Where and how.
WHAT TO BE CAREFUL WITH
Public networks Shared computers Devices you do not control Links in messages
THE LINK POINT
Do not log in through a link in a message about your account.
Go to the site the way you normally do.
That single habit defeats most phishing.
ON PUBLIC NETWORKS
Ensure connections are encrypted.
Avoid administering critical systems where possible.
WHAT TO CHECK BEFORE ENTERING CREDENTIALS
That the address is correct That the connection is secure
WHAT ATTACKERS USE
Addresses that look almost right Pages that are visually identical
WHAT TO DO AFTER USING A SHARED COMPUTER
Log out Clear the session Change the password, if it was anything important
WHAT TO ENABLE
Login notifications, where available.
An alert about a login you did not make is the earliest warning you get.
WHAT TO DO ABOUT SUCH AN ALERT
Change the password immediately.