Most breaches don't start with a genius. They start with a door you forgot to lock.
A tool that picks the right security software for your device, and seven steps that close the doors attackers actually use — not the ones we imagine.
THE TOOL
Which security software fits you?
Four questions, under a minute. No signup, no email. Results are based on independent AV-TEST and AV-Comparatives testing — not vendor marketing.
Question 1 of 4
How do you mostly use your device?
THE STEPS
Seven steps that close most doors
Every step here came out of something that actually happened, covered in the series. No theory — mistakes that cost people dearly.
01Change your router and camera passwords today
In 2016, nobody broke any security. Three young men wrote a list of sixty passwords — things like admin and 12345 — and tried them on every home device connected to the internet. It worked on hundreds of thousands of them, and those devices became an army that took down half of the American internet for hours.
Do this now: open your router settings and change the username and the password together — changing the password alone isn't enough. Then repeat it for cameras, the printer, and anything else in your home that connects to the network.
02Keep a backup the network can't reach
A copy saved on the same drive is not a backup — if the machine is hit, the copy is hit with it.
And here's a difference most people don't know: a deleted file stays on the disk until something else replaces it, which is why it can sometimes be recovered. A file that has been written over has genuinely been replaced, and there is nothing left to recover. Some attacks do exactly the second thing.
Do this now: an external drive you unplug after every backup, or a cloud service that keeps old versions. And most importantly, try restoring one file today. A backup you've never tested isn't a backup.
03Update the moment the update arrives
The virus that shut down hospitals in 150 countries in 2017 came in through a flaw Microsoft had already published the fix for — two months before it happened. It wasn't an unknown weakness. It was a known one that people put off patching.
Do this now: turn on automatic updates for your system, your browser and your phone. The 'Remind me later' button is the risk, not the update.
04Show file extensions
A file extension is the characters after the dot in its name, and it decides how your system treats it: a file ending in .txt is text that does nothing, while a file ending in .vbs is a program that runs commands on your machine.
In 2000, millions of people received an attachment whose full name was LOVE-LETTER-FOR-YOU.TXT.vbs. Windows hid the final extension by default, so all they saw was .TXT. They opened it believing it was a text note.
Do this now: in File Explorer, go to View and turn on 'File name extensions'. After that, one glance tells you what you're opening.
05Turn on two-factor — with an app, not a text
Two-factor means your password alone doesn't open your account — a second code is asked for as well.
But don't rely on text messages: a fraudster can call your mobile operator pretending to be you and move your number onto a SIM card of theirs, so the codes arrive to them instead. An authenticator app generates the code inside your own device, so it can't be moved that way.
Do this now: start with your email before any other account — every other account is recovered through it, and whoever holds it holds them all.
06The sender's name proves nothing
The name you see on a message is text the sender types themselves, and it has nothing to do with the real address it came from. And a message may genuinely come from a friend — because their machine was infected and sent itself to every name in their address book.
Do this now: before any link asking for money or login details, call the sender and confirm by voice. And urgency written into the message — 'within the hour', 'your account will be closed' — is a warning sign in itself.
07Don't put everything on one network
In 2012, tens of thousands of office machines at a major oil company went down in a single day. Yet the oil never stopped flowing for a minute, because the operational systems sat on a separate network and the virus found no route to reach them.
The idea is simple: a virus travels between machines that are connected to each other. So anything you can't afford to lose, keep it off the network everyone uses.
At home: don't leave your backup drive plugged in all the time. Copy to it, then unplug it.
At work: don't put cameras and door-access systems on the same network as staff. And ask one question — if our network went down right now, how would we get into the building and how would we talk to each other? If the answer is 'through that same network', the plan is incomplete.
THE SERIES
The full stories
Every step above came out of one of these stories.
- 1988The Morris Worm — a student took down a tenth of the internet by accident
- 1999Chernobyl — the virus that killed the motherboard itself
- 2000ILOVEYOU — a love letter that cost the world billions
- 2010Stuxnet — the first digital weapon in history
- 2012Shamoon — when a giant went back to pen and paper
- 2016Mirai — security cameras took down half the internet
- 2017WannaCry — hospitals stopped, and one man halted it by chance
- 2024CrowdStrike — the day we switched ourselves off, with no attacker
GET IN TOUCH
Consulting and partnerships
For corporate security-awareness training, technical consulting, or sponsorship and advertising partnerships — email me below.
Emailm.abutalib@thughra.net