The attacks I read about for work are not reserved for interesting targets. The same credential stuffing, the same phishing, the same stolen device: they arrive at ordinary people every day, and knowing how they work is only an advantage if you turn it around and point it at your own life.

A stolen laptop is what made me start writing any of this down. What follows is what I actually do, in the order the effort pays back.

The highest-value defences

In order of return on effort:

  1. A password manager, with a unique password per site. Password reuse is how one breach becomes many, and this single change ends credential stuffing against you. Use a strong master password you memorise.
  2. Multi-factor authentication everywhere it is offered, especially email and banking. Prefer an authenticator app or a hardware key over SMS, which is phishable and SIM-swappable.
  3. Keep software updated. Most real compromise uses a known, patched bug. Auto updates on every device.
  4. Encrypt your devices. Full-disk encryption on the laptop and phone, so a theft is a lost device rather than a data breach. This is the one on the list I learned the hard way.
  5. Back up. The 3-2-1 rule: three copies, two media, one off-site. A backup is the answer to ransomware and theft.

Recognise the attacks aimed at you

  • Phishing: an urgent message asking you to click, log in, or pay. Verify through a channel you trust, not the one in the message. Check the real sender and the real URL.
  • Fake support and pretexting: nobody legitimate asks for your password or a one-time code. Ever.
  • Malicious links and downloads: do not run what you did not seek out.

Email is the master key

Your email resets every other account. Protect it hardest: the strongest password, the strongest MFA (a hardware key), and a recovery method you control. If an attacker owns your email, they own everything downstream.

Privacy hygiene

  • Review app permissions; deny what an app does not need.
  • Limit what you post publicly; it is OSINT on you.
  • Freeze credit if that is available where you live.
  • Use a separate email for signups versus important accounts.

Recovery planning

  • Store account recovery codes somewhere secure and separate from the manager.
  • Keep an encrypted backup of the password manager.
  • Know how to remotely wipe a lost phone and laptop.