In priority order — because the first two items do most of the work.
You don't need to become paranoid or buy anything. Almost everything that happens to ordinary people comes down to a reused password, a missing second factor, or a convincing message. Fix those and you've handled the overwhelming majority of realistic risk.
01Protect your email like it's the master keystart here
Because it is. Every "forgot password" link on every other account lands in your inbox. Someone with your email has everything downstream — bank, shopping, social, work.
Give it a long, unique password used nowhere else.
Turn on two-factor authentication — an authenticator app if offered, not SMS.
Check the "recovery" settings. An old phone number or a dead backup email is a side door.
02Stop reusing passwords
The realistic attack isn't someone guessing your password. It's a company you signed up with years ago getting breached, and attackers trying that same email and password everywhere else. That's called credential stuffing, and it's automated and constant.
The one tool worth having: a password manager. It generates and remembers unique passwords so you only memorize one. Any reputable one is dramatically better than reusing passwords, which is the actual thing hurting people.
You don't have to convert every account at once. Do email, banking, and your phone/Apple/Google account first, then change others as you naturally log in.
03Turn on 2FA where money or identity lives
Banking, payment apps, your phone carrier account, your primary Google/Apple account, and anywhere your card is saved. Prefer an authenticator app over SMS where you can — SMS can be defeated by SIM-swapping, where someone convinces your carrier to move your number to their phone.
Worth doing once: call your mobile carrier and ask for a port-out PIN or account lock. It takes ten minutes and it's the specific defense against SIM-swap, which is how people with valuable accounts actually get taken.
04Update things automatically
Phone, computer, and browser — turn on automatic updates and let them run. Most successful attacks use known vulnerabilities that were patched months earlier. This is the highest-value thing you can do that requires no ongoing effort.
05Learn the shape of a scam, not a list of them
The specific stories change constantly; the structure doesn't. Nearly every scam has two ingredients: urgency and an unusual payment or login request.
Your bank will never need you to move money to a "safe account." That is always a scam.
Nobody legitimate is paid in gift cards, crypto, or wire because it's "faster."
If a message pressures you to act immediately, that pressure is the attack.
Don't click the link — go to the site yourself the way you normally would.
The rule that beats caller ID: hang up and call back on a number you already had — off your card, your statement, or the official site. Caller ID and sender addresses are trivially faked. Verifying on a channel you chose defeats nearly all of it.
06Back up what you'd hate to lose
Photos and documents, in two places, one of them not in your house. Cloud backup plus an external drive covers theft, fire, and ransomware. Then check once that you can actually restore a file — untested backups have a way of not existing.
07If something's already wrong
Start with email. Change that password first, then check its forwarding rules and filters — attackers add rules to quietly copy your mail.
Change passwords on anything sharing that password, banking first.
Sign out of all devices/sessions in the account's security settings.
Check whether your address appears in known breaches, and prioritize those accounts.
If money moved, call your bank immediately — speed genuinely matters for recovery.
Want the full checklist to work through?
The Personal Cybersecurity Checklist — every step in order, so you can tick them off and know you didn't miss one. Instant download.
Unique password on your email, 2FA on email and money, automatic updates, and hang-up-and-call-back when anything feels urgent. Four habits. They're not exciting and they handle most of what actually happens.