Skip to content
Cyber securityEstimated 9 min read time

How to practice good cyber hygiene: 10 security tips

Key Insights

  1. Keep devices updated and use unique passwords with MFA
  2. Back up files and secure your devices and home network
  3. Recognize phishing and limit what you share online

Keeping your computer, phone and other connected devices secure doesn't have to be complicated. Good cyber hygiene means developing everyday habits that help protect your devices, accounts, personal information and financial information from malware, phishing, unauthorized access and other cyber threats. Think of it as digital maintenance. Just as you lock your doors, maintain your car and protect important documents, a few simple online security habits can help protect your digital life.

Here are 10 cyber hygiene practices to add to your routine.

1. Keep your devices and software updated

Install updates for your operating system, web browser, applications and security software when they become available. Software updates often include security patches that address vulnerabilities that could otherwise be exploited by cybercriminals. Whenever possible, turn on automatic updates so important security fixes aren't missed.

Don't forget about your:

  • Computer
  • Smartphone
  • Tablet
  • Web browser
  • Applications
  • Smart devices
  • Home router

Keeping your devices and software up to date is one of the simplest ways to improve your security.

2. Use strong, unique passwords

Avoid using the same password for multiple accounts. If a password is stolen in a data breach, criminals may try those same credentials on other websites and services. Using unique passwords helps limit the damage if one account is compromised. A password manager can make this easier by creating and securely storing unique passwords for your accounts. For important accounts, consider using a long, unique passphrase rather than a short or easily guessed password.

3. Turn on multi-factor authentication

Multi-factor authentication (MFA), sometimes called two-factor authentication (2FA), adds another layer of protection to your accounts. Instead of relying only on your password, MFA requires an additional verification step when you sign in.

Turn it on whenever it is available, particularly for important accounts such as:

  • Online banking
  • Email
  • Cloud storage
  • Social media
  • Government accounts
  • Password managers

Where available, consider using phishing-resistant authentication methods such as passkeys or security keys for your most sensitive accounts. MFA can help protect an account even if your password has been compromised.

4. Use security software and your device's firewall

Many computers and mobile devices include built-in security features. Make sure they are enabled and kept up to date.

Depending on your device, this may include:

  • Antivirus or anti-malware protection
  • A firewall
  • Anti-phishing protection
  • Device encryption
  • Security monitoring

Use reputable security software and avoid downloading security programs from unfamiliar websites. A firewall can help monitor and control network traffic, providing another layer of protection between your device and potential threats.

5. Back up your important information

Imagine losing your photos, documents or other important files because your device fails, is lost or is infected with ransomware. Regular backups can help you recover your information.

Consider backing up important files to:

  • An external storage device
  • A secure cloud storage service
  • Another trusted backup location

For particularly important information, maintaining more than one backup can provide additional protection. Don't just assume your backups work. Test them periodically to make sure you can actually recover your files when you need them. The Canadian Centre for Cyber Security recommends regularly testing backup recovery and keeping backups separate from your computer where possible.

6. Secure your home Wi-Fi

Your home Wi-Fi network connects many of your devices to the internet, so it deserves attention too. Use a strong, unique Wi-Fi password and change the default administrator credentials on your router. If your router supports WPA3, use it. If WPA3 isn't available, use the strongest current security option supported by your router.

You should also keep your router's firmware updated when updates are available. When using public Wi-Fi, be particularly careful with sensitive activities such as online banking. If you need to access financial information while away from home, consider using cellular data or another trusted connection.

7. Learn how to recognize phishing

Even the best technical security tools can't replace good judgment. Phishing messages are designed to trick you into clicking a link, opening an attachment, providing personal information, sharing login credentials or sending money.

Be cautious when a message:

  • Creates a sense of urgency
  • Requests sensitive information
  • Contains an unexpected link
  • Includes an unexpected attachment
  • Asks you to make a payment
  • Claims your account has been compromised
  • Offers an unexpected prize, refund or investment opportunity

Before clicking, stop and verify. If a message appears to come from your bank, government organization or another company, contact the organization using information you find independently rather than using the link or phone number provided in the suspicious message.

8. Be careful about what information you share

Personal information can be valuable to fraudsters. Think carefully about what you share online, particularly on social media. Information such as your full name, date of birth, address, workplace, family relationships, travel plans or other personal details can sometimes be combined with information from other sources to create more convincing scams or attempts at identity theft.

Before providing personal information online, ask:

Who is asking for it, why do they need it and how will it be used?

If an unexpected message asks for personal or financial information, verify the request independently before responding.

9. Use a standard account for everyday computer use

If your computer allows you to create different types of user accounts, consider using a standard user account for everyday activities instead of an administrator account. Administrator accounts have broader system permissions. Using a standard account for routine activities can limit what malicious software or an unauthorized user may be able to do if your account is compromised. If you need administrator access to install software or make system changes, you can use your administrator credentials when required.

10. Stay informed about new scams and security threats

Cyber threats continue to evolve. Scammers regularly change their tactics, and new phishing and impersonation techniques can make fraudulent messages increasingly convincing. Take a few minutes from time to time to learn about current scams and security recommendations from trusted sources. The Canadian Centre for Cyber Security provides guidance for Canadians on protecting devices, accounts and personal information. Staying informed can help you recognize suspicious activity before you act on it.

A simple cyber hygiene checklist

You don't have to be a cybersecurity expert to improve your online security.

Start with these basic habits:

  • Keep your devices and software updated.
  • Use unique passwords or passphrases.
  • Consider using a password manager.
  • Turn on multi-factor authentication.
  • Keep security features enabled.
  • Back up important files regularly.
  • Secure your home Wi-Fi.
  • Be cautious with unexpected links and attachments.
  • Think carefully before sharing personal information.
  • Monitor your financial accounts for unusual activity.
  • Stay informed about current scams.

Small habits can make a meaningful difference over time.

What should you do if you think your device or account has been compromised?

If you believe your device, online account or banking information may have been compromised, don't panic. Start by taking steps to limit further access.

Depending on the situation, you may want to:

  1. Disconnect a potentially compromised device from the internet.
  2. Change affected passwords using a trusted device.
  3. Enable multi-factor authentication if it isn't already enabled.
  4. Contact your financial institution if banking or payment information may be affected.
  5. Monitor your accounts for unusual activity.
  6. Preserve suspicious emails, messages or other evidence.
  7. Report suspected fraud to the appropriate organization.

If you believe you have been the victim of fraud, you can report it to the Canadian Anti-Fraud Centre at 1-888-495-8501. If your YNCU banking information may have been compromised, contact YNCU as soon as possible so our team can help you determine what steps to take.

Good cyber hygiene starts with everyday habits

Cybersecurity doesn't have to mean understanding every technical threat or becoming an expert in computers. The most important steps are often simple: keep your software updated, use strong and unique passwords, turn on MFA, back up your information, protect your Wi-Fi and think twice before clicking unexpected links or sharing personal information. Good cyber hygiene is about creating habits that make your digital life safer—one small step at a time.

Frequently asked questions about cyber hygiene

What is cyber hygiene?

Cyber hygiene refers to the routine practices people use to protect their devices, accounts, personal information and data from cyber threats. Examples include using strong passwords, enabling MFA, installing software updates, backing up files and recognizing phishing attempts.

Why is cyber hygiene important?

Good cyber hygiene can reduce the risk of malware infections, account compromise, identity theft, data loss and other cyber threats. No security measure can eliminate every risk, but consistent security habits can make it more difficult for criminals to access your information.

What are the most important cyber hygiene practices?

Some of the most important practices include keeping software updated, using unique passwords, enabling multi-factor authentication, backing up important information, securing your Wi-Fi network and being cautious with unexpected messages and links.

How often should I update my computer and phone?

Install security and software updates as soon as reasonably possible. Automatic updates can help ensure that important security patches aren't missed.

Should I use a password manager?

A reputable password manager can help you create and store unique passwords for different accounts. This can make it easier to avoid reusing passwords and improve overall account security.

Is multi-factor authentication worth using?

Yes. Multi-factor authentication adds an additional verification step beyond your password and can help protect accounts if a password is stolen or compromised.

How often should I back up my files?

The appropriate backup schedule depends on how frequently your information changes and how important it is. Important files should be backed up regularly, and backups should be tested periodically to make sure they can be restored.

Is public Wi-Fi safe for online banking?

Public Wi-Fi can introduce additional security risks. For sensitive activities such as online banking, consider using your cellular data or another trusted connection instead.

If you clicked a suspicious link, don't provide additional information. Close the page and consider changing any credentials you may have entered. If financial or banking information was provided, contact your financial institution promptly using a trusted contact method.

What should I do if my banking information has been compromised?

Contact your financial institution as soon as possible. Explain what information may have been exposed and follow their instructions for protecting your account. You should also monitor your accounts for unusual activity and consider reporting suspected fraud to the Canadian Anti-Fraud Centre.

Related articles