Devices:
Check if your operating systemโ is (still) supportedOnly devices from reputable brands running an actively supported OS receive security patches. Outdated systems have known vulnerabilities that attackers can exploit.
Set your OS and apps to automatically updateโ Most cyberattacks exploit known vulnerabilities that updates have already fixed. Enable automatic updates so this happens without thinking about it.
Lock all your devices with a password, PIN, or biometrics โ The first line of defence against unauthorised access if a device is lost or stolen. Without it, anyone can pick it up and open it.
Set automatic screen lockโ (5 minutes) Prevents others from accessing your device when you step away and forget to lock it manually. Also lock it yourself any time you take a break.
Check what security software โ is already installed, and activate/install if needed Protects against viruses, malware, ransomware, and dangerous websites. Windows includes Microsoft Defender built in; Mac users should add Malwarebytes or Bitdefender.
Enable disk encryptionโ (FileVault / BitLocker / Device Encryption) A screen lock alone doesn't protect locally stored files if someone removes the drive or boots from USB. Encryption makes the data unreadable without your credentials โ and a lost unencrypted device containing personal data is mostly a reportable incident under the AVG.
Set your device's recycle bin to delete files automatically after 30 daysโ Files in the recycle bin are still on your device and recoverable. Auto-deletion ensures they're gone for good โ reducing the risk of sensitive data sitting around unnoticed.
Passwords:
Store โ all your passwords in the password manager A password manager is the only reliable way to use strong, unique passwords across all accounts without having to remember them. Easiest: use the import/exportโ function to migrate existing passwords in one go.
Delete โ all saved passwords from your browser(s) / former password manager / stored elsewhere Passwords saved in browsers, documents, emails, or on paper are easy to steal and hard to update consistently. The password manager is the single place they should live.
Replace weak passwords with strong passwordsโ generated by the password manager Human-chosen passwords are predictable. Generated passwords (minimum 14 characters, random) are not โ and the manager remembers them for you, so there's no trade-off.
Enable SSO โ (preferred option) or MFA/2FA (alternative option) on all your business accounts ( list per toolโ ) If a password is stolen or guessed, SSO/MFA is what stops an attacker from actually getting in. Enable it on every business account you have.
Policy:
Sign the Information Security Policy for employeesโ By signing, you confirm you've read and understood what's expected of you. This also gives the organisation a clear record of who has been informed.
๐ Recurring checks
Monthly:
Only needed if you couldn't set this automatically on your device (as suggested above):
Delete (or move) all items from your (1) downloads folder, (2) desktop, and (3) recycle binBusiness files that accumulate locally โ especially in Downloads โ are outside your secure cloud environment. Move them to the right business application or delete them.
Check that all security updatesโ are installed on your device Most successful attacks exploit known vulnerabilities that already have a patch available. Keeping your OS, browser, and software up to date closes those gaps.
Quarterly:
Check that the devices you use for business software still meet the requirements of the Information Security Policy for employeesโ Devices change โ new phone, different laptop, updated OS. A quarterly check ensures everything you use for work still complies.
Check your password manager's security report for weak passwords, missing MFA, or other vulnerabilities (e.g. Proton Pass monitor ) The report flags things that are easy to miss individually โ reused passwords, accounts without MFA, compromised credentials. Fix any issues flagged.
Yearly:
(Re-)read the Information Security Policy for employeesโ Policies evolve. An annual read ensures you're up to date with any changes and keeps good habits front of mind.
Take Google's phishing quiz (8 questions - takes ยฑ 5 minutes) Phishing is the most common way attackers gain access. Eight quick questions that sharpen your ability to spot it.
For organisations that use Google: Ensure that your Google Security Checkup results in 'No issues found'A quick scan of your Google account's security settings โ connected apps, recent sign-in activity, recovery options. Aim for 'No issues found'.