Key takeaways
- Five concrete habits close the most common ways into personal accounts and devices
- None require technical skill, and the basic version needs no paid software
- About 90 minutes in total, spread across one week (our estimate)
- The five habits: password manager, 2FA, software updates, email scrutiny, backup
Most cybersecurity advice is overwhelming. Articles list 50 things to do, and none of them is concrete enough to start with. This one is different: five habits that close the most common ways attackers get into personal accounts and devices. Do them over the next week and you will have shut the doors that most consumer attacks walk through.
Total time: about 90 minutes, spread across the week (our estimate). No paid software is required for the basic version; paid upgrades exist and are optional.
1. Install a password manager (about 20 minutes, this week)
The most important habit is using a unique, randomly generated password for every account. The reason: when one service is breached, your password ends up in a database that gets sold or leaked. If you reuse it elsewhere, attackers test it automatically against other major services. This is called credential stuffing, and it is one of the most common ways personal accounts are taken over.
A password manager generates a long random password for every new account, stores them encrypted, and fills them in on every device. You only need to remember one master password.
Un passo avanti. Sempre.
Unisciti al nostro canale Telegram per ricevere
aggiornamenti mirati, notizie selezionate e contenuti che fanno davvero la differenza.
Zero distrazioni, solo ciò che conta.
Entra nel Canale
What to install: Bitwarden’s free plan covers most people. 1Password is a paid alternative (the individual plan costs $47.88 a year since its price change of March 2026; check the current price before you subscribe).
Steps:
1. Sign up at bitwarden.com (or 1password.com)
2. Create a strong master password (long, and written on paper as a backup kept somewhere safe)
3. Install the browser extension on Chrome, Firefox, Safari or Edge
4. Install the mobile app on iPhone or Android
5. Over the next month, each time you log into an existing account, let the password manager save it. When a service asks you to change a password, let the manager generate a strong one.
After a few months you will not know what your individual passwords are. That is the goal.
2. Enable 2FA on your critical accounts (about 15 minutes, this week)
Two-factor authentication (2FA) means that, besides your password, a login needs a second proof of identity: a code from your phone, a hardware key, or a fingerprint. Even if an attacker gets your password through phishing or a breach, the second factor makes it much harder to log in as you. It does not make it impossible: some phishing sites also capture the code you type, or the session once you are logged in, which is why a hardware key, the hardest to phish, is the strongest option.
How much it helps has been measured. In a year-long study with researchers from New York University and the University of California, San Diego, published on May 17, 2019, Google found that an SMS code sent to a recovery phone number helped block 100 percent of automated bots, 96 percent of bulk phishing attacks and 76 percent of targeted attacks. Prompts on a signed-in phone did better still: 100, 99 and 90 percent.
Critical accounts to protect first:
– Email (Gmail, Outlook, Proton, iCloud)
– Apple ID or Google account (they control your devices)
– Bank and financial accounts
– Social media (Facebook, Instagram, X)
– Work accounts (Slack, Notion and similar)
How to enable it:
1. Open the account’s settings and find “Security” or “2-step verification”
2. Turn on 2FA and choose the method:
– Good: an authenticator app (Google Authenticator, Authy, 1Password or Bitwarden’s authenticator)
– Acceptable: SMS to your phone (much better than nothing, but exposed to SIM-swap attacks)
– Strongest: a hardware key (YubiKey, Google Titan) for your most valuable accounts
Spend the first 15 minutes on your email and your bank. Add the others over the next few weeks.
3. Turn on automatic software updates (about 10 minutes, today)
Software updates fix security holes. A device that does not update stays open to flaws that are already public, and those are the ones attackers use first, because the instructions are out there.
Turn it on everywhere:
– iPhone and iPad: Settings > General > Software Update > Automatic Updates
– Android: Settings > System > Software Update (the exact path varies by manufacturer)
– Mac: System Settings > General > Software Update > Automatic updates
– Windows: Settings > Windows Update, and keep automatic updates on
– Browsers: Chrome, Firefox, Safari and Edge update themselves by default; check that this is still on
For your apps, especially banking, password manager and email, turn on automatic updates in the App Store or Play Store settings.
4. Learn to recognize phishing emails (an ongoing skill, about 20 minutes to start)
Phishing is still one of the main ways attackers get passwords, despite all the technical defenses. The attacker sends an email that looks like a real notification (a bank fraud alert, a parcel delivery, a password that is about to expire) with a link to a fake login page. You type your credentials, and they take them.
Three rules that stop most phishing:
- Never use a link in an email to log into an account. Go to the site yourself: type the address or use a bookmark. If an email says “verify your bank account”, open your bank’s app instead of clicking.
- Read the sender’s full address. Phishing emails often come from addresses that are almost right: “support@amaz0n.com” (a zero instead of an o), “security@apple-id-support.com” (not apple.com). Read the whole address on every email that asks you to act.
- Urgency is a red flag. Real companies rarely threaten to close your account within 24 hours. Phishing works by creating panic so you act before you think. When an email makes you hurry, slow down and check.
This week: scroll through your last 100 emails and look for anything that looks like phishing. Report it with the “report phishing” button of your email service, or forward it to the Anti-Phishing Working Group at reportphishing@apwg.org. Then delete it.
5. Set up a backup that lives off your device (about 25 minutes, this weekend)
Ransomware does not only hit companies: it can lock personal photos, documents and work files and ask for money to unlock them. The reliable defense is a recent copy that the ransomware cannot reach.
A two-layer backup:
Un passo avanti. Sempre.
Unisciti al nostro canale Telegram per ricevere
aggiornamenti mirati, notizie selezionate e contenuti che fanno davvero la differenza.
Zero distrazioni, solo ciò che conta.
Entra nel Canale
Layer 1: automatic cloud sync (covers most ways of losing data):
– iPhone and iPad: iCloud Backup, in Settings > [your name] > iCloud
– Android: Google One backup
– Mac: iCloud Photos and iCloud Drive
– Windows: OneDrive
Cost: Apple gives 5 GB of iCloud storage for free, and in the United States iCloud+ starts at $0.99 a month for 50 GB. Google and Microsoft have similar free and paid plans.
Layer 2: a copy on an external drive (covers ransomware and a compromised cloud account):
– Buy an external drive large enough for your files
– Mac: Time Machine makes a full backup automatically when the drive is connected
– Windows: File History backs up automatically
– Connect it once a month, let it finish, then disconnect it. This matters: a drive that is always connected can be encrypted by ransomware together with everything else.
The disconnected drive is the key defense. Ransomware can only encrypt what it can reach.
What this costs, and what it protects you from
The basic version of these five habits is free, except for the external drive, which is a one-time purchase:
– Bitwarden free plan: $0
– An authenticator app: $0
– Software updates: $0
– Spotting phishing: $0
– iCloud or Google free storage: $0
– An external drive: a one-time cost
What it protects you from is large. In its data for 2024, the US Federal Trade Commission reported that consumers said they had lost $12.5 billion to fraud, 25 percent more than the year before. The largest share went to investment scams ($5.7 billion) and impostor scams ($2.95 billion): messages that push you to act fast. That is why habit 4, slowing down when an email hurries you, matters as much as the technical ones.
What to do this week
Monday: install Bitwarden and save your first 10 passwords.
Tuesday: turn on 2FA for your email and your bank.
Wednesday: turn on automatic updates on all your devices.
Thursday: check your inbox for phishing, report it and delete it.
Friday: order an external drive.
Weekend: set up Time Machine or File History.
Next month: move all your old passwords into Bitwarden and turn on 2FA on more accounts.
The five habits work together, each one making the next more effective. The password manager makes phishing harder, because it only fills in your password on the real site. 2FA makes a stolen password much less useful. Updates close holes before they are used.
You did all this without buying enterprise software, hiring a consultant or learning to code. You read one article and acted on it.
Welcome to From Noob to Ninja. This is lesson one.
Sources
- Google Security Blog, Kurt Thomas and Angelika Moscicki, “New research: How effective is basic account hygiene at preventing hijacking”, May 2019: https://security.googleblog.com/2019/05/new-research-how-effective-is-basic.html
- US Federal Trade Commission, “New FTC Data Show a Big Jump in Reported Losses to Fraud to $12.5 Billion in 2024”, March 2025: https://www.ftc.gov/news-events/news/press-releases/2025/03/new-ftc-data-show-big-jump-reported-losses-fraud-125-billion-2024
- Anti-Phishing Working Group, how to report phishing: https://education.apwg.org/report-phishing/overview/
- Apple, iCloud+ plans: https://www.apple.com/icloud/
- 1Password price change of March 2026, reported by MacRumors on February 24, 2026: https://www.macrumors.com/2026/02/24/1password-march-price-increase/





Leave a Reply