You don’t need to be a hacker to protect yourself online

I think one of the biggest misconceptions about online security is that you need to understand cybersecurity to stay safe. You really don't. Most scams I see aren't technically sophisticated at all.

They just try to catch you at the wrong moment: a parcel apparently waiting for you, Microsoft asking you to log in again, your bank warning you about a payment, or somebody sending an invoice that looks just believable enough.

Personally, I have one very simple rule. If an unexpected email or text asks me to log in somewhere, I don’t use the link. I open the actual website myself. Same with payments, password resets or anything involving personal information. It sounds almost stupidly simple, but that’s the point. A lot of security is just removing the opportunity to make a mistake.

Passwords are another one. We’re in 2026 and people still reuse the same password everywhere because remembering twenty different passwords is obviously ridiculous. That’s exactly why password managers exist. Use different passwords, enable MFA where you can, and stop treating your email account like just another login. If someone gets into your main email, they potentially have the reset button for half of your digital life.

Privacy is slightly different, because we’re constantly giving information away without really thinking about it. LinkedIn tells people where we work. Instagram can show where we are. Company websites show names and roles. Sometimes even an innocent out-of-office reply gives somebody useful information. None of this means we should disappear from the internet, but it’s worth remembering that scammers can use perfectly public information to make a completely fake message feel very real.

I don’t believe the answer is becoming paranoid about every email or link you receive. That’s exhausting. I think it’s more about developing a few habits and making them automatic. Don’t react immediately because a message says “urgent”. Check where it came from. Open the service yourself if you’re unsure. And if something feels slightly off, there is absolutely nothing wrong with stopping for thirty seconds before clicking anything. Most scams need you to act quickly. Don’t give them that advantage.

Alessio

Consulente tecnologico, sviluppatore software e problem solver. Condivido esperienze e riflessioni pratiche su tecnologia, operations e prodotti digitali.