Think first, then click! Don’t click on links in emails if you don’t know the sender. If you’re unsure whether the message is genuine, contact the person or company by another means (e.g. by phone) and ask whether the email really is from them.
Be wary of file attachments! Don’t open any file attachments unless you’re absolutely sure they’re safe. Although malware can disguise itself in all sorts of file formats (pdf, docx, jpeg, etc.), if the file ends in ‘exe’, you can be sure it’s a piece of software.
Be particularly wary of certain file attachments! Microsoft Office documents in particular (Word: docx, Excel: xlsx, PowerPoint: pptx) often conceal malware, as they allow you to use so-called ‘macros’ to programme small, recurring tasks (e.g. a specific table formatting). However, macros can also contain ‘malicious’ code, so you should disable them by default in your Office programme (in the Office programme: Options > Trust Centre > Macro Settings).
Choose good passwords! Use strong passwords with at least 16 characters and a combination of letters, numbers and special characters. A password manager (e.g. KeePassXC or Bitwarden) can help you manage lots of secure passwords, so you don’t have to remember them all individually.
Use two-factor authentication! Alwaysenable ‘two-factor authentication’ for accounts where you’ve stored particularly sensitive data and account details. This means that to log in, you’ll need not only a password but also an additional means of identification as a second authentication factor – this could be your mobile number or email address, for example. Anyone who only knows your password won’t be able to access the system at this stage.
Keep everything up to date! Regularly install security updates on your devices and in your apps to close any vulnerabilities in the software – this is really important. Large companies even pay their own hackers to search for vulnerabilities in their systems so that these can then be fixed with the next security updates.
Use antivirus software! Run antivirus scans on your devices regularly to check for malware. But make sure you check beforehand that the scanners are reputable, as they need extensive access to your system in order to scan your devices.
Make backups! Make regular backups of your data. It’s very simple: For laptops: simply plug in a storage device, e.g. a USB stick or an external hard drive with enough storage space for all your data, open the folder and copy your data onto it. Should your device ever be attacked – or perhaps even locked – the blackmailers won’t be able to harm you if you’ve already secured your data.
Important: If you do happen to be affected by an attack on your IT systems, contact the police! You should investigate even the slightest suspicion that you might be involved in criminal activities. The internet is not a lawless space, and ‘cybercrime’ is being punished more and more severely!