Cybersecurity

Cybersecurity Basics for Everyday Users

Plain-language defenses against the threats that actually hit normal people: phishing, malware, ransomware, weak passwords, and unsafe browsing. Practical, opinionated, and built around habits you can keep.

Quick summary

  • MFA on email + password manager covers most consumer risk.
  • Phishing wins through urgency, not sophistication — slow down.
  • Keep devices patched; ransomware loves stale software.
  • Back up irreplaceable data offline or to immutable storage.

The threats that actually matter

  • Phishing — fake emails, SMS, and DMs that harvest credentials.
  • Malware — software that runs without consent, from adware to spyware.
  • Ransomware — encrypts your files and demands payment.
  • Account takeover — credential stuffing using leaked password lists.
  • SIM swap — attacker hijacks your phone number to defeat SMS MFA.

The defenses worth your time

  • Hardware-key or app-based MFA (not SMS) on email, banking, and your password manager.
  • Unique randomly-generated passwords for every account.
  • Automatic OS, browser, and app updates.
  • A reputable antivirus or EDR for Windows; built-in protection is fine for macOS.
  • Backups: 3 copies, 2 different media, 1 offline.

Safe browsing in practice

Verify URLs before entering credentials, prefer bookmarks over search results for sensitive sites, never run software from links sent by strangers, and treat any 'urgent' message as suspicious by default.

Troubleshooting workflow

Run through these steps in order. Each step links to the right diagnostic tool.

  1. 1

    Check a suspicious link

    Reputation + TLS + phishing flags in one report.

    Open URL Safety Checker
  2. 2

    Verify a website

    Combined safety signal for any domain.

    Open Website Safety
  3. 3

    Inspect a suspicious email

    Analyse headers, SPF/DKIM/DMARC, route.

    Open Email Headers
  4. 4

    Check for VPN/DNS leaks

    Confirm your privacy posture matches expectations.

    Open VPN Leak Test

Frequently asked questions

What single step gives the biggest security win?

Turning on multi-factor authentication (MFA) on email and your password manager. Email is the master key — protect it first.

Do I really need a password manager?

Yes. Reusing passwords is the single biggest cause of consumer account compromise. A manager turns hundreds of unique strong passwords into one habit.

How do I spot phishing?

Mismatched sender domain, urgency pressure, unexpected attachments, requests to confirm credentials, and links that don't match the visible text. When in doubt, navigate directly instead of clicking.

Is a VPN necessary?

Not for safety on HTTPS sites — those are already encrypted. A VPN matters when you want privacy from your ISP or network operator, when traveling, or when geo-fencing applies.

What should I do after a breach?

Change the password on the breached account and anywhere you reused it, enable MFA, watch for follow-on phishing, and consider freezing your credit if PII was exposed.

Monitor it continuously

Save this check, get alerts on changes, and track multiple domains in one dashboard.

Learn about monitoring