Lots of people ask us for simple cybersecurity tips, so we’ve written down what we think are the most important things you should know or do about keeping you and your business safe from online threats. Of course, our cybersecurity services and IT services go much deeper than this with enterprise-level protection, but this will at least get you started…at least with protecting yourself personally.
Click the name of a tip to read all about it.
Don’t Trust
Bad guys are now experts in making fake things look real. That means the email from your bank asking you to confirm your password might look like a real email, even though the bank would never ask you to do such a thing.
And the email from the other executive in your company, your CPA, your wife or husband asking you to send money or click a link…there is a very good chance those are fake, too.
The bad guys are very, very good at what they do, and they WILL GET YOU if you’re not careful. That’s why we advise you to “DON’T TRUST”.
Don’t Respond
But what do you do if you’re really, really sure it’s a legitimate email, text message or Facebook post?
The answer is that you DON’T RESPOND in the way they are asking you to.
That means you don’t click the bank link they gave you, because it may be fake. WellsFORgo.com could look a lot like WellsFARgo.com if you’re not careful. But also the actual link behind ANY text or button could be entirely different than what you think.
And the phone number they give you might not actually be the phone number of McAfee Antivirus or Paypal or Amazon, but instead might be to a call center in India, with hundreds of scammers waiting for callers who TRUST too much.
So my advice is that you confirm some other way. YOU type in your bank’s URL. YOU look up the correct phone number on the website. YOU confirm that your boss, colleague, husband or wife actually needs you to buy $500 worth of Target gift cards BEFORE you drive to the store.
Do not respond using the easy way the bad guys give you. Respond in a way that you KNOW is correct.
Use a Complex Passwords
Hackers have tools that will use brute force and thousands of tries to log into websites. If you are using short or easy to guess passwords (the street you grew up on, or your birthdate, and so on), there is a good chance you will get hacked.
That is why it is very important to use long and complex passwords. For example, rather than using easily remembered words or numbers, use a combination of words, numbers, and symbols. Here’s example: uewh7mFa4F$6krNxow
No one would guess this. The problem is that it’s harder for you to remember…but don’t worry. We’ve got a solution for that in the next tip, using a Password Manager..
Use a Password Manager
A password manager is a piece of software that can remember not only your passwords, but your login URLs and usernames. When you want to log into a site, you tell the password manager to log in, and it navigates to the login pages and fills in your username and password for you.
And then the password manager is itself protected by a single password, often with Multi-factor authentication (see next section to learn about MFA).
The advantage to users is that they only need to remember one password, they save time logging into websites, and it makes it very easy for you to use very long and complex passwords for logging into individual sites.
Use MultiFactor Authentication (MFA)
Multi-factor authentication (MFA), which is also sometimes referred to as Two-Factor Authentication (2FA) adds a vital layer of security to your accounts by requiring more than just a password for access. By combining something you know (your password) with something you have (like a mobile phone) or something you are (like a fingerprint), MFA significantly reduces the risk of unauthorized access, even if your password is compromised.
Basically, what happens is that when anyone tries to log into your account with a legitimate username and password, the system will ask an MFA question. That answer could be a code sent via text message to your phone or email, or to get a code from a third-party piece of software, or to scan your fingerprint or face.
Implementing MFA across all your accounts helps protect sensitive information and makes it much harder for cybercriminals to exploit weak or stolen credentials. It’s a simple but powerful tool in enhancing your overall cybersecurity posture.
Setup Bank Alerts
A common scam is to hack into your bank and steal your money. If you follow the tips above, you are less likely to be a victim to such things. But just in case someone manages to log into your bank, how do you protect yourself?
The answer is to set up Alerts at your bank, which is a proactive way to monitor your financial activity and quickly detect any suspicious transactions. Alerts can notify you of unusual purchases, low balances, or large withdrawals, enabling you to respond quickly to potential fraud.
They can also help you stay on top of your finances by reminding you of upcoming payments or significant account changes.
This real-time awareness can prevent overdraft fees, improve budgeting, and give you peace of mind knowing you’re closely watching your money. In essence, bank alerts are a simple yet effective tool for maintaining financial security and control.
Add a Cell Phone PIN Code
Since mobile phones are often used for Multi-Factor Authentication, and store so much critical personal information, it makes sense that if a bad guy can access your phone, or even your phone account, you’ll be in serious trouble.
There are lots of bad guys who will try to steal your identity by cloning your phone number, accessing your mobile phone account or making changes to your mobile phone account in an effort to steal your identity.
That’s why it is important to set up an Account Change PIN code with your mobile phone provider. Since this PIN code would be needed in order to make any changes to your account — or to verify your account in the event of a breach — you can block such activity before it even begins.
Use an Antivirus System
Bad guys use fake links and malicious software to steal your information, steal your money, monitor your activity, and get you to do things you shouldn’t do. Using software to protect yourself — usually referred to as Antivirus software — is an important first step to protect yourself.
Antivirus software acts as a first technical line of defense by detecting and blocking malicious software before it can hurt you or your computer. Regular scans and real-time protection help ensure that your computer system — whether it’s a PC or Mac — remains safe from threats.
Talk to us for our most recent list of preferred Antivirus software. Some are amazing, and others do almost nothing.
Learn How To Spot Fake Links & Email Senders
We’re all in a hurry, and don’t always read as carefully as we should. That’s what the bad guys depend on when they disguise malicious links and use deceptive email addresses to trick you into revealing sensitive information or downloading malware.
Many people don’t know that the URL inside a link does NOT need to match the published link. For example, RealWebsite.com might look like a real link to RealWebsite.com, but it can actually be a link to FakeAndDangerousWebsite.com.
To protect yourself, always hover over links to see the actual URL before clicking, and check the sender’s email address for slight misspellings or unusual domains (wellsFORgo vs wellsFARgo, for example).
Also, be cautious of unexpected requests for personal information or urgent actions that might cause you to hurry and not thoroughly examine the sender’s URL or link URLs.
Need More CyberSecurity Help?
Max Avrukin, founder of DigitalUppercut, has been a leader in the IT and CyberSecurity field for 20 years. If your company wants to not worry about your IT or Cybersecurity each and every day, contact Max at DigitalUppercut or call him at 213-398-8771.