Cybersecurity is an important part of protecting your personal information, online accounts and finances. As more of our everyday activities move online, cybercriminals have more opportunities to target passwords, financial information and personal data. Scammers can use phishing emails, text messages, fake websites, social media, impersonation and other forms of social engineering to trick people into giving up information or access to their accounts. The good news is that there are practical steps you can take to reduce your risk.
Here are some of the most important cybersecurity tips to help protect your accounts, devices and personal information.
Using the same password for multiple accounts can put several accounts at risk if that password is compromised. Create a unique password or passphrase for each important account, particularly your email, online banking, financial accounts and social media. Long passphrases can be easier to remember and harder for criminals to guess. A password manager can also help you generate and securely store unique passwords for your accounts. You don't necessarily need to change a strong password simply because a certain amount of time has passed. Instead, change it immediately if you believe it has been compromised or if there has been suspicious activity on the account. The Canadian Centre for Cyber Security recommends using long passwords or passphrases and avoiding password reuse.
Multi-factor authentication (MFA), sometimes called two-factor authentication (2FA), adds another layer of security when you sign in.
Instead of relying only on your password, MFA requires an additional form of verification, such as:
MFA can help protect your account even if someone obtains your password. The Canadian Centre for Cyber Security recommends using MFA wherever it is available, particularly for accounts containing sensitive information. For your most important accounts, such as email and financial services, consider using the strongest authentication option available.
Software updates aren't just about adding new features. They can also include security fixes that address vulnerabilities criminals could exploit.
Keep your:
Up to date.
Whenever possible, turn on automatic updates so important security patches are installed without requiring you to remember to do it manually. The Canadian Centre for Cyber Security recommends keeping operating systems and applications current with the latest security updates.
Phishing is one of the most common ways criminals try to steal personal information. A phishing message may appear to come from your bank, a government organization, a delivery company, a retailer, a friend or another trusted organization.
The message might ask you to:
Don't assume a message is legitimate simply because it uses a familiar logo, name or phone number. Instead, stop and verify the request independently. If you receive a message supposedly from your financial institution, for example, don't use the link or phone number provided in the message. Visit the institution's official website or use a trusted phone number to contact them directly. The Canadian Centre for Cyber Security recommends verifying suspicious communications and avoiding links in unsolicited messages.
Before clicking a link, ask yourself whether you were expecting the message.
Be especially cautious when a message:
When you're unsure, navigate to the organization's website yourself rather than clicking the link. Remember that sophisticated phishing attacks can look very convincing. Spelling mistakes are no longer the only warning sign.
Your social media accounts can reveal more personal information than you realize.
Information such as your:
could potentially be used by criminals to make scams or impersonation attempts more convincing. Review your privacy settings and think carefully before posting personal information publicly. Avoid sharing information that could be used to guess security questions or build a profile about you. The Canadian Centre for Cyber Security recommends limiting personal information shared online and reviewing social media privacy and security settings.
Regularly reviewing your financial transactions can help you identify suspicious activity sooner.
Look for:
Don't assume a small transaction isn't important. Criminals may test stolen payment information with a small purchase before attempting something larger. If you see a transaction you don't recognize, contact your financial institution promptly.
Your passwords, PINs and authentication codes are private.
Be extremely cautious if someone contacts you unexpectedly and asks for:
A legitimate organization generally won't need you to disclose your password or authentication code to "protect" your account. If someone asks you to provide a verification code that was sent to your phone or authentication app, stop and verify who you're dealing with. Criminals may be trying to use the code to complete a login themselves.
Technology is making some scams harder to recognize. Criminals can use information gathered from social media and other online sources to create highly personalized messages. Artificial intelligence can also make phishing messages, fake profiles, voice impersonation and other social engineering attempts more convincing. That means you shouldn't rely on obvious spelling mistakes, poor grammar or strange formatting as your only way of identifying a scam. Instead, focus on the behaviour of the request.
If someone is creating urgency, asking for sensitive information, requesting money or telling you to bypass normal procedures, take a step back and verify the request independently. The Canadian Centre for Cyber Security notes that AI is making social engineering more effective by enabling more realistic and personalized phishing and impersonation attempts.
Your home Wi-Fi network is another part of your digital security. Use a strong Wi-Fi password and change the default administrator credentials on your router. Keep your router firmware updated when updates are available. You should also protect your devices with a screen lock, PIN, password or biometric authentication. Avoid accessing sensitive financial accounts from shared or untrusted devices whenever possible.
Cybersecurity isn't only about preventing an attack. It's also about being prepared if something goes wrong. Regularly back up important documents, photos and other files to a secure location. A backup can be particularly valuable if your device is lost, damaged or affected by malware or ransomware.
If you believe one of your accounts has been compromised, act quickly.
Change the password immediately. If you used the same password anywhere else, change it on those accounts as well.
If MFA wasn't already enabled, turn it on as soon as possible.
Look for unauthorized logins, transactions, password changes, new devices or other suspicious activity.
If banking or payment information may have been compromised, contact your financial institution immediately.
Your email account is particularly important because criminals may use it to reset passwords for your other accounts. Make sure it has a unique password and MFA enabled.
If you believe you have experienced fraud or identity theft, report it to the appropriate authorities and keep records of suspicious messages, transactions and other evidence. The Canadian Centre for Cyber Security recommends changing compromised passwords, checking accounts for suspicious activity and contacting your financial institution when appropriate.
You don't need to be a cybersecurity expert to improve your online security. Start with the basics:
Use unique passwords. Turn on MFA. Keep your devices updated. Be cautious with unexpected messages. Protect your personal information. Monitor your financial accounts. And when something doesn't feel right, stop and verify before you act.
Cybercriminals continually change their tactics, so staying informed is an important part of protecting yourself.
Cybersecurity is the practice of protecting computers, mobile devices, networks, accounts and information from unauthorized access, attacks, theft and other digital threats.
Start by using strong, unique passwords or passphrases, enabling multi-factor authentication, keeping your software updated, being cautious with unexpected emails and text messages, protecting your personal information and regularly monitoring your financial accounts.
Phishing is a type of scam in which criminals impersonate a legitimate person or organization to trick you into clicking a malicious link, opening an attachment, providing sensitive information or sending money.
Yes. MFA provides an additional layer of protection because someone generally needs more than just your password to access an account. The Canadian Centre for Cyber Security recommends using MFA where available, particularly for accounts containing sensitive information.
You should change a password immediately if you believe it has been compromised. More importantly, use a unique password or passphrase for every account and consider using a password manager to help manage them securely.
Be cautious when an unexpected message asks you to click a link, provide personal information, make a payment, open an attachment or act urgently. Don't rely on spelling mistakes alone. Verify the request independently using contact information you obtain from a trusted source.
Contact your financial institution immediately. Review your accounts for suspicious transactions, follow your financial institution's instructions for securing your account and report suspected fraud to the appropriate authorities. Have concerns about your security? Call us at immediately at 1-888-277-1043