By J. Mesa
Most security incidents don’t start with a brilliant hacker. They start with a habit: a reused password, a skipped update, a quick click. The same seven habits show up again and again, in homes and in businesses.
Here is each one, why it puts you at risk, and how to fix it.
1. Why are weak passwords dangerous?
Passwords such as “password” and “123456” sit at the top of every attacker’s list. Software tries them in seconds.
The fix: Use a long passphrase made of several unrelated words. Words from another language make it harder to guess. Something built around a phrase like “Biba Mes CHamoru” means a lot to me and nothing to a cracking tool. Don’t copy an example from a blog post, mine included. Make your own, and use a different one for every account. A password manager keeps track of them.
2. Is it safe to share passwords?
No. Sharing a streaming login to catch the latest episode of a show feels harmless. Once you share a password, you no longer control where it goes. The other person may reuse it, save it somewhere unsafe, or fall for a phishing email.
The fix: Give each person their own account. For family services, use the plan’s built-in sharing feature. At work, never share a login. If several people need the same system, give each one a separate account, so you can see who did what and remove access when someone leaves.
3. Is public Wi-Fi safe?
Public Wi-Fi in an airport, hotel, or café is a shared network. An attacker on it can set up a fake hotspot with a similar name or try to intercept traffic that is not encrypted.
The fix:
- Confirm the network name with staff before you join
- Use your phone’s hotspot for banking and work
- Use a virtual private network (VPN) when you handle sensitive or business data while traveling
- Turn off automatic connection to open networks
4. What happens if I click a suspicious link?
Phishing is a common way for attackers to get into accounts. A link can lead to a fake login page that captures your password, or it can install malware on your device.
The fix: Check the address before you click. Don’t open attachments you did not expect. If you doubt an email, call the business or person using a phone number from their official website. Do not use the contact details in the email.
If you already clicked, change the password for that account from a different device and tell your IT contact.
5. Why do software updates matter?
Updates carry security patches that fix known flaws. Skip them, and attackers can use those flaws against you. Updates take time and interrupt your day. They also close the holes that criminals are using right now.
The fix: Turn on automatic updates for your operating system, browser, apps, and phone. Restart when asked. Replace devices that no longer receive updates.
6. Why should I change default settings?
Many routers, cameras, and other devices ship with a standard username and password such as “admin” and “admin.” Lists of those defaults are published online. Attackers scan the internet for devices that still use them.
The fix: Change the default username and password on every device as soon as you set it up. Start with your home or office router. Turn off features you don’t use, such as remote management.
7. What if I don’t back up my data?
Without a backup, a ransomware attack, a failed drive, or a stolen laptop means the data is gone.
The fix: Back up to an external drive or cloud storage. Follow the 3-2-1 rule: three copies, two types of storage, one offsite. Test that you can restore a file. It is better to have a backup and not need it than the alternative.
What other bad habits should I watch for?
- No multi-factor authentication. A second step at login blocks most attacks that use stolen passwords. Turn it on for email and banking first.
- Oversharing online. Birthdays, pet names, and travel plans help attackers guess security answers and write convincing scams.
- Using an administrator account for daily work. Malware runs with the rights of the account that opens it. Use a standard account for everyday tasks.
- Ignoring old accounts. Close accounts you no longer use. Each one is a breach waiting to happen.
Which habit should I fix first?
Start with passwords and multi-factor authentication. Stolen and weak passwords open more accounts than any other cause. Then turn on automatic updates, which takes a few minutes and keeps working without you. Backups come third.
How do I change habits across a whole team?
- Make the safe way the easy way. Provide a password manager and turn on automatic updates for everyone.
- Explain the reason behind each rule. People follow rules they understand.
- Train in short sessions through the year.
- Praise people who report a suspicious email or admit a mistake.
- Write the rules into a short policy that new hires read on day one.
How do I know if a bad habit already caused harm?
- Search your email address at haveibeenpwned.com to see if it appears in a breach
- Review the login history on your email and bank accounts
- Look for email forwarding rules you did not create
- Check that your backups ran
If you find a problem, change the password, turn on multi-factor authentication, and tell anyone who may be affected.
Are these habits a problem for businesses too?
Yes, and the stakes are higher. One employee’s reused password can expose a customer database. One unpatched server can stop operations for a week. The same seven fixes apply, and a business should add written policies and regular training.
Your next step
Pick the habit from this list that describes you and fix it today. Cybersecurity is a priority for everyone, at home and at work. If you want your whole team to build better habits, Cerberus Cybersecurity offers cybersecurity training for every audience. Contact us to learn more.
Leave a Reply