Your Personal Security Checklist
You do not need to do everything at once. Start with the items that feel most manageable and work your way through the list over a few days or weeks. Each step you complete makes you meaningfully more secure.
Passwords
- Use a unique password for every account. Never reuse passwords across sites.
- Make passwords at least 12 characters long. Passphrases (like PurpleSunsetBicycle7!) are strong and easy to remember.
- Set up a password manager to store and generate your passwords securely.
- Change passwords immediately for any account that has been involved in a data breach.
Two-Factor Authentication
- Enable two-factor authentication (2FA) on your email account first. It is the gateway to all your other accounts.
- Turn on 2FA for banking, social media, and cloud storage accounts.
- Use an authenticator app rather than SMS when possible for stronger protection.
- Save your backup codes in a secure location in case you lose access to your phone.
Backups
- Identify your most important files, including photos, documents, and work projects.
- Set up automatic backups to the cloud, an external drive, or both.
- Test your backups every few months by restoring a file to make sure they work.
- Follow the 3-2-1 rule: three copies of data, on two types of storage, with one copy off-site.
Software Updates
- Turn on automatic updates for your operating system (Windows, macOS, iOS, Android).
- Keep your web browser updated. It is your main window to the internet.
- Update apps on your phone regularly, especially banking and security-related apps.
- Do not ignore update notifications. They often include important security patches.
Privacy Settings
- Review privacy settings on your social media accounts and set profiles to friends-only or private.
- Limit app permissions on your phone. Give apps only the access they need.
- Clear cookies and browsing data periodically.
- Consider using a privacy-focused browser or search engine for everyday browsing.
Browser Security
- Bookmark important websites (bank, email, shopping) to avoid phishing sites.
- Look for HTTPS and the padlock icon before entering passwords or payment information.
- Only install browser extensions from trusted sources and remove ones you no longer use.
- Be cautious with downloads. Only download software from official websites.
Email Security
- Use a strong, unique password for your email account.
- Enable 2FA on your email.
- Be skeptical of unexpected emails with links or attachments, even from people you know.
- Review connected apps and remove any you no longer use.
Mobile Security
- Use a PIN, password, or biometric lock (fingerprint or face) on your phone.
- Only install apps from official app stores.
- Review app permissions and revoke any that are unnecessary.
- Enable remote wipe so you can erase your phone if it is lost or stolen.
Getting Started
Pick three items from this checklist that you have not done yet and complete them today. Then come back tomorrow and do three more. Within a week, you will have made significant improvements to your overall online security, without any technical expertise required.