How to protect against IT attacks — IT defence
How to protect yourself from IT attacks — IT protection In the lines below we'll focus on companies but also households. Lots of things look similar in both contexts.
How to protect yourself from IT attacks — IT protection
In the lines below we'll focus on companies but also households. Lots of things look similar in both contexts. The biggest issues are usually data theft, viruses on computers, or accidentally deleted documents. How do you prevent it and save yourself from significant trouble?
We're here to spread the word and advise on how to behave correctly in IT risk areas.
Passwords
You can prevent password theft as follows. We recommend setting up two-factor authentication when signing in. Today this option is fortunately becoming more and more common — for example SMS or OTP code verification. OTP (one-time password) means generating a fresh password each sign-in. Other options include fingerprint or a hardware key. What should a safe password look like?- Long enough (at least 8 characters, more is better)
- Includes lowercase and uppercase letters, numbers, and special characters
- As random a sequence as possible
Email — don't forget the "back door"
When creating an email account, fill in all your contact details — otherwise, if you forget your sign-in info, the provider would send you a new password but you'd have no recovery email or phone number, and you'd simply lose access. The same goes for other services. In companies, email is the main communication tool — and also the most frequent target of cyberattacks. It's worth installing protection that monitors phishing on your email. These run not only on endpoints but also on the mail server itself — filters bouncing viruses, spam, and phishing.Don't leave devices unattended (lock them)
If you need to step away from your device, lock it. Then no one can delete anything, steal anything, write something to your social media as a "joke", or install undesirable software. Locking doesn't lose your work — all apps keep running. For those who keep forgetting: on Windows, lock with Win+L, CTRL+ALT+DEL, or via the Start menu.Security software
Everyone thinks of an installed antivirus, but that's not enough to fully protect your computer. These programs are now standard on PCs. You also need to keep Windows and other software (browser, Office suite, etc.) up to date. Updates patch flaws that progressively show up among users, so don't postpone them as a precaution. Pirated software is cheap or free, but in the end it may not pay off at all. Don't download it — there's a real risk of pulling in viruses (and other threats like spyware, ransomware = malicious software). A modern antivirus is the obvious choice. It already includes a firewall, anti-malware, anti-spyware, anti-adware, and anti-ransomware. How exactly the program and its tools work — perhaps a topic for another article. It's a fairly complex topic, but technically very interesting. Have you ever heard of a zero-day attack? How do you prevent it after following all security advice? A zero-day attack means an attacker found a "hole" in some software and exploits it unnoticed until it's discovered. Through that gap they can again drop malicious payloads onto a PC. Such an attack is often spotted by an educated person navigating this area; IPSec, which monitors network traffic, can also help — and so can a web-application firewall.We're here to spread the word and advise on how to behave correctly in IT risk areas.
Other general IT security recommendations
- Click only on verified things; think while you work. Visit verified websites and ads. Watch for fraudulent emails — especially ones pretending to come from your bank.
- Only download verified apps (via known stores) and don't grant access to everything (location, contacts, etc.) at any cost.
- Back up your data regularly. Use external drives or cloud. You can even buy software that does it for you.
- Watch out when connecting via public Wi-Fi — anyone can monitor you. So we wouldn't recommend entering personal data (banking, login credentials, etc.).
- When selling a device, just deleting things isn't enough — factory-reset it. Encrypt data first using the phone's feature. When selling a computer, format the disks. It pays to encrypt data even during normal use. Then the right files are visible only to you; if someone signed in under a different user, they wouldn't see them.
- Train your employees on IT security regularly — that prevents, for example, accidental information leaks from the company.
- Use a separate phone for business, or split off a business space on a personal device — alternatively use a dual-SIM phone.
- Watch out for properly configured webcams, so you don't have to deal with unauthorized external access.