Not every security improvement requires a security team or a budget. These five habits take minutes each and close off some of the most commonly exploited weaknesses — personal or organisational.
1. Turn on MFA everywhere it's offered
Email, banking, social media, cloud storage — if an account offers multi-factor authentication, enable it. It remains the single highest-leverage control against account takeover.
2. Move your passwords into a password manager
Browser-saved passwords are a prime infostealer target. A dedicated password manager with a strong master password and its own MFA is meaningfully harder to compromise.
3. Update before you log off for the weekend
Unpatched software is still one of the most common initial-access vectors. A five-minute update before the weekend closes windows attackers actively scan for.
4. Slow down before clicking unexpected links
Hover to check the real destination, look closely at the domain for typosquatting, and treat urgency ("act now," "account suspended") as a red flag rather than a reason to rush.
5. Back up anything you can't afford to lose
Ransomware and device failure both end the same way without a backup. The 3-2-1 rule — three copies, two different media, one offsite — still holds up.

Co-published with NexSecure Cybersecurity · Nathaniel T.O, SOC Analyst
Key takeaways
- None of these require a security budget — just five minutes and a bit of consistency.
- MFA and a password manager alone eliminate a large share of common account-takeover paths.
- A backup you've never tested is not a backup you can rely on — check it works.