The whole category in one page.
WHAT ACTUALLY CAUSES INCIDENTS
Something out of date, a reused credential, or a person being deceived.
Not sophisticated attacks. Attacks are automated and indiscriminate — you are found, not selected.
THE SHORT LIST THAT PREVENTS MOST OF IT
Updates applied automatically Unique passwords with a second step, through a password manager you provide Backups kept separated and actually tested Access removed the day someone leaves Verification by voice for anything involving money
None of it is expensive.
THE TWO DEVICE SETTINGS THAT MATTER MOST
A screen lock with a short timeout, and encryption.
Together they make a lost device an inconvenience rather than a breach.
THE ONE HABIT THAT DEFEATS MOST ATTACKS
Never use links in messages about accounts. Go to the site the way you normally do.
And never give a verification code to anyone, whoever they claim to be.
THE BACKUP RULE THAT DEFEATS RANSOMWARE
At least one copy the compromised machine cannot reach.
THE MOST VALUABLE CONTROL YOU CAN BUILD
A team that reports problems immediately, because nobody is blamed for reporting.
An incident reported in minutes is containable. One hidden for a week is not.
WHAT TO DO FIRST
Establish what devices, accounts and data you actually have.
You cannot protect what you have not identified.