The order matters more than the list
Almost every security guide is a long list of tips, all presented as equally urgent. The result is that people start with the easiest one, get bored and never reach the one that actually mattered.
This is the order by real impact:
- A unique password on your email and two-factor authentication there. Do only this and you have done half the work.
- A password manager, so you can stop reusing keys without memorising anything.
- Two-factor on banking and anything holding money.
- Recovery codes saved on paper, away from your phone.
- System and browser kept updated, which is dull and closes most technical holes.
What comes after that — VPNs, paid antivirus, specialised browsers — is perfectly respectable and has far less impact. If you have not done the five points above, starting there is optimising the wrong part.
What you are actually defending against
The mental image of someone deciding to attack you personally is almost always wrong, and it leads people to misjudge their own risk. What really happens is this:
- Automated attacks using leaked lists. A program tries millions of email-and-password pairs across dozens of services. By far the most common.
- Mass phishing. Emails and texts sent to millions of addresses hoping a small percentage bite.
- Phone fraud using real data from breaches to sound credible.
All three are indiscriminate. That is why "I am nobody important" protects you from nothing: you do not have to be interesting to be on a list.
The four decisions, with the reasoning
1. A different password on every site
This is what turns someone else's breach into a local problem instead of a cascade. It does not require memory: it requires a manager.
2. Two-factor authentication
It turns a stolen password into a minor problem. The method matters — an authenticator app resists better than SMS, and a physical key better than both — butany method turned on beats none by a wide margin.
3. Knowing how to recognise a scam
No technical measure protects you if you are the one handing over the password. Check the real domain, the real destination of the link, and whether the message is rushing you. Perfect spelling and the browser padlock prove nothing.
4. Having a plan for when something goes wrong
Recovery codes saved, a second device registered, and knowing what to do the day a breach notice arrives.
What you can stop doing
- Changing passwords every three months. Discouraged since 2017 by the very bodies that popularised it.
- Swapping letters for numbers. Attack dictionaries do that automatically.
- Avoiding public Wi-Fi for fear of traffic being read. HTTPS already encrypts it; the real risk is a fake network.
- Trusting the browser padlock as proof a site is legitimate. It only says the connection is encrypted.