Login

For user
For provider
Search Easy Read

Cybersecurity in everyday life – Here’s what you can do

IT security (also known as cyber security) affects almost everyone these days. Whether it’s online banking, online shopping or social media – many digital activities involve the processing of data that needs to be protected. Whilst data protection safeguards personal data, IT security ensures that devices, networks and systems are secure against attacks . The two areas therefore complement each other. Even simple measures can significantly reduce the risk of data misuse – you can get started straight away.

Why is IT security important to me?

We leave behind many digital traces in our daily lives, and this information is extremely valuable. If it falls into the wrong hands, it can be used for fraud, identity theft or other criminal offences. Furthermore, personal data is also collected in large quantities to be used for analysis or sold to the advertising industry, where your data and behaviour are analysed in order to send you personalised adverts (product adverts optimised for you or your target group).

That is why it is important to protect your personal data and access to your data – for example, your user accounts on websites and in apps – especially if they contain details such as your name, address, telephone number, email address and bank details. By doing so, you not only protect your privacy but also minimise the risk of your data being misused or even of you suffering financial loss. There is always a residual risk, as criminals use various ‘clever’ tricks to gain access to protected areas – such as those secured by passwords – but you should under no circumstances make it unnecessarily easy for them.

What are the typical threats?

Phishing:

One of the most common scams used to steal your personal details is known as ‘phishing’. In this scam, criminals send emails or text messages that purport to come from, for example, a bank, an online shop or a parcel delivery service. The aim is to lure you onto fake websites so that you enter your personal details or login credentials there. It isn’t always easy to spot these fakes. Pay particular attention to the sender and the tone of the message:

- Does the message come from a suspicious-looking email address?

- The sender’s name might sound familiar, but is it spelled correctly?

- Are you being asked to click on a link or provide details?

- Are you being pressured because it’s supposedly something very important (e.g. that your account will be blocked if you don’t act immediately)?

You can read about further criteria to help you spot phishing in our article on ‘How to spot phishing’!

Social engineering:

Social engineering, which essentially means social manipulation, involves exploiting people as a weak link in fraud schemes. Criminals may, for example, pose as police officers, bank staff orrelatives. Their aim is to obtain confidential information (e.g. login details/passwords) or money (both in cash and via bank transfer). To do this, they concoct convincing stories and emergencies, and in some cases even use AI-generated voices. This scam is also known as the ‘grandchild scam’ or ‘shock call’. However, emails from supposed work colleagues or bosses asking you to make a payment or download a programme (which is actually malware) are also very typical examples of this. You can spot this scam, for example, by the artificially created sense of urgency or unusual curiosity about secrets and personal details.

Malware:

These include, for example, viruses or Trojans. These are small computer programmes that install themselves on your device and then interfere with it or spy on you. They can, for example, read your personal contacts or passwords, activate your camera or access your photos and videos. It is particularly serious when so-called ransomware is used – ‘blackmail software’ that, for example, locks or encrypts your device and renders it inoperable until you pay a ransom. Such malware is usually hidden in email attachments and disguised as documents, such as invoices or photos. If you click on these, the programme installs itself in the background without you realising.

Data breaches:

Sometimes, even the best protection of your personal data is of no use if the systems into which it is entered have vulnerabilities of their own, allowing data to be accessed in this way. This can happen when criminals hack into devices and programmes, when operators of digital services make mistakes and inadvertently publish customers’ data, or when data transmission – such as the entry of a password – is not sufficiently encrypted and protected. This lack of protection is not easily detectable from the outside, but there are indications of it, for example, if the web address begins with ‘http’ instead of ‘https’ – because the ‘s’ marks the difference between an outdated and a more recent encryption standard for websites.

What can I do?

 

Think first, then click! Don’t click on links in emails if you don’t know the sender. If you’re unsure whether the message is genuine, contact the person or company by another means (e.g. by phone) and ask whether the email really is from them.

Be wary of file attachments! Don’t open any file attachments unless you’re absolutely sure they’re safe. Although malware can disguise itself in all sorts of file formats (pdf, docx, jpeg, etc.), if the file ends in ‘exe’, you can be sure it’s a piece of software.

Be particularly wary of certain file attachments! Microsoft Office documents in particular (Word: docx, Excel: xlsx, PowerPoint: pptx) often conceal malware, as they allow you to use so-called ‘macros’ to programme small, recurring tasks (e.g. a specific table formatting). However, macros can also contain ‘malicious’ code, so you should disable them by default in your Office programme (in the Office programme: Options > Trust Centre > Macro Settings).

Choose good passwords! Use strong passwords with at least 16 characters and a combination of letters, numbers and special characters. A password manager (e.g. KeePassXC or Bitwarden) can help you manage lots of secure passwords, so you don’t have to remember them all individually.

Use two-factor authentication! Alwaysenable ‘two-factor authentication’ for accounts where you’ve stored particularly sensitive data and account details. This means that to log in, you’ll need not only a password but also an additional means of identification as a second authentication factor – this could be your mobile number or email address, for example. Anyone who only knows your password won’t be able to access the system at this stage.

Keep everything up to date! Regularly install security updates on your devices and in your apps to close any vulnerabilities in the software – this is really important. Large companies even pay their own hackers to search for vulnerabilities in their systems so that these can then be fixed with the next security updates.

Use antivirus software! Run antivirus scans on your devices regularly to check for malware. But make sure you check beforehand that the scanners are reputable, as they need extensive access to your system in order to scan your devices.

Make backups! Make regular backups of your data. It’s very simple: For laptops: simply plug in a storage device, e.g. a USB stick or an external hard drive with enough storage space for all your data, open the folder and copy your data onto it. Should your device ever be attacked – or perhaps even locked – the blackmailers won’t be able to harm you if you’ve already secured your data.

 

Important: If you do happen to be affected by an attack on your IT systems, contact the police! You should investigate even the slightest suspicion that you might be involved in criminal activities. The internet is not a lawless space, and ‘cybercrime’ is being punished more and more severely!

Take our online self-assessment to improve your cybersecurity skills!
Date: 27.07.2026
Authors: Jessica Wawrzyniak