Practical cyber safety tips for individuals and businesses

Stay safe this Cybersecurity Awareness Month with a practical guide designed to help you protect your personal information, devices, accounts, and organization from today's most common cyber threats.

Personal online safety tips:

Recognize and prevent common scams

Today's scams often look like everyday communications from banks, retailers, government agencies, or even people you know. Understanding the common red flags can help you separate legitimate requests from attempts to steal your information or money.

Ways to protect yourself:


Never send money to someone you've never met in person.

Be cautious of unexpected requests for personal or financial information.

Verify contact details through official websites or trusted sources.

Pause and think before responding to urgent requests or emotional appeals.

When in doubt, contact the organization directly using a trusted phone number or website.

Create strong passwords

Strong passwords remain one of the simplest and most effective ways to protect your accounts. When creating passwords, follow these best practices:


Use at least 12 characters.

Use a mix of uppercase and lowercase letters, numbers, and symbols.

Avoid using the same password across multiple accounts.‍

Steer clear of easily guessable information like your name, birthday, or pet's name.

Enable multi-factor authentication (MFA)

Passwords alone aren't enough.

Multi-factor authentication adds an extra layer of security by requiring a second form of verification, such as a code sent to your phone, a biometric scan, or a security key.

Whenever available, enable MFA, especially for email, banking, and social media.

Watch for phishing attempts

Cybercriminals often disguise malicious emails, messages, and websites as legitimate communications. They may even use personal information they have already obtained to make scams appear more convincing. Protect yourself by:


Thinking before you click links or open attachments

Verifying unexpected requests through trusted channels.

Checking email addresses and website URLs carefully

Being cautious of messages that create urgency or pressure

Questioning requests for sensitive information

Being aware of impersonation scams, fake support calls, and other tactics used to gain trust.

Watch for ClickFix scams

Cybercriminals sometimes impersonate technical support and provide step-by-step instructions designed to compromise your device instead of fixing it. Stay safe by:


Questioning unexpected error messages and security warnings

Avoiding instructions that ask you to copy, paste, or run commands

Checking with a trusted source before making changes to your device

Keeping your browser and operating system up to date.

Reporting suspicious websites or messages when possible

Keep software up to date

Software updates frequently contain security fixes that address newly discovered vulnerabilities. Regularly update:


Operating systems

Web browsers

Mobile devices

Applications and software

Monitor account activity

Reviewing account activity regularly can help you identify suspicious behavior before it becomes a larger issue. Check for:


Unrecognized login attempts

Unknown devices

Unexpected password changes

Unusual transactions or activity

If something doesn't look right, change your password immediately.

Business online safety tips:

Adopt a default-deny approach

Allow only trusted applications and processes to run and nothing else. A default-deny approach helps organizations maintain greater control over their environment, reduce risk, and prevent unauthorized software from executing.

Enforce least privilege access

Least privilege ensures users, applications, and systems have access only to the resources required to do their jobs. This helps prevent unauthorized access, restrict attacker movement, and reduce the potential impact of compromised credentials.

Secure remote access

Remote access should be tightly controlled to reduce potential attack paths. Implementing MFA, role-based access controls, strict access policies, and closing inbound ports help prevent unauthorized access while maintaining secure connectivity for remote users.

See how to enable remote access while closing inbound ports here: Zero Trust Network Access  

Segment your network

Network segmentation creates boundaries between systems, applications, and resources. These controls help prevent attackers from moving laterally across the environment and gaining access to additional assets.

Control scripts and PowerShell usage

Scripting environments and command-line utilities are commonly used in modern attacks. Restricting unauthorized script execution and monitoring privileged tools helps limit opportunities for attackers to gain a foothold or move undetected within the environment.

Remove unnecessary applications and services

Unused applications, outdated services, and unnecessary software expand your attack surface. Organizations should regularly audit their environments and remove tools, applications, and services that are no longer required.

Strengthen identity security

Compromised credentials remain one of the leading causes of cyber incidents. Strong password policies, MFA, conditional access policies, continuous authentication, and device-based verification monitoring help reduce identity-based attacks.

Maintain continuous visibility

Reducing your attack surface starts with eliminating unnecessary software and services. Organizations should routinely assess their environments and remove outdated, unused, or unapproved applications that could introduce security vulnerabilities.

Keep systems updated

Effective security requires more than reacting to threats. Prioritizing critical updates, addressing vulnerabilities promptly, and retiring unsupported software helps organizations maintain a stronger security posture.

Train employees to recognize threats

Human error continues to play a major role in cyber incidents. Ongoing security awareness training helps employees identify phishing attempts, suspicious activity, and social engineering tactics before attackers gain access.

Take the next step toward better cybersecurity

Whether you're protecting your family, your business, or both, small security improvements can make a big difference.

Additional resources: