenient for daily use, but the passcode is more secure against certain attacks (can't be compelled in court, can't be used while you're unconscious). See Understanding Biometrics in the Authentication topic.

Enable Find My Device

If you lose your phone, you need to be able to locate it, lock it remotely, and erase it if necessary.

iPhone (Find My):

Android (Find My Device):

Enable Automatic Updates

Mobile OS updates fix security vulnerabilities. Enable automatic updates so you're always protected.

iPhone:

Android:

Review App Permissions

Apps request access to your camera, microphone, location, contacts, and more. Review what you've granted and revoke unnecessary permissions.

iPhone:

Android:

Do this review quarterly; apps update and request new permissions over time.

Disable Lock Screen Notifications for Sensitive Apps

Notifications on your lock screen can reveal sensitive information to anyone who glances at your phone.

iPhone:

Android:

Enable Automatic Backup

If you lose your phone, you need your data backed up. Enable automatic cloud backup.

iPhone (iCloud Backup):

Android (Google Backup):

3.2.3 Better Protection

Enable Remote Wipe Capability

If your phone is stolen and you can't recover it, you should be able to erase all data remotely.

iPhone:

Note: After erasing, you can't track it anymore

Android:

Note: After erasing, you can't track it anymore

Use Encrypted Backups

Cloud backups can be encrypted so even the backup provider can't access your data.

iPhone (Advanced Data Protection):

Android:

Disable USB Accessories When Locked

USB accessories can be used to attack locked phones. Disable them when locked.

iPhone:

Android:

Use One-Time Passwords for Apps

For email and other accounts accessed through apps, use app passwords instead of your main password.

Review Location Services Settings

Location tracking is convenient but invasive. Review what's tracking you and when.

iPhone:

Android:

Turn Off Unused Wireless Features

Bluetooth, WiFi, and NFC create additional attack surfaces when not in use.

Use Control Center/Quick Settings for easy toggling.

Review Privacy & Tracking Settings

Apps and advertisers track your activity across apps and websites. Limit this tracking.

iPhone:

Android:

3.2.4 Extra Credit

Use Separate Work/Personal Profiles (Android)

Android allows multiple user profiles or work profiles to keep personal and work data separated. This may already be a requirements and set up automatically depending on where you work and how you access work data on your phone. Contact your local IT center with any questions.

Use Secure Folder / Private Space Features

Some phones offer encrypted, hidden spaces for sensitive apps and files.

Samsung Secure Folder:

Google Private Space (Android 15+):

iPhone:

Enable Advanced Privacy Features

iPhone (iOS 15+):

Android:

Set Up a SIM PIN

A SIM PIN prevents someone from using your SIM card in another phone (protects against SIM-swap attacks).

iPhone:

Android:

Warning: If you enter the wrong SIM PIN 3 times, you'll need a PUK code from your carrier to unlock it. Keep your carrier's customer service number handy.

Use Lockdown Mode (iPhone) for High-Risk Situations

Lockdown Mode is an extreme security mode for people facing serious targeted threats (journalists, activists, executives).

3. Your Devices

3.3 Operating System Hardening

Core Concepts: Minimize Your Exposure, Protect Your Data

Your operating system is the foundation of your computer's security. Everything else, your applications, your files, your passwords, sits on top of it. A properly configured OS blocks most attacks before they can start. A poorly configured one leaves the door wide open.

Modern operating systems have excellent security features built in. The challenge is that many of these features aren't enabled by default, or the default settings prioritize convenience over security. This section shows you how to configure your OS for better protection without making it unusable.

3.3.1. Understanding OS Security

Operating system hardening means configuring your system to be more resistant to attacks. This involves:

We'll cover Windows, macOS, and Linux. Skip to the section for your operating system, or read them all if you use multiple systems.

Maintaining Your Hardened System

OS hardening isn't a one-time task. Maintain your security:

Remember: Security is about balance. If a setting makes your computer too difficult to use, you'll disable it or work around it, defeating the purpose. Find the right balance between security and usability for your needs.

3.3.2. The Basics

Enable Automatic Updates

This is the single most important thing you can do. Unpatched vulnerabilities are responsible for roughly half of all data breaches. Software vendors release updates to fix security holes; if you don't install them, you're leaving known vulnerabilities exposed.

Windows:

Mac:

Linux:

Use an Antivirus

Modern operating systems come with built-in antivirus that's quite good. Make sure it's enabled and updating. 

Part of a defense in depth strategy.

Windows Defender:

There is some debate as to whether these are necessary for Mac and Linux. While Unix-based and Linux operating systems are generally more secure (Mac is Unix-based), they are not immune to viruses. There is also a rise in development of malware for Linux-based operating systems as their use becomes more common. Also, there is more to malware than just viruses, and most modern antivirus solutions are able to detect and block access to websites known to be infected, monitor system processes for evidence of ransomware, and detect malicious web traffic. Make a risk-based decision for yourself: Is the risk of dealing with leaked personal information and ransomware worth the tiny amount of system resources protection requires? Personally, I recommend Sophos as part of a defense-in-depth strategy.

Mac XProtect:

Linux:

Enable Built-In Firewall

A firewall blocks unauthorized network connections to and from your computer. Every modern OS has one built in, make sure it's on.

Windows:

Mac:

Linux:

Enable Full-Disk Encryption

Encryption scrambles your entire drive so no one can access your files without your password. If your laptop is stolen, your data is protected. This is especially important for laptops and any computer with sensitive information.

Important: Back up your data before enabling encryption. While rare, problems during encryption can result in data loss.

Windows (BitLocker - Windows Pro or higher):

Note: Windows Home edition doesn't include BitLocker. Consider upgrading to Pro or using VeraCrypt (free, open-source alternative).

Mac (FileVault):

Linux (LUKS):

Create Separate Accounts for Each Person

Never share user accounts. Each person should have their own account to provide security and privacy for everyone.

On computers:

Windows:

Mac:

Lock Your Screen When Not In Use

Your screen should lock when you step away. This prevents someone from accessing your computer if you forget to lock it manually. On Windows use windows key + L; on Mac use command + control + Q; on Linux, use windows key + L (dependent on keyboard).

You should also set your screen to automatically lock in case you step away and forget.

Windows:

Mac:

Linux (Ubuntu):

Disable AutoPlay/AutoRun

When you connect a USB drive or CD, your computer can automatically run files. This is dangerous as malware often spreads via USB drives. Turn off AutoPlay.

Windows:

Mac:

Linux:

3.3.3. Better Protection

Review and Minimize Privacy Settings

Modern operating systems collect data about how you use your computer. Some of this is for diagnostics, some for targeted advertising. Review these settings and turn off what you don't need.

Windows:

Mac:

Linux:

Configure User Account Control (Windows)

User Account Control (UAC) prompts you when programs try to make system changes. Make sure it is configured it to always notify you.

Disable Unnecessary Services (Windows)

Windows runs many background services. Some are necessary, others aren't. Disabling unused services reduces attack surface.

Safe services to disable for most users:

How to disable:

Warning: Only disable services you understand. When in doubt, leave it alone.

Disable Legacy Network Protocols (Windows)

Windows keeps old networking features for compatibility. You probably don't need them, and they're security risks.

Review Startup Programs

Programs that start automatically when you boot slow down your computer and can be security risks. Review and disable unnecessary startup items.

Windows:

Mac:

Linux:

3.3.4 Extra Credit

Create a Guest Account

If friends or family need to use your computer, create a guest account with limited access. This protects your files and prevents accidental system changes.

Windows:

Mac:

Enable Secure Boot (Windows/Linux)

Secure Boot prevents unauthorized operating systems and bootloaders from starting. It protects against bootkits and rootkits that load before Windows.

Note: Some Linux distributions and dual-boot setups may have compatibility issues with Secure Boot. Verify that your distribution and hardware are compatible with secure boot before enabling.

Encrypt External Drives

If you store sensitive data on external drives or USB sticks, encrypt them too.

Windows (BitLocker To Go):

Mac:

Linux:

Disable SMBv1 Protocol (Windows)

SMBv1 is an old file sharing protocol with known security vulnerabilities (like WannaCry ransomware). Disable it unless you need to connect to very old network devices.

3. Your Devices

3.4 Physical Security

Core Concepts: Minimize Your Exposure, Protect Your Data

All the passwords, encryption, and firewalls in the world won't help if someone can simply walk away with your laptop or peek over your shoulder to see your password. Physical security is often overlooked because we focus on digital threats, but physical access defeats almost all security measures.

If someone steals your laptop, they have unlimited time to try to break your encryption or find vulnerabilities. If they watch you type your password once, they don't need to hack anything. Physical security is where digital security starts.

3.4.1. Understanding Physical Security

Physical security covers protecting your devices and data from:

The good news is most physical security measures are simple, inexpensive, and about habits more than technology. You don't need expensive equipment, you need to lock your screen every time, keep devices with you, and stay aware of your surroundings.

3.4.2. The Basics

Lock Your Screen Every Time

This is the single most important physical security habit. Lock your screen whenever you step away from your device, even for a moment. Also, never leave devices unattended in public. It only takes a second for someone to pick it up.

Quick lock shortcuts:

Be Aware of Your Surroundings

Shoulder surfing is when someone watches your screen or keyboard to see what you're typing. They could observe passwords, PINs, sensitive emails, etc. They do not have to be directly over your shoulder either, across the room with a cellphone camera is enough. To that point, even security cameras could inadvertently capture sensitive information.

How to protect yourself:

Use Device Tracking Features

Enable Find My Device features on all your devices (covered in Mobile Device Hardening and OS Hardening sections).

What this enables:

Test it now: Make sure you can actually locate your devices before you need to.

Be Cautious with Public Charging Stations

Public USB charging stations (airports, hotels, conference centers) can be compromised with "juice jacking" attacks that install malware or steal data.

How to protect yourself:

Mark Your Devices

Visibly marking your devices makes them less attractive to thieves (harder to resell) and easier to identify if recovered. Just don’t use anything which could make it a bigger taget, such as your name or a company logo.

Marking options:

What to mark:

Document: Keep a record of serial numbers and device identifiers. Take photos. Store this in your password manager or secure cloud storage.

3.4.3. Better Protection

Secure Webcam and Microphone

Your webcam and microphone can be accessed by malware or accidentally left on during video calls.

Simple protection:

Use a Cable Lock for Laptops

Cable locks (Kensington locks) physically secure your laptop to a desk or other fixed object.

When to use:

What to buy:

Note: Cable locks are deterrents, not absolute security. Determined thieves can cut cables or remove the lock slot, but they do reduce opportunistic theft.

Use Privacy Screens

Privacy screens are physical filters that narrow the usable field of view of your monitor. Some laptops have this feature integrated. HP has a featured called the Sure View integrated privacy screen which can be turned on and off using a keyboard shortcut. If your laptop does not have a built-in privacy screen, consider purchasing one if you frequently access sensitive data in public.

When to use:

What to buy:

Tradeoff: Privacy screens reduce screen brightness and can make it harder to see in certain lighting. Worth it for sensitive work.

3. Your Devices

3.5 Data Lifecycle and Disposal

Core Concept: Protect Your Data

Data doesn't just disappear when you delete it. When you click "delete" or throw a device in the trash, your personal information often remains completely recoverable. This section covers how to properly manage data throughout its entire lifecycle, from creation to destruction.

Whether you're selling an old phone, donating a computer, recycling a hard drive, or just trying to clean up years of accumulated digital clutter, you need to know how to truly delete data so it can't come back to haunt you.

3.5.1 Understanding Data Lifecycle and Deletion

Delete doesn’t mean “gone.” When you delete a file, your computer doesn't actually erase it, it just marks that space as "available for reuse." The data sits there, completely intact, until something else overwrites it. This might take days, months, or never happen at all.

Where your data lives:

Real-world consequences of improper disposal:

3.5.2. The Basics

Factory Reset Before Selling or Donating Devices

Never sell, donate, or recycle a device without factory resetting it.

Before factory reset:

How to factory reset:

iPhone/iPad:

Android:

Windows:

Mac:

Delete Old Online Accounts

Old accounts you no longer use still contain your personal data.

Some accounts to review include:

Before deleting account:

If you’re not sure how to delete an account (service provider instructions are not always clear) you can look up the site here: https://justdeleteme.xyz/ 

Delete Cloud Data You Don't Need

Data in the cloud doesn't necessarily automatically delete when you delete it locally. Review your cloud data storage occasionally and remove any sensitive information to limit its exposure. Don’t forget to empty the trash, as cloud services often retain deleted items for 30+ days.

3.5.3. Better Protection

Use Secure Deletion Tools

When disposing of a computer, if you have used it to store sensitive files, normal deletion isn't enough. Secure deletion tools overwrite the data multiple times.

DoD 5220.22-M standard: Overwrites data 7 times (for HDDs). Once considered necessary, now overkill; 1-3 passes is sufficient for HDDs. For SSDs, multiple overwrites are ineffective due to wear-leveling; use manufacturer's Secure Erase utility or ensure the drive was encrypted from the beginning.

Check Printers and Copiers

Many printers and copiers have internal storage that keeps copies of things you printed or scanned.

Before disposing:

3.5.4. Extra Credit

Plan for Digital Legacy

What happens to your data when you die? Plan for it.

Digital legacy planning:

Services:

4. Network and Browsing

4. Network and Browsing

4.1 Browser Hygiene

Core Concepts: Protect Yourself, Minimize Your Exposure

Your web browser and email are your primary gateways to the internet, and the primary ways attackers try to reach you. Most cyber attacks start with either a malicious website or a phishing email. Good browser and email hygiene can stop the vast majority of these attacks before they start.

You don't need to be a technical expert. Most protection comes from recognizing common patterns, adjusting a few settings, and building good habits about what you click.

4.1.1. Understanding Browser Threats

Common browser threats:

4.1.2. The Basics

Use a Modern, Updated Browser

Modern browsers have built-in security features that older browsers lack. Keep your browser updated to get the latest protections.

Enable automatic updates:

Look for HTTPS and the Padlock Icon

HTTPS encrypts the connection between your browser and the website. Always check for it, especially on sites where you enter passwords or payment information.

What to look for:

Warning signs:

NEVER enter passwords or payment info on HTTP sites. Close the site and find a secure alternative.

Check URLs Carefully Before Clicking

Attackers create fake websites with URLs that look almost right. Always verify URLs before clicking or entering information.

How to check URLs:

Common tricks:

When in doubt, type the URL manually rather than clicking links.

Use Minimal Browser Extensions

Browser extensions have access to everything you do in your browser. Only install extensions you truly need from trusted developers.

Extension safety rules:

See the Software and App Safety section for additional extension guidance.

4.1.3. Better Protection

Configure Browser for Privacy

Browsers collect data about your browsing. Review and restrict this.

Chrome:

Firefox:

Safari:

Use a Privacy-Focused Search Engine

Search engines track your searches and build profiles. Consider alternatives that don't track.

Privacy-focused options:

How to change default search:

Install a Reputable Ad Blocker

Ad blockers prevent malicious ads and reduce tracking. Choose carefully - some ad blockers themselves track you.

Avoid: AdBlock, AdBlock Plus (these allow "acceptable ads," ads that pay them)

4.1.4. Extra Credit

Use Hardened Browser

For maximum privacy and security, use browsers with hardened default configurations.

Privacy-focused browsers:

Advanced Firefox hardening:

Use Browser Profiles or Containers

Separate your browsing into different profiles or containers to isolate activities.

Browser profiles (Chrome/Edge/Brave):

Firefox containers:

4. Network and Browsing

4.2 Home Wifi Security

Core Concepts: Protect Your Data, Minimize Your Exposure

Your home WiFi network is the gateway to everything in your digital life, your computers, phones, tablets, smart home devices, security cameras, and more. A compromised network means all your devices are at risk. Worse, your neighbors or someone parked outside could be using your internet for illegal activities, and it would trace back to you.

Securing your home WiFi doesn't require deep technical expertise. Most protection comes from changing a few default settings that take 15-30 minutes to configure.

4.2.1. Understanding WiFi Security Risks

Common WiFi threats:

4.2.2. The Basics

Change Your Router's Default Admin Password

This is the single most important thing you can do. Routers typically come with default passwords like "admin/admin" or "admin/password" that are publicly known. Anyone on your network can access your router's settings with these defaults.

Some more modern routers like what you would get from your Internet Service Provider (ISP) may come with a unique password on a sticker on the back of the device. It is still a good idea to change this password.

How to access your router:

Change the admin password:

Use WPA3 or WPA2 Encryption

WiFi encryption protects your wireless traffic from being read. WPA3 is the newest and most secure, but not all devices support WPA3 yet. WPA2/WPA3 (mixed mode) is fine if you have devices on your home network that don’t support WPA3.

How to enable:

NEVER use:

Create a Strong WiFi Password

Your WiFi password (also called the network key or passphrase) protects who can connect to your network.

Password requirements:

How to change:

Tip: Consider creating a passphrase from 4-5 random words: "Correct-Horse-Battery-Staple-47!" is both strong and easier to type on phones than random characters.

Keep Router Firmware Updated

Router firmware is like the operating system for your router. Manufacturers release updates to fix security vulnerabilities.

How to update:

Enable automatic updates if available:

If no auto-update: Check manually every 3 months.

Use a Custom Network Name (SSID)

Your network name (SSID) shouldn't reveal your router model or personal information.

Why change it:

What NOT to use:

Good options:

How to change:

4.2.3. Better Protection

Disable WPS (WiFi Protected Setup)

WPS was designed to make connecting devices easier, but it has a critical security flaw that makes it easy to crack your WiFi password.

Why disable it:

How to disable:

Set Up a Guest Network

A guest network gives visitors internet access without exposing your main network and devices.

Benefits:

How to set up:

What to put on guest network:

Disable Remote Management

Remote management allows you to access router settings from outside your home network. Unless you specifically need this, disable it.

Why disable:

How to disable:

Disable Universal Plug and Play (UPnP)

UPnP allows devices to automatically open ports in your router. This is convenient but can be exploited by malware.

Why disable:

How to disable:

Note: Some gaming consoles and P2P applications prefer UPnP. If you have issues, you can manually configure port forwarding instead, or enable UPnP again.

Review Connected Devices Regularly

Check what's connected to your network to spot unauthorized devices.

How to check:

If you find an unknown device:

Do this monthly: Set a calendar reminder to review connected devices.

4.2.4. Extra Credit

Use VLANs to Segment Your Network

VLANs (Virtual LANs) separate devices into isolated network segments. This is advanced but powerful.

Example segmentation:

Benefits:

Requirements:

Note: This is advanced. Most people should use guest networks instead, which provide similar isolation with much easier setup. You will need to search online to contact an IT support person for specific instructions for your equipment.

Install a Custom Router

You can turn any PC into a custom router by installing open source router software, such as OPNSense. This is relatively advanced, so not for the faint of heart, but worth the effort if you are willing to learn a bit about networking and OK with spending a few hundred dollars for a truly secure, custom solution. You can view my guide on TheDen Home Network Runbook if you are curious about what is involved.

4. Network and Browsing

4.3 Smart Home and IoT Devices

Core Concepts: Minimize Your Exposure, Protect Your Data

Smart home and other Internet of Things (IoT) devices make life convenient; smart speakers, security cameras, thermostats, door locks, light bulbs, refrigerators, and more. But these devices are often the weakest link in your home network. Many ship with poor default security, rarely get updated, and connect to the internet 24/7.

A compromised smart device can become a gateway for attackers to access your entire network, spy on you through cameras and microphones, or recruit your devices into a botnet (an army of hacked devices used for cyberattacks).

With some basic precautions, you can enjoy the convenience of smart devices without compromising your security.

4.3.1. Understanding IoT Security Risks

What are IoT devices?

Any device that connects to the internet but isn't a traditional computer or phone:

Common IoT security problems:

Real-world consequences:

You don't need to avoid IoT devices, they're useful and can make life easier. But treat them with appropriate caution. An IoT device is basically a tiny computer, running software, connected to the internet 24/7. Would you leave a computer with default password "admin" connected to the internet? No? Then don't do it with your TV either.

4.3.2. The Basics

Change All Default Passwords

Default passwords are publicly available and attackers scan for devices using them.

For each IoT device:

Keep Firmware Updated

IoT devices need security updates just like computers. Enable automatic updates where possible.

How to update:

For devices without apps:

Create a quarterly reminder to check for updates for your IoT devices that don't auto-update.

Disable Unnecessary Features

IoT devices often have features enabled by default that you don't need. Turn them off.

Common features to disable:

How to find these:

Review Device Permissions and Privacy Settings

IoT device apps request permissions on your phone. Review and restrict them.

Check app permissions:

Common unnecessary permissions:

Use Strong Authentication for Device Apps

The apps that control your IoT devices should have strong passwords and MFA.

For each device manufacturer account:

See the Authentication section for detailed password and MFA guidance.

4.3.3. Better Protection

Research Security Before Purchasing

Not all IoT devices are created equal. Buy from manufacturers with good security track records.

Before buying, check:

Good signs:

Red flags:

Put IoT Devices on Your Guest Network

IoT devices shouldn't have access to your computers and phones. Use your guest network to isolate them.

Why this matters:

What to do:

Exception: Devices that need to communicate with your phone/computer (like Chromecast, AirPlay, or printer) may need to be on the main network. This is a tradeoff where you weigh convenience against security for each device.

Use Physical Controls for Cameras and Microphones

Cameras and microphones in IoT devices can be compromised. Use physical controls.

For cameras:

For microphones:

Review Smart Speaker Voice History

Smart speakers record your voice commands. Review and delete this history regularly.

Amazon Alexa:

Google Home:

Apple HomePod:

4.3.4. Extra Credit

Use Local Control Instead of Cloud

Devices that work locally don't require internet and can't be compromised through manufacturer's cloud.

Local control options:

Benefits:

Tradeoff: More complex to set up and requires ongoing maintenance. Only recommended for technically comfortable users.

Use VLANs for Advanced Network Segmentation

VLANs provide the strongest isolation between IoT devices and your trusted devices.

VLAN segmentation example:

Firewall rules:

Requirements:

See the Home WiFi section for more on VLANs, of TheDen Home Network Guide.

4. Network and Browsing

4.4 Virtual Private Networks (VPNs)

Core Concepts: Protect Yourself, Protect Your Data

VPNs are one of the most misunderstood security tools. They're marketed as making you "invisible online" which isn't true, but they do have legitimate, specific uses that can protect your privacy and security.

This section cuts through the marketing hype to explain what VPNs actually do, when you need one, when you don't, and how to choose and use one effectively.

4.4.1. Understanding VPNs

What is a VPN?

A Virtual Private Network creates an encrypted tunnel between your device and a VPN server. All your internet traffic goes through this tunnel before reaching its destination. A VPN protects your network traffic from local snooping on public WiFi, but it does not make you anonymous or protect you from phishing or malware.

Think of regular internet traffic like sending a postcard. Anyone handling it can read the message and see where it’s going. A VPN puts your postcards in sealed envelopes and sends them to a trusted friend (the VPN server) who opens them and sends them to their final destination. The recipient sees the message as coming from your friend, not you.

What VPNs DO:

What VPNs DON'T DO:

The trade-off: VPNs add an extra step to your internet connection, which usually means slower speeds. You're trading some speed for privacy and security in specific situations.

When You Should Use a VPN

On Public or Untrusted WiFi

This is the real reason for using a VPN. Use a VPN when connected to any open (unencrypted) WiFi network. An open WiFi network is any network you do not have to enter a network key to connect to.

Note that captive portal sign-in is not the same thing. If you have ever connected to a network, then had to open a browser and sign in to get internet access, you were probably on an open network with a captive portal. A captive portal is a web page that appears when you connect to some WiFi networks (like at hotels or airports) requiring you to agree to terms or enter a password before accessing the internet. These do not offer any protection!

When you connect to an open WiFi network, all other people on the network can potentially see what you are doing. This means a malicious person could also tamper with the data coming from or going to your device. A VPN encrypts all your traffic so they cannot.

For Privacy from Your ISP

Your internet service provider can see all the websites you visit. A VPN hides this.

Why you might want this:

Keep in mind: You're shifting trust from your ISP to your VPN provider. Choose your VPN provider carefully.

When You DON'T Need a VPN

To "Stay Anonymous Online"

VPNs don't make you anonymous, this is marketing hype. You are still tracked based on the accounts you log into, browser and device fingerprinting, tracking cookies, and payment information.

If you want more anonymity (for journalism, activism, etc.), you need specialized tools like Tor, not just a VPN.

4.4.2. The Basics

Choose a Reputable VPN Provider

This is the most important decision. A bad VPN provider is worse than no VPN as they can see and log everything you do. Avoid free tiers, as they make money by selling ads to you or your data to someone else. In fact, avoid any VPN that offers a free tier.

What to look for:

My recommendation is Mullvad https://mullvad.net/en.

4.4.3. Better Protection

Install On Your Phone Too

(Tested with Mullvad, should be a similar process for others)

Android Setup:

iOS Setup:

4.4.4. Extra Credit

Run Your Own VPN Server

Advanced users can set up their own VPN server.

Options:

Benefits:

Drawbacks:

Best for encrypting your traffic on a public WiFi or accessing your home network remotely, not for privacy from ISP or geographical restrictions.

4. Network and Browsing

4.5 Travel Guide

Core Concepts: All Four

Travel introduces unique risks. Prepare before you go and stay vigilant while away.

4.5.1. Before You Leave

4.5.2. During Travel

4.5.3. At Border Crossings

Plan for Border Crossings

International border agents can legally search devices in many countries.

Standard precautions:

High-security approach:

5. Backups and Recovery

5. Backups and Recovery

5.1 Backups

Core Concepts: Protect Your Data, Have a Recovery Plan

You need backups BEFORE disaster strikes. Ransomware, hardware failure, theft, accidental deletion, fire, flood, or simple human error, any of these can wipe out years of photos, documents, and memories in seconds. The question isn't IF you'll need a backup, but when.

5.1.1. Understanding Backups

A backup is simply a copy of your files stored somewhere other than your main device. If something happens to your computer or phone, you can restore your files from the backup. The key principles:

The 3-2-1 Rule

This is the gold standard for backups:

Don't let perfect be the enemy of good, even one automatic backup is better than none.

Common Backup Mistakes to Avoid

Quick Start Backup Plan

If you do nothing else, do this today:

This gives you basic protection in 30 minutes. You can add cloud backup and other layers later.

Remember: The best backup is the one that exists. A simple automatic backup you've tested beats a perfect backup plan you never implement. Start simple, then improve over time.

5.1.2. The Basics

Enable Built-In Backup Tools

Every modern operating system has a built-in backup feature. Turn it on right now:

Windows (Windows Backup):

Mac (Time Machine):

Linux (varies by distribution):

Know What You're Backing Up

Make sure your backup includes:

You don't need to back up:

Back Up Your Phone

Your phone probably contains more important data than your computer; photos, contacts, messages, and app data.

iPhone (iCloud Backup):

Android (Google Backup):

Test Your Backups

This is critical and almost everyone skips it. A backup you haven't tested is just hope, not a backup.

How to test:

Test your backups at least twice a year. Set a calendar reminder.

5.1.3. Better Protection

Use Encryption

If your backups contain sensitive information, encrypt them.

Why encrypt?

How to encrypt:

Critical: Store your encryption password somewhere safe (password manager). If you lose it, your backup is useless.

Add Cloud Backup

If you back up to a removable drive, consider adding backups to a cloud service provider. Cloud backup stores your files on servers maintained by a company, accessible from anywhere with internet. This gives you the "offsite" component of the 3-2-1 rule.

Good cloud backup options:

General purpose cloud storage:

Dedicated backup services (recommended):

Why dedicated backup services are better:

Maintain Your External Drive Backup

If you're using an external hard drive for backups:

Ransomware consideration: Some ransomware can encrypt external drives that are connected. To protect against this:

Set a Backup Schedule

Different types of data need different backup frequencies:

Most backup software handles this automatically once you set it up.

Back Up Before Major Changes

Always create a backup before:

Monitor Your Backup Storage

Check regularly that you have enough space:

5.1.4. Extra Credit

Own Your Cloud Data

When you use cloud services like Google Drive, iCloud, or Dropbox, your data lives on someone else’s computer. For most situations this is fine, it's convenient and reliable, but you give up some control. The company can change terms, raise prices, close accounts, or potentially access your files. If you want more control over your cloud storage, you can create your own personal cloud.

What "owning your cloud" means:

Basic options for personal cloud storage:

Network Attached Storage (NAS) - A NAS is essentially a specialized computer with hard drives that sits on your home network and provides storage to all your devices.

Beginner-friendly NAS options:

What you can do with a NAS:

How difficult is it?

Considerations:

This gives you speed, control, and protection.

Bottom line:

Owning your cloud data isn't for everyone, but if you:

then a personal NAS can be a great long-term investment. Otherwise, commercial cloud services are perfectly fine and often more reliable for non-technical users.

Implement True Offsite Backup

For maximum protection, keep a backup in a completely different physical location:

Options:

Offsite backups protect against fire, flood, theft, and natural disasters that could destroy both your computer and local backups.

Create a Disaster Recovery Plan

Document your backup system so you (or someone helping you) can recover:

What to document:

Keep this documentation in your password manager and print a copy for your emergency kit.

6. Incident Playbooks

6. Incident Playbooks

6.1 How to Use These Playbooks

When you discover a security incident:

  1. Don't panic - Take a breath; most incidents are recoverable if you act systematically

  2. Find the right playbook - Match your situation to one of the scenarios below

  3. Follow the steps in order - Steps are prioritized by urgency and importance

  4. Document everything - Keep notes on what happened, when, what you did, who you spoke to

  5. Ask for help - If you're overwhelmed, ask a tech-savvy friend or professional

6. Incident Playbooks

6.1 Account Compromise

Compromised Email Account

Signs your email might be compromised:

Step 1: Regain Control if Locked Out (IMMEDIATELY)

Step 2: Update Security Settings (Within Minutes)

Step 3: Damage control (Within Hours)

Step 4: Additional Actions

Compromised Password Manager

This is the worst-case scenario. Act fast!

Signs your password manager is compromised:

Step 1: Regain Control (IMMEDIATELY)

Step 2: Reset All Passwords In Your Vault (IMMEDIATELY – this takes time)

Assume every account in your vault is compromised. Work through tiers in order. For EACH account changed:

  1. Change password to new unique password

  2. Remove all authorized devices

  3. Enable or verify MFA

  4. Check recent activity

  5. Verify security questions and recovery settings

  6. Check for account-specific issues (email forwarding, rofile changes, etc)

Tier 1 – Immediately

Tier 2 – Within 1 Hour

Tier 3 – Within 4 Hours

Tier 4 – Within 12 Hours

Tier 5 – Within 24 Hours

Step 3: Additional Actions

Compromised Financial Account

(Bank, credit union, credit card, investment account, etc)

Signs of compromise:

Step 1: Regain Control (IMMEDIATELY)

Step 2: Update Security Settings (Within Minutes)

Step 3: Damage Control (Within Hours)

Additional steps:

Compromised Social Media Account

(Facebook, Twitter/X, Instagram, LinkedIn, forums, etc)

Signs of compromise:

Step 1: Regain Control (IMMEDIATELY)

Step 2: Update Security Settings (Within Minutes)

Step 3: Damage Control (Within Hours)

Step 4: Additional Actions

Compromised Cloud Storage Account

(Google Drive, OneDrive, iCloud, Dropbox, etc)

Signs of compromise:

Step 1: Regain Control (IMMEDIATELY)

Step 2: Update Security Settings (Within Minutes)

Step 3: Damage Control (Within Hours)

Step 4: Additional Actions

Compromised Shopping Account

(Amazon, eBay, Etsy, etc)

Signs of compromise:

Step 1: Regain Control (IMMEDIATELY)

Step 2: Update Security Settings (Within Minutes)

Step 3: Damage Control (Within Hours)

Step 4: Additional Actions

If Any Other Account is Compromised

Signs of compromise:

Step 1: Regain Control (IMMEDIATELY)

Step 2: Update Security Settings (Within Minutes)

Step 3: Damage Control (Within Hours)

Step 4: Additional Actions

6. Incident Playbooks

6.3 Personal Data Incidents

Identity Theft

Signs of identity theft:

Step 1: Contain the Damage (IMMEDIATELY)

Step 2: Close Fraudulent Accounts (Within 24-48 Hours)

Step 3: Secure Your Legitimate Accounts (Within 48 Hours)

Step 4: Additional Actions

Lost or Stolen Wallet or Purse

What's at risk:

Step 1: Immediate Containment (IMMEDIATELY)

Step 2: Replace Documents (Within 24-48 Hours)

Step 3: Monitoring

Sent Money to a Scammer

Common scenarios:

Step 1: Try to Stop the Payment (IMMEDIATELY)

Document everything:

For wire transfers:

For credit/debit card charges:

For payment apps (Venmo, PayPal, Zelle):

For gift cards:

For cryptocurrency:

Step 2: Report the Fraud (Within 24 Hours)

Step 3: Protect Against Further Loss (Within 24 Hours)

Gave Out Personal Information

Follow this playbook if you gave out high risk, personal information via email or to a caller in a conversation you did not initiate.

High Risk Personal Information:

Step 1: Immediate Actions (Based on What You Shared)

Step 2: Monitor accounts daily for 2 weeks

If you see anything unusual, follow the appropriate playbook

Clicked a Phishing Link or Opened Suspicious Attachment

Your next steps are based on what you did, based on risk.

Low Risk

High Risk

Received Notice of Data Breach

This is when a company notifies you your data was exposed.

Common notification sources:

Step 1: Verify Notification is Legitimate (IMMEDIATELY)

Beware of phishing! Don't click links in breach notification emails, instead, verify using one of the following:

Step 2: Understand What Was Exposed (Within 24 Hours)

Read the notification carefully:

Step 3: Take Action Based on Data Exposed (Within 48 Hours)

If passwords were exposed: Follow the playbook for the type of compromised account above

If email address only: Not much you can do here, just understand you will likely start receiving a lot of spam and potentially phishing attempts, so be extra vigilant in the coming weeks and months.

If Social Security number or financial data:

If medical information:

Step 4: Accept Company's Offer (If Valuable)

Many companies offer:

Evaluate the offer:

Step 5: Additional Actions

Document the breach:

Monitor relevant accounts based on exposure and consider legal action if negligence was involved.

Ongoing monitoring:

SIM Swap Attack

Signs of SIM swap:

Step 1: Regain Control of Phone Number (IMMEDIATELY)

Contact your mobile carrier:

Step 2: Secure Accounts That Use Phone for 2FA (Within 1 Hour)

Attackers may have targeted accounts using SMS for two-factor authentication. Verify recent logins to new devices in the following priority:

If there was an unauthorized login, for each account:

6. Incident Playbooks

6.4 Device Incidents

Ransomware Infection

Signs of ransomware

Step 1: Isolate the Infection (IMMEDIATELY)

Step 2: Assess and Report (Within 1 Hour)

Do NOT pay the ransom, there is no guarantee of file recovery and this funds criminal activity

Step 3: Recovery Options

If decryption is available from your assessment, follow the instructions. This differs by type of ransomware and who is providing instruction, so I cannot be more specific than that.

If no decryption is available AND you have backups then performing a clean reinstall of your operating system is the way to go. Again, I cannot be more specific as there are too many variables. If you aren’t sure how to do this, ask a technical friend or visit somewhere that services computers (Microcenter, Best Buy, Apple Store, etc).

If no decryption is available and you DON’T have backups, I’m sorry, you’re pretty screwed. From a clean computer, go through all your accounts and remove that computer as an authorized device. Under no circumstances should you boot this computer and connect to anything until it is clean. Keep an eye on the decryption assistance sites above, there may be something in the future that can help, or seek assistance from a professional service.

Malware or Virus Infection (Not Ransomware)

Signs of malware infection:

Step 1: Isolate The Infection (IMMEDIATELY)

Step 2: Scan and Remove (Within 1 Hour)

Step 3: Check for Damage (Within 24 Hours)

Step 4: Additional Actions

If infection cannot be cleaned, contact your antivirus provider. Even if you don’t pay for the service they may still offer help.

The worst-case scenario, make sure your backups are working and perform a clean reinstall of your operating system. If unsure how to do this, talk to a technical friend or seek professional services.

Gave Remote Access to Your Computer

Common scenarios:

Step 1: Cut Off Access (IMMEDIATELY)

Step 2: Scan for Malware (Within 30 minutes)

Step 3: Additional Actions

What To Do If Your Phone or Computer Is Lost or Stolen

Act quickly, the sooner you respond, the better your chances of recovery or protecting your data.

Step 1: Protect Your Data (IMMEDIATELY)

Use Find My Device (see Mobile Device Hardening or Physical Security section) to:

Suspend services and force logouts:

If you had an authenticator app on your phone, you may lose MFA access, so you may need to use another device where the authenticator app is install or the recovery codes form your password manager.

Step 2: Erase and File Reports (Within 12 Hours)

If stolen or otherwise not recoverable:

Step 3: Recovery

If device is recovered, before using:

If suspicious changes found, factory reset the device and proceed as if setting up a new device.

7. Reference

7. Reference

7.1 Maintenance Checklists

Monthly Checklist

Time Required: ~30 minutes

Backups

Network Security

Software & Updates

Quarterly Checklist

Time Required: ~1-2 hours

Account Security Review

Device Maintenance

Annual Checklist

Time Required: ~2-3 hours (can be spread across multiple sessions)

Comprehensive Account Audit

Backup & Recovery Testing

Privacy Review

7. Reference

7.2 Glossery

Term

Definition

3-2-1 Rule

A backup strategy: keep 3 copies of your data, on 2 different types of storage, with 1 copy stored offsite (like in the cloud).

Account recovery

The backup ways to prove an account is yours (like a recovery email, phone number, or recovery codes) if you forget your password or lose your phone.

Admin account

A computer account that can install software and change system settings. Use it rarely.

Adware

Unwanted software that shows ads or tracks you for ads.

Antivirus

Software that looks for and blocks malicious software (malware). Built‑in options are usually enough when combined with updates.

Attack Surface

The sum of the attack vectors where an attacker can attempt an attack.

Authenticator app

An app that generates time‑based codes for multi‑factor authentication (MFA). Works even without cell service.

Backup

A second copy of your files you can restore if your device is lost, stolen, damaged, or encrypted by ransomware.

Biometric

Using your body (fingerprint, face) to unlock a device or app.

BitLocker / FileVault / LUKS

Full-disk encryption tools built into operating systems. BitLocker (Windows), FileVault (macOS), and LUKS (Linux) scramble your entire hard drive so data can't be accessed without your password.

Botnet

A network of infected devices controlled by attackers to launch coordinated cyberattacks, send spam, or mine cryptocurrency without the owners' knowledge.

Browser extension

A small add‑on to your web browser. Only install ones you truly need and trust.

Caller ID spoofing

When scammers fake the phone number that appears on your caller ID to make it look like a call is from your bank, the IRS, or another trusted source.

Captive portal

The web page that appears when you connect to some WiFi networks (like at hotels or airports) requiring you to agree to terms or enter a password before accessing the internet.

Cloud

Someone else's computers you access over the internet (like iCloud, Google Drive, OneDrive).

Data breach

When sensitive information is stolen from a company or organization's systems, often exposing passwords, emails, credit card numbers, or personal data of users.

DDoS attack

Distributed Denial of Service attack. When many compromised devices flood a website or service with traffic to overwhelm it and make it unavailable.

Default gateway

The IP address of your router. Your computer uses this to access the internet and other networks.

Encryption

A way to scramble data so only someone with the right key can read it. Examples: FileVault (macOS), BitLocker (Windows), built‑in encryption on iPhone and Android.

End‑to‑end encryption (E2EE)

Only the sender and receiver can read messages; even the service provider cannot.

Firewall

A security feature that controls which network traffic is allowed. Your router and computer have one built in.

Firmware

The permanent software programmed into a hardware device (like a router or smart device) that controls how it operates. Like an operating system, but specifically for that device.

Guest network

A separate wireless network for visitors and untrusted devices that keeps them isolated from your main network, computers, and files.

IoT (Internet of Things)

Any device that connects to the internet but isn't a traditional computer or phone, like smart speakers, thermostats, security cameras, or smart light bulbs.

IP address

Internet Protocol address. A unique number assigned to each device on a network that identifies it, like a street address for your computer or phone.

ISP

Internet Service Provider. The company that provides your internet connection (like Comcast, AT&T, Verizon).

Keylogger

Malicious software that records everything you type on your keyboard to steal passwords and sensitive information.

Kill switch (VPN)

A VPN feature that automatically blocks all internet traffic if the VPN connection drops, preventing your data from being exposed.

Malware

Malicious software designed to harm, spy, or steal (viruses, ransomware, spyware, trojans).

Multi‑factor authentication (MFA)

Adding a second step to log in (like a code or prompt) so a stolen password alone is not enough.

Operating system (OS)

The main software that runs your device (Windows, macOS, Linux, iOS for iPhone, Android).

Passkey

A newer, phishing-resistant sign-in method that uses cryptography instead of passwords. Passkeys are stored on your device and use biometrics or a PIN to unlock, but the biometric data never leaves your device.

Passphrase

A longer, easy‑to‑remember password made of several words.

Password manager

A secure app that creates and stores unique passwords for every account.

Phishing

A fake message (email/text/DM) that tries to trick you into clicking a link, opening an attachment, or sharing a code or password.

PIN

Personal Identification Number. A numeric password, typically 4-6 digits, used to unlock devices or authenticate transactions.

Quishing

QR code phishing. A scam using QR codes in emails or texts to trick you into visiting fake websites that steal your information.

Ransomware

Malware that locks your files and demands payment to unlock them.

Recovery codes

Backup codes provided when you enable multi-factor authentication that let you access your account if you lose your phone or authenticator app.

Remote wipe

Erasing a lost or stolen device over the internet.

SIM‑swap

A criminal moves your phone number to their SIM card to receive your text messages and calls.

Social engineering

The art of manipulating people into giving up confidential information or taking actions that compromise security. Attackers exploit human psychology (trust, fear, urgency) rather than technical vulnerabilities.

Software update

A fix or improvement for your device or app. Turning on automatic updates closes security holes.

SSID

Service Set Identifier. The name of your wireless network that appears when you search for available WiFi networks.

UPnP

Universal Plug and Play. A feature that lets devices automatically open ports in your router. Convenient but can be exploited by malware to bypass your firewall.

URL

Uniform Resource Locator. The web address you type into your browser (like https://www.example.com).

USB

Universal Serial Bus. The common rectangular port and cable used to connect devices like keyboards, mice, external drives, and phones to your computer.

Virtual private network (VPN)

A service that encrypts your internet traffic and routes it through the VPN provider. Useful on public Wi‑Fi; not a magic invisibility cloak.

VLAN

Virtual Local Area Network. A way to separate devices on a network into isolated groups so they can't communicate with each other, improving security and organization.

WEP / WPA / WPA2 / WPA3

WiFi security protocols. WPA3 is the newest and most secure, WPA2 is older but still secure, WPA (original) is outdated, and WEP is completely broken and should never be used.

WPS

WiFi Protected Setup. A feature designed to make connecting devices easier using a PIN, but it has security flaws that make it easy for attackers to crack your WiFi password.

Zero-knowledge encryption

Encryption where even the service provider cannot access your data because they never have your encryption keys. Only you can decrypt your files.