In today’s digital world, cyberattacks are unfortunately quite common. Cybercrimes take many forms, from large-scale attacks that target corporations to smaller phishing attacks aimed at gaining a person’s personal information.
October is Cybersecurity Awareness Month, but good online hygiene should be practiced year-round.
We all have a part to play in cybersecurity. When we hear about massive data breaches, it can feel overwhelming and lead us to think we’re powerless to stop cybercriminals. The truth is there are several practical steps we can take to safeguard our devices and data.
Here are four easy ways to boost your cyber hygiene.
Enable multifactor authentication. Also known as two-step verification, multifactor authentication adds a second step when you log into an account. It could be a PIN, security question, code sent to your email or secure token.
Regardless of the type of authentication, this additional step makes it at least twice as hard for cybercriminals to access your account. Some accounts require MFA while others offer it as an extra security layer users can turn on, and you should use it when it’s available.
Use strong passwords and a password manager. Passwords are the “keys” to your online home. Your passwords should always be long, unique and complex. Create passwords using at least 12 characters and a combination of upper- and lowercase letters, numbers, and special characters.
Never reuse passwords for multiple accounts. If you have many accounts, consider using a password manager to store them easily and securely in one place.
Keep software up to date. It may seem obvious, but regularly updating software is one of the easiest ways to keep your personal information secure. Most companies provide automatic updates and will send reminders so you can easily install them. If you’re not receiving automatic software updates, set a reminder to do so quarterly.
Be aware that some cybercriminals will send fake updates; these typically appear as a pop-up window when visiting a website. Use good judgment and always think before you click.
Don’t take the bait: Learn to recognize and report phishing attacks. The signs of a phishing attack can be subtle, so take the extra time to thoroughly inspect suspicious emails and other messages.
Most phishing emails include offers that are too good to be true, an urgent or alarming tone, misspellings and odd language, ambiguous greetings, strange requests, or an email address that doesn’t match the company or person it’s coming from. Most platforms like Outlook, Gmail and iCloud allow users to report phishing emails. If you suspect a phishing attempt, take an extra minute to report it.
Cybercriminals aren’t going away, but when we all take a risk-based approach to our lives online, we’re creating a safer internet for all. Visit cisa.gov for additional cybersecurity tips.