← Back
Device Hygiene
Purpose: reduce account compromise and data loss with daily digital security habits anyone can follow.
Do This First (20 Minute Hardening)
- Turn on auto updates for OS and browser.
- Enable screen lock with strong PIN/passphrase.
- Enable 2FA on email and financial accounts first.
- Install a password manager and replace reused passwords.
Tools and Materials
- Password manager
- Authenticator app or hardware key
- OS with encryption enabled
- Antivirus/antimalware scanner (where applicable)
- Security checklist printout
Account Security Baseline
| Control | Minimum Standard | Target Standard | Review Frequency |
| Password length | 12 chars | 16+ chars passphrase | At setup only |
| 2FA | SMS fallback | Authenticator or security key | Quarterly |
| Session timeout | 10 min lock | 5 min lock | Monthly |
| Admin rights | Single admin account | Daily account + admin separate | Quarterly |
Phishing Defense Workflow
- Stop before clicking. Read sender domain fully.
- Check for urgency manipulation words.
- Open known site manually instead of clicking links.
- Validate unusual requests through a second channel.
If message says "act now" and asks for login, payment, or recovery codes, assume hostile until proven otherwise.
Decision Table for Suspicious Activity
| If this happens | Do this now | Backup action | Verify |
| Unknown login alert | Change password and revoke sessions | Rotate 2FA and recovery codes | No new login alerts in 24h |
| Clicked suspicious link | Disconnect network and run scan | Reset browser profile | No malicious extensions/processes |
| Lost phone/laptop | Remote lock/wipe if possible | Reset key account credentials | Device marked inaccessible |
| Ransom note appears | Isolate device immediately | Restore from clean backup | Data restored without payment |
Common Mistakes and Fixes
- Mistake: reused passwords. Fix: unique password for every account.
- Mistake: ignoring updates. Fix: patch within 72 hours for critical updates.
- Mistake: too many browser extensions. Fix: keep only essentials, review monthly.
- Mistake: downloading random APK/EXE files. Fix: official stores and signed sources only.
- Mistake: no recovery plan. Fix: print and store recovery codes securely.
Scenario Drills
Drill 1: Fake Invoice Email
- Present 5 mixed real/fake emails.
- Classify each in under 60 seconds.
- Explain verification steps used.
- Goal: 100 percent detection of malicious emails.
Drill 2: Account Takeover Response
- Simulate unauthorized login on one account.
- Run lockout and password reset process.
- Revoke sessions and rotate 2FA.
- Goal: containment in under 15 minutes.
Printable Hygiene Checklist
- [ ] Auto updates enabled
- [ ] Device encryption enabled
- [ ] Unique passwords for critical accounts
- [ ] 2FA active on email and finance
- [ ] Recovery codes exported and stored safely
- [ ] Extension and app audit done this month
- [ ] Last security drill date logged
Safety note: never share one-time codes, even with someone claiming to be support staff.
QR REASSEMBLY: Scan content QRs in order to reconstruct this page offline.
Scan to open this page:

Offline Content QRs
Scan in order to reconstruct full page text offline.