Security
The Digital Privacy Playbook: Practical Steps That Actually Protect You
Most privacy advice fails because it is either too vague to act on or so extreme that nobody keeps it up for a week. This playbook is built the other way round: a short list of changes ranked by how much risk each one removes per minute spent. Work down it in order and stop wherever the cost stops feeling worth it. Even the first two sections put you ahead of the overwhelming majority of accounts that get compromised.
Start with the account that owns everything
Your primary email is the master key. Every reset link, every recovery code and every account confirmation lands there. An attacker who owns it owns your bank, your cloud storage and your social presence, regardless of how strong those individual passwords are.
Give that account a unique password used nowhere else, the strongest second factor you can enable, and a recovery path that does not depend on an SMS to a number that can be ported away. Then check the list of connected apps and revoke everything you no longer recognise.
If you do nothing else in this guide, do this. It is roughly ten minutes and it removes the single largest category of catastrophic loss.
Passwords: the only system that survives contact with reality
A manager, not a memory
Reused passwords are the reason breaches cascade. One leaked shopping site becomes a bank login because the same string protected both. No human can remember a hundred unique strings, which is why the answer is a password manager rather than more discipline.
Pick any reputable manager, set one long passphrase you can actually recall, and let it generate everything else. Import your browser-saved logins, then use the manager's own breach report to fix the reused and exposed ones first.
Passkeys are steadily replacing this entirely. Where a site offers a passkey, take it: there is no shared secret to steal, and phishing pages cannot collect one because the credential is bound to the real domain.
- One unique credential per site, generated not invented
- A single strong passphrase protecting the vault
- Passkeys wherever they are offered
- Fix reused and breached entries before anything else
Second factors, ranked
Not all two-factor is equal. A hardware key or a passkey is the strongest, because it verifies the site's identity as well as yours. An authenticator app generating codes is a solid middle ground. SMS is the weakest, because a SIM swap moves your number to someone else's hands without touching your phone.
SMS is still far better than nothing. If it is the only option a service supports, enable it, and separately ask your mobile operator to place a port-out lock on the number.
Save your backup codes somewhere offline. The most common self-inflicted lockout is enabling strong two-factor on a new phone and discarding the recovery codes on the assumption the device will never be lost.
Shrinking your data footprint
Every app you grant location, contacts and microphone access to is a copy of your life sitting on someone else's server, governed by a policy you did not read. Auditing permissions once removes years of accumulated access.
Go through your phone's privacy dashboard and downgrade location to while-using for everything except navigation and emergency tools. Revoke contact access from anything that is not a messaging app; that permission is how your address book ends up in advertising graphs.
On the browser side, a content blocker and a search engine that does not build a profile cover most of the tracking you meet day to day. Clearing cookies periodically breaks the long-lived identifiers that stitch your sessions together.
Recognising phishing in the moment
The pressure is the tell
Modern phishing is well written and visually perfect. Spelling mistakes are no longer the signal. What remains constant is manufactured urgency: an account closing, a payment failing, a refund expiring, a delivery held. Urgency exists to stop you from checking.
The reliable defence is a habit rather than a judgement. Never act inside a message. Close it, open the app or type the address yourself, and see whether the same alert is waiting for you there. If it is real, it will be.
Treat unexpected attachments and shortened links as hostile by default, and treat any call that asks you to install software, share a screen or read out a code as fraud regardless of who it claims to be.
Devices, networks and backups
Automatic updates are the highest-value security setting on any device, because most real attacks use flaws that were patched months earlier. Turn them on everywhere and let reboots happen.
Full-disk encryption is on by default on modern phones and most laptops; confirm it rather than assume it. Combine it with a lock screen that actually engages quickly, because physical access is a far more common threat than remote intrusion.
Public networks are less dangerous than they once were now that nearly all traffic is encrypted in transit, but a reputable VPN still helps on hotel and airport connections. Finally, keep a backup you could restore from tomorrow: ransomware and a dropped phone have identical consequences without one.
- Automatic updates on, everywhere
- Encryption confirmed and a fast-engaging lock screen
- One offsite backup you have actually tested
What to do in the first hour of a breach
Change the password on the affected account and on your primary email, in that order. Sign out all other sessions, which most services offer as a single button, then review the account's recent activity and connected devices.
Check whether the recovery email or phone number was quietly changed; that is the standard move to lock the real owner out. Restore it, then rotate the second factor entirely rather than trusting the existing one.
Tell the people affected. If a messaging or social account was involved, a short public note prevents your contacts from being scammed by someone wearing your name.
The honest summary
Privacy is not a product you buy once, and total anonymity is not a realistic goal for a person who wants to use the internet. What is realistic is being a substantially harder target than the default, which is where nearly all opportunistic attacks stop.
Unique credentials, strong second factors, permissions kept short, updates applied and a backup you trust. Five habits, an afternoon of setup, and a risk profile that looks nothing like the one you started with.