Check if your operating system is (still) supportedOnly devices from reputable brands running an actively supported OS receive security patches. Outdated systems have known vulnerabilities that attackers can exploit.
Set your OS and apps to automatically updateMost cyberattacks exploit known vulnerabilities that updates have already fixed. Enable automatic updates so this happens without thinking about it.
Lock all your devices with a password, PIN, or biometrics The first line of defence against unauthorised access if a device is lost or stolen. Without it, anyone can pick it up and open it.
Setautomatic screen lock(5 minutes)Prevents others from accessing your device when you step away and forget to lock it manually. Also lock it yourself any time you take a break.
Check whatsecurity software is already installed, and activate/install if neededProtects against viruses, malware, ransomware, and dangerous websites. Windows includes Microsoft Defender built in; Mac users should add Malwarebytes or Bitdefender.
Enable disk encryption(FileVault / BitLocker / Device Encryption)A screen lock alone doesn't protect locally stored files if someone removes the drive or boots from USB. Encryption makes the data unreadable without your credentials — and a lost unencrypted device containing personal data is mostly a reportable incident under the AVG.
Set your device's recycle bin todelete files automatically after 30 daysFiles in the recycle bin are still on your device and recoverable. Auto-deletion ensures they're gone for good — reducing the risk of sensitive data sitting around unnoticed.
Passwords:
Store all your passwords in the password managerA password manager is the only reliable way to use strong, unique passwords across all accounts without having to remember them. Easiest: use the import/export function to migrate existing passwords in one go.
Delete all saved passwords from your browser(s) / former password manager / stored elsewherePasswords saved in browsers, documents, emails, or on paper are easy to steal and hard to update consistently. The password manager is the single place they should live.
Replace weak passwords withstrong passwordsgenerated by the password managerHuman-chosen passwords are predictable. Generated passwords (minimum 14 characters, random) are not — and the manager remembers them for you, so there's no trade-off.
EnableSSO (preferred option) or MFA/2FA(alternative option) on all your business accounts (list per tool)If a password is stolen or guessed, SSO/MFA is what stops an attacker from actually getting in. Enable it on every business account you have.
Policy:
Sign theInformation Security Policy for employeesBy signing, you confirm you've read and understood what's expected of you. This also gives the organisation a clear record of who has been informed.
Recurring checks
Monthly:
Only needed if you couldn't set this automatically on your device (as suggested above):
Delete (or move) all items from your (1) downloads folder, (2) desktop, and (3) recycle binBusiness files that accumulate locally — especially in Downloads — are outside your secure cloud environment. Move them to the right business application or delete them.
Check that allsecurity updatesare installed on your deviceMost successful attacks exploit known vulnerabilities that already have a patch available. Keeping your OS, browser, and software up to date closes those gaps.
Quarterly:
Check that the devices you use for business software still meet the requirements of theInformation Security Policy for employeesDevices change — new phone, different laptop, updated OS. A quarterly check ensures everything you use for work still complies.
Check thatSSO(preferred option) orMFA/2FA(alternative option) is still active on all business accountsAccess settings can inadvertently change after updates, account migrations, or when adding new tools. A quarterly check ensures nothing has slipped through.
Check your password manager's security report for weak passwords, missing MFA, or other vulnerabilities (e.g. Proton Pass monitor ) The report flags things that are easy to miss individually — reused passwords, accounts without MFA, compromised credentials. Fix any issues flagged.
TakeGoogle's phishing quiz(8 questions - takes ± 5 minutes)Phishing is the most common way attackers gain access. Eight quick questions that sharpen your ability to spot it.
For organisations that use Google:Ensure that yourGoogle Security Checkupresults in 'No issues found'A quick scan of your Google account's security settings — connected apps, recent sign-in activity, recovery options. Aim for 'No issues found'.