Cybersecurity guide

Cybersecurity Guide for Home Users

A practical security plan for people who want to protect their accounts, money, devices, and family data without becoming cybersecurity specialists. Start with the accounts that can unlock everything else, then work outward to devices, the home network, smart products, backups, and recovery.

By Kodi A. Cochran · Substantively reviewed

This guide uses current FBI, NIST, and FTC material. Product interfaces differ, so use the security and recovery controls provided by your actual account, device, router, carrier, and financial institution.

Start with the controls that prevent one mistake from becoming ten

The FBI's Internet Crime Complaint Center received 1,008,597 complaints for 2025 and reported nearly $21 billion in losses. Phishing/spoofing, extortion, and investment schemes were among the most frequently reported complaint categories. The FBI also described scammers using fake social profiles, voice cloning, altered identification documents, and convincing synthetic media to create pressure and impersonate trusted people.FBI 2025 Internet Crime Report release, April 2026

Those complaint figures describe reports submitted to IC3; they are not a probability that a particular household will be victimized. The useful lesson is simpler: modern consumer security is not just antivirus. Attackers frequently try to take over trusted accounts, persuade people to authorize payments, steal recovery codes, impersonate people or organizations, and exploit devices that no longer receive security fixes.

If you only have an hour, do these things first: secure your primary email account, turn on strong multi-factor authentication or a passkey where available, stop reusing passwords, update your phones/computers/router, verify your backups, and make sure you know how to recover the accounts that matter most.

The order matters

Your primary email account is often the recovery path for banking, shopping, social media, cloud storage, and other accounts. Your phone may receive authentication prompts and recovery messages. Your password manager may hold nearly every credential. Treat those as high-value security roots.

  1. Secure the primary email account. Use a unique credential, stronger authentication, current recovery information, and review active sessions/devices.
  2. Secure financial and identity accounts. Banking, payment, tax, government, healthcare, carrier, and major shopping accounts deserve the same treatment.
  3. Secure the device that authenticates you. Update it, use a strong screen lock, enable device encryption where supported, and protect the account used for device recovery.
  4. Fix password reuse. A unique password for every password-based account prevents one breach from automatically unlocking another service.
  5. Secure the router and connected devices. Unsupported infrastructure can undermine otherwise well-secured accounts.
  6. Test recovery. Know how to restore important files and regain access before you are locked out or a device fails.

1. Protect your accounts and recovery paths

Use unique passwords, not password formulas

NIST's current Digital Identity Guidelines moved away from mandatory mixtures of uppercase, lowercase, numbers, and symbols. For systems that use a password as the only authentication factor, NIST SP 800-63B-4 requires verifiers to use a minimum of 15 characters, block commonly used or compromised values, and not impose other composition rules. NIST also says passwords should not be changed periodically unless there is evidence of compromise.NIST SP 800-63B-4

That document governs federal digital identity implementations rather than every consumer website, but it is a useful modern benchmark. As a user, the important habits are: make passwords long, keep them unique, do not create predictable variations such as changing only a number or symbol, and replace a credential when you learn it may have been exposed.

Use a password manager when you have many accounts

A password manager can generate and store unique credentials so you do not have to memorize dozens of them. Protect the manager itself with a strong master credential and the strongest additional authentication it supports. Keep recovery information current and understand what happens if you lose the device or master credential.

Prefer stronger authentication when an account offers it

Two-factor or multi-factor authentication makes a stolen password less useful. NIST distinguishes phishing-resistant cryptographic authentication from passwords and manually entered one-time codes. WebAuthn is one example of a standard that provides phishing resistance through cryptographic binding to the legitimate site's domain.NIST SP 800-63B-4 authenticator requirements

For a consumer, that generally means: use a passkey or security-key-style option when a trusted service offers one and you understand its recovery model; otherwise use an authenticator-based second factor when available. A text-message code is still useful when it is the only second factor offered, but do not share a verification code because someone calls, texts, or emails asking for it.

Protect account recovery with the same care as login

Review recovery email addresses, phone numbers, trusted devices, backup codes, and active sessions on high-value accounts. Remove devices and recovery methods you no longer control. Store recovery codes somewhere that remains accessible if your phone is lost but is not casually exposed in email or an unlocked note.

2. Treat unexpected urgency as a reason to verify

Scams arrive through email, text messages, phone calls, social media, search results, advertisements, QR codes, and compromised accounts belonging to people you know. The medium changes; the pressure pattern is often similar.

Stop before you act

  • Do not use a phone number, login link, payment address, or support contact supplied by an unexpected message when money or account access is at stake.
  • Open the organization's known app or type a known address yourself. For a person, contact them through a separate channel you already trust.
  • Never provide a one-time verification code, password-reset code, backup code, or remote-control access simply because someone claims to be support, your bank, law enforcement, a government agency, or a family member.
  • Be skeptical of instructions to move money to “protect” it, purchase gift cards or cryptocurrency, deposit a check and return part of the money, or bypass a bank's normal fraud controls.
  • Voice and video are no longer sufficient proof of identity by themselves. When a high-stakes request is unusual, verify it independently.

The FTC's consumer guidance recommends contacting the company through a phone number or website you know is real rather than clicking an unexpected message's link.FTC: Protect Your Personal Information From Hackers and Scammers

Do not execute commands copied from a website or message unless you understand them

In June 2026 the FTC warned about fake CAPTCHA pages that instruct visitors to open a system command interface and paste/run hidden commands, resulting in malware installation. A legitimate human-verification challenge should not require you to run operating-system commands.FTC: How to spot a CAPTCHA scam

3. Keep phones and computers supported, updated, and locked

Turn on automatic operating-system, browser, application, and security updates when practical. FTC consumer guidance notes that updates often contain important security fixes and recommends keeping software current.FTC consumer security guidance

Use the security features already in the device

  • Use a non-trivial screen lock and biometric unlock if it helps you consistently keep the device locked.
  • Enable built-in device encryption where it is not already automatic.
  • Use the platform's device-location and remote-lock/wipe capability if you are comfortable with the account and privacy tradeoff.
  • Install applications from sources you intentionally trust and remove applications or browser extensions you no longer use.
  • Review sensitive permissions such as microphone, camera, accessibility, location, contacts, and full-disk/file access.
  • Do not disable built-in security protections just to install an application that demands it unless you understand the consequence.

If a phone, computer, or operating system no longer receives security updates, plan to replace or retire it from sensitive use. An unsupported device can remain functional while accumulating publicly known vulnerabilities.

4. Secure the home router without guessing at its interface

Do not assume every router is managed at the same private IP address or has the same feature names. Use the manufacturer's or internet provider's documented administration method for your exact model.

NIST IR 8425A defines cybersecurity outcomes for consumer-grade router products, while FTC guidance gives consumers a straightforward configuration baseline.NIST IR 8425AFTC: How To Secure Your Home Wi-Fi Network

  • Use WPA3 Personal when supported, or WPA2 Personal when WPA3 is unavailable. Do not rely on WEP or original WPA.
  • Change factory/default router administrator credentials and use a unique Wi-Fi password.
  • Enable automatic firmware/security updates when the product supports them; otherwise follow the vendor's supported update process.
  • Disable internet-facing remote administration unless you have a real need for it and know how it is protected.
  • Disable WPS and UPnP when you do not need them and your environment functions correctly without them.
  • Use a guest network for visitors and, where practical, untrusted or lower-assurance smart devices.
  • Confirm the router still receives security support. Replace it when it reaches end of security support rather than using an arbitrary age rule.

A different DNS resolver can provide privacy or filtering features, but it is not a substitute for keeping the router and endpoints secure. Choose one only after understanding who operates it, what it logs or filters, and what changes when the service is unavailable.

5. Buy and operate smart devices with the support lifecycle in mind

NIST's consumer IoT profile emphasizes capabilities across the whole product, including configuration, data protection, software updates, cybersecurity state awareness, and information about vulnerabilities and the support lifecycle.NIST IR 8425 NIST's April 2026 IoT guidance update also emphasizes post-market support and end-of-life communication.NIST IoT guidance update, April 2026

Before buying

Look for a manufacturer that explains how long security updates are expected, how vulnerabilities are reported, whether the device supports unique credentials or modern authentication, what cloud service is required, and what happens to your data and functionality when support ends.

After setup

  • Replace default credentials when the device uses them and enable stronger authentication if supported.
  • Apply security updates and enable automatic updates when appropriate.
  • Disable remote access, microphones, cameras, cloud integrations, sharing, or purchasing features you do not use.
  • Review which household accounts can administer the device and remove former users.
  • Place less-trusted IoT devices on a guest or isolated network when your router provides a workable isolation feature.
  • Retire or isolate a security-sensitive device when its manufacturer stops security support.

6. Back up what cannot be recreated

Prioritize irreplaceable photos and videos, personal documents, tax and financial records, creative work, password/recovery material that is appropriate to back up, and any data that would cause serious harm if a phone or computer failed today.

A useful backup has independence and history

Keep more than one copy of important data and avoid making every copy depend on the same account, device, or continuously synchronized folder. Synchronization is useful for availability, but deletion, corruption, or ransomware can sometimes propagate to synchronized copies. Version history, a protected backup service, or a disconnected/local copy can provide a recovery point that ordinary sync does not.

Test recovery periodically. Open restored files, not just the backup application. For encrypted backups, make sure you can recover the encryption key or account. For cloud backups, understand how account recovery works if your phone is lost at the same time.

7. If an account is taken over

The FTC recommends using the provider's recovery process, securing the device first when malware may be involved, then changing the password, signing out other sessions, enabling two-factor authentication, and reviewing recovery information after regaining access.FTC: How To Recover Your Hacked Email or Social Media Account

  1. Use a trusted device and the service provider's official recovery path.
  2. If you still have access, change the credential to a new unique one and remove unknown sessions/devices.
  3. Review MFA methods, recovery email/phone details, app passwords, connected applications, delegated access, and email forwarding/filter rules.
  4. Check other accounts where the same password was reused and replace it there immediately.
  5. If the compromised account is email, assume password resets or messages for other services may have been visible and review high-value accounts.
  6. Warn contacts if the attacker used your account to send scams.

8. If you think malware or remote-control software was installed

If a scammer gained remote access or you ran an unknown command, disconnecting the affected device from the network can stop ongoing remote access while you assess it. Use another trusted device for urgent password changes if you believe credentials may have been captured.

FTC guidance for a computer or phone exposed to a scammer includes updating security software, running a scan, removing what it identifies, changing passwords, and turning on two-factor authentication.FTC: What To Do if You Were Scammed

For a serious compromise—especially one involving banking, intimate/private data, employer systems, persistent remote access, or malware that returns after removal—consider professional help. Reinstalling or resetting a device can be appropriate when trustworthy cleanup cannot be established, but preserve important data and recovery information first when it is safe to do so.

9. If money or identity information may be involved

  • Contact the bank, card issuer, payment service, carrier, or other affected institution using a known official channel.
  • Report internet-enabled fraud to the FBI's Internet Crime Complaint Center when appropriate and preserve transaction IDs, messages, account information, dates, and payment details.
  • Use IdentityTheft.gov for a personalized U.S. identity-theft recovery plan when personal information is being misused.
  • If identity theft or exposed identity information creates a risk of new credit being opened, consider a credit freeze. The FTC states that freezes are free to place or lift, do not affect a credit score, and remain until lifted.FTC: Get a credit freeze to stop identity thieves

Acting quickly matters, but speed should not mean trusting the first “recovery agent” who contacts you. The FBI has warned that scammers impersonate IC3 personnel and target people who have already lost money. A promise that someone can recover stolen cryptocurrency or funds for an upfront payment is a reason for independent verification.

10. Make security easier for the whole household

Household security works better when the plan is simple enough that people will actually use it. Avoid turning every suspicious message into a test people can fail. Make it normal to ask another family member before sending money, entering a verification code, installing remote-support software, or responding to an unusual emergency request.

Create a small shared plan

  • Choose a known way to verify urgent requests from family members if a phone or social account is compromised or a voice/video impersonation is used.
  • Know who can help recover the primary household email, phone-carrier, and cloud accounts.
  • Teach children and less-technical family members that asking for help before clicking or paying is a security control, not a failure.
  • Keep important recovery contacts and device purchase/support information somewhere available during an outage or account lockout.
  • Review devices and high-value accounts a few times per year and after a move, device replacement, breakup, death, or other household change that affects access.

A practical 30-day home security reset

Today

  • Secure primary email with a unique credential and stronger authentication.
  • Update the phone and computer you use for banking and account recovery.
  • Review active sessions and recovery methods on primary email and financial accounts.
  • Confirm that irreplaceable data has at least one recoverable backup.

This week

  • Move reused passwords to unique credentials using a password manager if helpful.
  • Enable passkeys or stronger MFA on high-value accounts where supported.
  • Update the router, change default administrator credentials, and verify WPA2/WPA3 configuration.
  • Inventory smart devices and remove ones you no longer use or cannot identify.

This month

  • Test restoring important files from backup.
  • Review smart-device support status, permissions, and remote-access features.
  • Discuss the household verification plan for urgent money/account requests.
  • Write down official recovery paths for the few accounts whose loss would create the most damage.

Latest cybersecurity briefings

Use current advisories as context, not as a substitute for the durable controls above.

Cybersecurity · · 6 min read

GitHub Security Lab Finds 24 Android Vulnerabilities with Open Source AI Taskflows

GitHub Security Lab says targeted open-source AI taskflows helped researchers find and report 24 Android vulnerabilities. The useful lesson for application-security teams is not that an agent replaces expert review, but that repeatable threat-model prompts can scale entry-point analysis, variant hunting, and review coverage.

  • GitHub Security Lab
  • Android security
  • AI security agents
  • Application security
  • Taskflow Agent
Open dedicated page

Cybersecurity · · 6 min read

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: Active Exploitation Response Guide

Citrix disclosed eight NetScaler ADC and Gateway vulnerabilities on September 27, 2026 and says exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated deployments. Internet-facing gateway owners should prioritize fixed builds, exposure review, compromise assessment, and evidence-based recovery.

  • Citrix NetScaler
  • CVE-2026-88771
  • CVE-2026-88772
  • Active exploitation
  • Edge security
Open dedicated page

Cybersecurity · · 6 min read

GitHub Copilot App Local Sandboxing: What the New Security Boundary Does and Does Not Protect

GitHub added per-project local sandboxing to the Copilot app in public preview. The feature can restrict agent-invoked tools from files, networks, and credentials, but it is off by default and does not apply to cloud sandbox sessions or remote hosts.

  • GitHub Copilot
  • Local sandboxing
  • AI agents
  • Developer security
  • Least privilege
Open dedicated page

Cybersecurity · · 6 min read

GitHub SSH Security Changes: RSA SHA-1 Retirement, 3072-bit Keys and Post-Quantum Key Exchange

GitHub has published a staged SSH security transition: new RSA keys uploaded after October 14, 2026 must be at least 3072 bits, SHA-1 RSA signatures and an older Diffie-Hellman exchange are scheduled for removal, and GitHub is adding ML-KEM hybrid post-quantum key exchange support.

  • GitHub
  • SSH
  • RSA SHA-1
  • Post-quantum cryptography
  • ML-KEM
Open dedicated page

Cybersecurity · · 6 min read

SharePoint CVE-2026-65660 Enters the Exploited-Vulnerability Conversation: How to Respond

CVE-2026-65660 is a high-severity SharePoint Server vulnerability associated with active exploitation reporting and CISA KEV tracking. Organizations running on-premises SharePoint should combine patching with compromise assessment and credential review.

  • Microsoft SharePoint
  • CVE-2026-65660
  • CISA KEV
  • Collaboration security
  • Incident response
Open dedicated page

Source feedback

Editorial

Found a factual issue, superseded source, broken citation, or important context we should review? Send the specific claim and supporting source through the correction path so it can be evaluated against the article record.

Continue learning

Related guides after Cybersecurity Guide for Home Users

Follow the next implementation topic without returning to search.

Put this guide to work

Turn Cybersecurity Guide for Home Users into a decision-ready next step.

Use the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.