Cybersecurity Tips Most People Ignore: A Practical Checklist

⚠️ Affiliate Disclosure: This article contains affiliate links. If you purchase through them we may earn a commission at no extra cost to you. Read our full disclosure.

Key Takeaway:
Most people who get hacked aren’t hacked through their IP address. Attackers go after the things that unlock everything else: your email account, your phone number, reused passwords, and a few seconds of trust on a phone call. The fixes that matter most are unglamorous and mostly free — secure your email first, move away from SMS codes, lock your phone number with your carrier, freeze your credit, and verify any urgent request through a second channel. The checklist below is ordered by how much each step protects you for the effort it takes.


Why Most Security Advice Misses the Point

The FBI’s Internet Crime Complaint Center received just over 1 million complaints in 2025, with reported losses of $20.9 billion. According to the report, the biggest losses came from investment fraud, followed by business email compromise and tech-support scams — with phishing, romance scams, account takeovers and SIM swaps also tracked. Those are attacks on people and accounts, not on network addresses.

Your IP address does reveal something: your internet provider and a rough location, usually a city. That’s worth understanding (here’s what someone can and can’t do with it), but on its own it rarely leads to harm. The tips below are the ones that actually stop the attacks people fall for.


🔑 Accounts: Start With Your Email

1. Treat your email account as the master key

Almost every “forgot password” link goes to your email. Whoever controls your inbox can reset your bank, social media, shopping and cloud accounts in minutes. So secure it before anything else: a unique password used nowhere else, and two-factor authentication switched on.

2. Check for forwarding rules and connected apps

This is the step almost nobody does. A common trick after breaking into an email account is to add a quiet forwarding rule — copying your mail, or anything containing “invoice” or “password”, to the attacker — so they keep watching even after you change your password. Open your email settings and look at forwarding, filters and “connected apps” or “third-party access”. Remove anything you don’t recognise.

3. Use an app or a passkey instead of SMS codes

Any two-factor authentication is far better than none. But codes sent by text message can be intercepted if someone takes over your phone number (see tip 6). An authenticator app is stronger, and a passkey — now supported by Google, Apple, Microsoft and many large sites — is stronger still, because it only works on the real website and can’t be typed into a fake one.

4. Save your recovery codes somewhere offline

When you turn on two-factor authentication, most services give you a set of one-time recovery codes. Print them or store them in a password manager. Losing your phone without them is how people lock themselves out of their own accounts — and “account recovery” support is exactly what scammers impersonate.

5. Stop reusing passwords, and check the ones you have

When one site is breached, attackers try the same email and password on hundreds of others. A password manager removes the need to remember anything but one strong master password. To see whether a password has already appeared in a known breach, use the private check in our password tools — only the first five characters of a hash leave your browser, never the password.


📱 Your Phone Number Is an Account Too

6. Lock your number against SIM swapping

In a SIM swap, a criminal convinces your mobile carrier to move your number to their SIM card. From that moment, your calls and text codes go to them. Most carriers now offer a free number lock, port-out PIN or account PIN that has to be given before the number can be moved. Set it in your carrier’s app or account settings, and don’t use the same PIN anywhere else.

7. Keep automatic updates on — phone, browser, router

Most real-world compromises of devices use vulnerabilities that already have a fix. Automatic updates close them without you thinking about it. The router is the one people forget: it rarely updates itself, and it sits between every device you own and the internet. Our home network checklist covers the router settings worth changing.

8. Audit browser extensions and app permissions

A browser extension with permission to “read and change data on all websites” can see every page you open, including your bank. Extensions also change hands: a harmless tool can be sold and updated into adware. Remove anything you don’t use. On your phone, check which apps have location, microphone and contacts access, and switch off what they don’t need.


💳 Identity and Money

9. Freeze your credit (US)

A credit freeze stops anyone — including you — opening new credit in your name until you lift it. It’s free at all three bureaus (Equifax, Experian and TransUnion) and doesn’t affect your credit score. It’s the single most effective protection against identity theft after a data breach, and you can lift it temporarily in minutes when you apply for credit yourself.

10. Turn on transaction alerts

Most banking apps can notify you of every card payment or transfer. It costs nothing and turns fraud you’d notice at the end of the month into fraud you notice in seconds — while there’s still a chance to stop the payment.

11. Shrink what’s findable about you

People-search sites publish home addresses, phone numbers, relatives and ages — exactly what a scammer needs to sound convincing, or to answer your security questions. Removing yourself takes an afternoon; our Delete Yourself directory lists the opt-out pages for the major data brokers, in the order that makes the biggest difference.


🧠 Habits That Beat Most Scams

12. Verify urgent requests through a second channel

A call from “your bank”, a message from “your boss”, a voice note from a family member in trouble — if it’s urgent and involves money or a code, stop and contact them another way, using a number you already have. Voice cloning makes a familiar voice no guarantee any more. Agree a family code word for emergencies. The Scam Test walks through the patterns, and if you’ve already lost money, be ready for the recovery scam that often follows.

13. Keep backups that ransomware can’t reach

The rule of thumb is 3-2-1: three copies of what matters, on two different kinds of storage, with one kept offline or off-site. A backup drive that’s always plugged in gets encrypted along with everything else. A cloud backup with version history, or a drive you unplug after each backup, survives.

14. Be realistic about public Wi-Fi

Public Wi-Fi is less dangerous than it used to be, because almost every site now uses HTTPS, which encrypts what you send even on an open network. The remaining risks are fake hotspots with convincing names, login pages that ask for more than they should, and the network operator seeing which sites you visit. On networks you don’t trust, a reputable VPN hides your traffic from the network itself — we earn a commission from PureVPN and IPVanish — and the free VPN leak test shows whether any VPN is actually doing its job.


✅ The 30-Minute Version

If you only do a few, do them in this order:

Step Time What it stops
Unique password + 2FA on your email5 minTakeover of every account that resets through email
Check email forwarding rules and connected apps3 minAn attacker quietly reading your mail
Carrier number lock / port-out PIN5 minSIM swaps and stolen text codes
Credit freeze at all three bureaus (US)15 minNew accounts opened in your name
Agree a family code word1 minVoice-clone and “family emergency” scams

Then work through the rest over a weekend: password manager, passkeys, backups, extensions, data brokers.


FAQ

Is my IP address a security risk?

A small one. It shows your internet provider and an approximate location, and it can be targeted with nuisance attacks like DDoS. It doesn’t give anyone access to your accounts or files. You can see exactly what yours reveals with the free What Is My IP tool.

Is SMS two-factor authentication still worth using?

Yes — it’s much better than a password alone. It’s just the weakest form of 2FA, because it depends on your phone number staying yours. Use an authenticator app or passkey where you can, and lock your number with your carrier either way.

Does a credit freeze hurt my credit score?

No. A freeze only blocks new credit checks until you lift it. Your existing cards and accounts work normally, and it has no effect on your score.

Do I need antivirus?

On Windows and macOS, the built-in protection is decent for most people as long as updates stay on. Most losses today come from being tricked into handing over a code, a password or a payment — which no antivirus can stop — so the habits above matter more.

How do I check whether a suspicious email is real?

Don’t use the links or numbers in it; go to the company’s site or app directly. If you want to look deeper, paste the email’s headers into the free Email Header Analyzer to see whether it really came from the domain it claims.


Related Reading

Scroll to Top