The attacks I read about for work are not reserved for interesting targets. The same credential stuffing, the same phishing, the same stolen device: they arrive at ordinary people every day, and knowing how they work is only an advantage if you turn it around and point it at your own life.
A stolen laptop is what made me start writing any of this down. What follows is what I actually do, in the order the effort pays back.
The highest-value defences
In order of return on effort:
- A password manager, with a unique password per site. Password reuse is how one breach becomes many, and this single change ends credential stuffing against you. Use a strong master password you memorise.
- Multi-factor authentication everywhere it is offered, especially email and banking. Prefer an authenticator app or a hardware key over SMS, which is phishable and SIM-swappable.
- Keep software updated. Most real compromise uses a known, patched bug. Auto updates on every device.
- Encrypt your devices. Full-disk encryption on the laptop and phone, so a theft is a lost device rather than a data breach. This is the one on the list I learned the hard way.
- Back up. The 3-2-1 rule: three copies, two media, one off-site. A backup is the answer to ransomware and theft.
Recognise the attacks aimed at you
- Phishing: an urgent message asking you to click, log in, or pay. Verify through a channel you trust, not the one in the message. Check the real sender and the real URL.
- Fake support and pretexting: nobody legitimate asks for your password or a one-time code. Ever.
- Malicious links and downloads: do not run what you did not seek out.
Email is the master key
Your email resets every other account. Protect it hardest: the strongest password, the strongest MFA (a hardware key), and a recovery method you control. If an attacker owns your email, they own everything downstream.
Privacy hygiene
- Review app permissions; deny what an app does not need.
- Limit what you post publicly; it is OSINT on you.
- Freeze credit if that is available where you live.
- Use a separate email for signups versus important accounts.
Recovery planning
- Store account recovery codes somewhere secure and separate from the manager.
- Keep an encrypted backup of the password manager.
- Know how to remotely wipe a lost phone and laptop.
