Most successful attacks do not involve genius hackers. They involve a reused password, a convincing fake message, or a device that missed an update. That is encouraging, because it means a handful of habits stop most of the attacks people actually face.
This is the second step in our cybersecurity basics learning path. If you are new to the topic, start with What Is Cybersecurity? first.
Habit 1: one strong password per account
When a website is breached, attackers often get a list of email addresses and passwords. They then try those same pairs on hundreds of other sites, a technique called credential stuffing. If you reused the password, one breach becomes many.
So the most important rule is a different password for every account. Nobody can remember dozens of strong passwords, and nobody should try. Two practical approaches:
- A password manager. An app that creates and remembers a long random password for each site, locked behind one strong master password. Most phones and browsers include one.
- Passphrases. Several unrelated words strung together, such as four or five random words, are long, hard to guess, and easier to type than a jumble of symbols.
Length matters more than cleverness. Swapping letters for numbers ("p4ssw0rd") fools no one; attackers' tools try those substitutions automatically.
Habit 2: turn on multi-factor sign-in
Multi-factor authentication (MFA) means signing in with two kinds of proof: something you know (a password) plus something you have (your phone or a security key) or something you are (a fingerprint). A stolen password alone is then not enough.
Turn it on first for the accounts that unlock everything else: your email, because it can reset every other password, and any account tied to money. An authenticator app or a physical security key is stronger than a code sent by text message, but any second factor is far better than none.
One warning: if anyone asks you to read them a sign-in code, it is a scam. Real companies do not ask for those codes.
Habit 3: learn to spot phishing
Phishing is a message that pretends to come from someone you trust, to get you to click a link, open an attachment, enter a password, or send money. It arrives by email, text, social media, or phone call.
Warning signs:
- Urgency or fear. "Your account will be closed in 24 hours." "Unusual activity detected."
- A request for credentials, codes, or payment. Especially gift cards or wire transfers.
- A sender or link that is almost right. A misspelled company name, or a link whose real address does not match the organization.
- Something unexpected. A prize you did not enter, a delivery you did not order, an invoice from a company you do not use.
The safest response is to go around the message. Do not click the link. Open the app or type the website address yourself, or call the organization using a number you already know. If the message was real, the same information will be waiting there.
Habit 4: keep everything updated
Updates often fix vulnerabilities: weaknesses that attackers already know how to use. Once a fix is published, attackers study it and target everyone who has not installed it yet. Delaying updates leaves a known door open.
Turn on automatic updates for your phone, computer, browser, and apps. Replace devices that no longer receive security updates; an old router or phone that the manufacturer has stopped supporting will never be fixed.
Habit 5: share carefully
Information you post can be used to guess passwords, answer security questions, or make a phishing message more convincing. Before sharing, ask:
- Does this reveal where I live, where I go to school, or when my home is empty?
- Would I be comfortable with a stranger, an employer, or a college seeing this in five years?
- Does this app really need my location, contacts, or microphone?
Review the privacy settings on your accounts and remove app permissions you do not use. Good digital citizenship also means protecting other people: ask before posting photos of friends, and never share someone else's private information.
If something goes wrong
Mistakes happen to careful people. If you clicked a bad link or think an account was taken over:
- Change the password for that account, and anywhere else you used it.
- Turn on MFA if it was not already on.
- Tell someone: a parent, teacher, your IT team, or the organization involved. Speed matters more than embarrassment.
- Watch for unusual activity in your email, bank, and social accounts.
Try it yourself
Do a 30-minute security checkup:
- Turn on MFA for your main email account.
- Find one account where you reused a password and change it.
- Check that automatic updates are on for your phone and browser.
- Review which apps have access to your location and remove one you do not need.
The next step in this path looks at the other side: how attackers find weaknesses in software itself.
Further reading
- Our glossary defines every security term in this path in plain English.
- Cybersecurity Basics: Digital Citizenship Glossary of Terms from Recorded Future covers online safety vocabulary for students. Suggested by a student reader.