Stay safe online
Practical steps that actually reduce your risk. Pick one area, make one change, then come back for the next.
Protect Your Accounts
Use a Password Manager
A password manager creates and stores a unique, strong password for every account so you only need to remember one master password. Look for open-source or independently audited options, end-to-end encryption, local storage choices, and a clear security track record. Compare a few reputable managers and choose one that fits your devices and budget.
Turn on MFA/2FA
Multi-factor authentication adds a second step after your password — usually a code from an app, a hardware key, or a biometric check. Even if your password leaks, attackers can't get in without that second factor. Turn it on for email, banking, and any account that holds sensitive data.
Secure Your Email
Your email is the master key to most of your online life. Protect it with a strong, unique password, MFA, and a recovery option only you control. Watch for suspicious sign-in alerts and review connected apps and forwarding rules regularly.
Protect Your Recovery Options
Recovery codes, backup email addresses, and phone numbers are how you get back into an account if you're locked out. Store backup codes somewhere safe and offline, keep recovery phone numbers current, and avoid using an easily guessed email for recovery.
Protect Your Devices
Keep Devices Updated
Most attacks use known bugs that already have a patch. Turn on automatic updates for your operating system, browser, and apps, and install security updates as soon as they're available. A fully patched device closes the doors attackers use most.
Use Antivirus Protection
Modern operating systems include built-in protection that is enough for most users. If you want extra tools, look for software from established vendors with transparent testing, independent reviews, and a privacy policy you understand. Avoid tools that make exaggerated claims or come from unknown sources.
Block Malicious Ads & Trackers
Malvertising and invasive trackers can lead you to scam sites or fingerprint your browsing. A reputable ad blocker or privacy-focused browser can reduce this risk. Choose one with a clear privacy policy, open development, and positive independent reviews.
Back Up Important Files
If ransomware, theft, or hardware failure hits, a backup is your safety net. Keep copies in at least two places — for example, an encrypted cloud service and an external drive you disconnect when not in use. Test that you can actually restore files from your backup.
Browse & Connect Safely
Verify Before You Click
Stop and check before clicking links, opening attachments, or scanning QR codes. Hover to see the real URL, look up the sender through a separate channel, and be especially cautious when a message creates urgency or asks for money or login details.
Secure Your Wi-Fi
Change your router's default admin password, use the strongest encryption available (WPA3 or WPA2), and keep router firmware updated. Avoid using the default network name, and consider hiding your network or using a guest network for visitors and smart devices.
Use HTTPS & Trusted Websites
HTTPS encrypts data between you and a site, but it does not mean the site is legitimate. Check the domain carefully for misspellings or odd endings, use bookmarks for important sites, and verify unfamiliar sites through independent reviews or searches before entering personal info.
Protect Your Personal Information
Think Before You Share
Details like your birthday, address, pet names, workplace, and travel plans can be used to impersonate you or answer security questions. Share less publicly, review old posts, and assume anything posted online can be copied or archived.
Limit App Permissions
Apps often request access to contacts, camera, microphone, location, and files they do not need. Review permissions in your device settings, deny what isn't required, and remove apps you no longer use. The less data an app can reach, the less it can leak.
If Something Goes Wrong
If you suspect a hack, scam, or identity theft, act quickly. These steps limit damage and help you recover.
Secure your email first
Your email can reset most other accounts. Change its password and review recent activity, forwarding rules, and connected apps.
Change compromised passwords
Update the password for any account that was breached or reused. Make each one unique, and turn on MFA where available.
Sign out of other sessions
Use your account security settings to sign out of all devices. This kicks attackers out of active sessions.
Contact your bank
If any financial information was exposed, call your bank or card issuer to watch for fraud or freeze cards.
Freeze your credit
A credit freeze stops new accounts from being opened in your name. It is free, reversible, and one of the strongest protections against identity theft.
Report identity theft
File a report with your national identity-theft authority. This creates an official record and starts recovery steps.
Remove suspicious software
Uninstall unknown programs or browser extensions, run a security scan, and reset your browser if odd behavior continues.
Report the scam
Report phishing, fraud, and impersonation to the platform, your local cybercrime unit, and any relevant company being impersonated.
Not sure what to do?
Describe what happened and LucidBot will walk you through the right first steps.
If you do nothing else: turn on MFA on your email account. Your email is the master key to everything else.
CyberLucid provides educational information, not endorsements or guarantees. Before installing or purchasing any security product, verify current details on the vendor's official website and check recent independent reviews and security research.