Online security checklist
Ten habits that protect you better than any single product, most of which cost nothing.
This guide contains no partner links. It is general information for home users and small offices.
- Install updates promptly. Operating system, browser and app updates close security holes that attackers actively exploit. Turn on automatic updates wherever you can.
- Use a unique password for every account. Reused passwords mean one breach unlocks many accounts. A reputable password manager makes this practical.
- Turn on two-factor authentication (2FA). Prefer an authenticator app or a hardware security key over SMS codes, especially for email, banking and cloud storage.
- Protect your email account first. Password resets for most other accounts go to your inbox, so it is the key to everything else.
- Keep backups — and keep one offline. A common rule of thumb is 3-2-1: three copies, on two kinds of media, one of them off-site or disconnected. An offline copy cannot be encrypted by ransomware.
- Keep security software active. Use the protection built into your operating system or a reputable third-party product, and make sure it is up to date. See our guide to Avast for what these products do.
- Be suspicious of urgency. Messages demanding immediate action — “your account will be closed”, “pay now” — are a hallmark of scams. See how to spot phishing.
- Download software only from official sources. Use the developer’s website or the official app store for your device.
- Be careful on public Wi-Fi. Most sites now use encrypted HTTPS connections, which protect the content of your traffic. A VPN adds a layer of privacy on untrusted networks but does not make you anonymous and does not stop malware.
- Lock and encrypt your devices. Use a PIN, password or biometric lock, and turn on device encryption (built into modern Windows, macOS, Android and iOS devices) so a lost device does not expose your data.
If something goes wrong
- Disconnect the affected device from the network.
- From a clean device, change the password of your email account and of any account that may be affected, and check your 2FA settings.
- If money or banking details are involved, contact your bank straight away using the number on your card or its official website.
- Report fraud to the police. In the EU, national cybersecurity authorities publish guidance on what to do; in the Czech Republic this is the National Cyber and Information Security Agency (NÚKIB).
General information only. For incidents affecting a business, seek professional help.