Personal Cybersecurity Guide
Disclaimer: This skill provides general wellness and health information for educational purposes only. It does NOT constitute medical advice, diagnosis, or treatment recommendations. The information provided is not a substitute for professional medical judgment. Always consult a qualified healthcare professional before making decisions about your health, starting a new fitness program, or changing your diet. If you are experiencing a medical emergency, contact emergency services immediately.
When to Use
Use this skill when:
- User asks about cybersecurity personal techniques or best practices
- User needs guidance on cybersecurity personal concepts
- User wants to implement or improve their approach to cybersecurity personal
Do NOT use when:
- The request falls outside the scope of cybersecurity personal
- User needs a different specialized skill for their specific situation
- The topic requires professional consultation beyond general guidance
Questions to Ask First
- How many online accounts do you estimate you have (email, banking, social media, shopping)?
- Do you currently use a password manager?
- Do you have two-factor authentication enabled on your most important accounts?
- Have you ever been a victim of a hack, phishing attack, or data breach?
- What devices do you use daily (phone, laptop, tablet, smart home devices)?
- Do you use public Wi-Fi frequently (coffee shops, airports, hotels)?
- What is your comfort level with technology?
- Do you handle sensitive information for work from personal devices?
- How many people have access to your devices or accounts?
- What is your biggest cybersecurity concern (identity theft, privacy, financial fraud)?
Phase 1: Password Management
Why Passwords Matter
Over 80% of data breaches involve compromised passwords. Reusing passwords across sites means one breach can compromise all your accounts.
Password Best Practices
Strong password characteristics:
- Minimum 16 characters (longer is better)
- Mix of uppercase, lowercase, numbers, and special characters
- NOT based on personal information (birthdate, pet name, address)
- NOT a common word or phrase
- Unique for every account (no reuse)
Passphrase method (recommended):
Create a memorable phrase with random words:
Example: "correct-horse-battery-staple" (but use your own random words)
Add complexity: "Correct-Horse-Battery-Staple-42!"
Password Managers
Why use a password manager:
- Generates strong, unique passwords for every account
- Remembers them all so you do not have to
- Auto-fills login forms securely
- Alerts you to compromised passwords
- Works across all your devices
Recommended Password Managers:
| Manager |
Cost |
Platforms |
Key Features |
| Bitwarden |
Free / $10/year premium |
All platforms |
Open source, excellent free tier |
| 1Password |
$36/year |
All platforms |
Travel mode, family sharing |
| Dashlane |
$60/year |
All platforms |
VPN included, dark web monitoring |
| KeePassXC |
Free |
Desktop (cross-platform) |
Offline, open source, full control |
Setting up a password manager:
- Choose a manager and create your account
- Create a STRONG master password (this is the one password you must remember)
- Write your master password on paper and store it in a secure physical location
- Install the browser extension and mobile app
- Start saving passwords as you log into sites
- Gradually update weak or reused passwords with generated ones
- Enable two-factor authentication on the password manager itself
Passwords to Change First (Priority Order)
- Email accounts (email is the key to all other account recovery)
- Financial accounts (banking, investment, payment apps)
- Password manager master password
- Social media accounts
- Cloud storage (Google Drive, iCloud, Dropbox)
- Shopping accounts with saved payment information
- Work accounts
- All remaining accounts
Phase 2: Two-Factor Authentication (2FA)
What is 2FA?
Two-factor authentication requires two different types of verification to access an account: something you know (password) plus something you have (phone, security key) or something you are (biometrics).
Types of 2FA (Ranked by Security)
| Method |
Security Level |
Convenience |
Notes |
| Hardware security key (YubiKey, Titan) |
Highest |
Medium |
Physical device, phishing-resistant |
| Authenticator app (TOTP) |
High |
High |
Time-based codes on your phone |
| Push notification |
High |
Very High |
Approve/deny on phone app |
| SMS text message |
Medium |
Very High |
Better than nothing, but vulnerable to SIM swap |
| Email code |
Low-Medium |
High |
If email is compromised, 2FA is bypassed |
Setting Up 2FA
Priority accounts for 2FA:
- Email (Gmail, Outlook, etc.)
- Financial accounts (banks, investment platforms)
- Password manager
- Social media
- Cloud storage
- Work accounts
- Shopping accounts with stored payment info
Recommended authenticator apps:
- Authy (cloud backup, multi-device sync)
- Google Authenticator
- Microsoft Authenticator
- 1Password (built into the password manager)
Setup process (typical):
- Go to account security settings
- Find "Two-Factor Authentication" or "Two-Step Verification"
- Choose your 2FA method
- Follow the setup wizard (usually scan a QR code with your authenticator app)
- Save backup codes in your password manager or a secure location
- Test the setup by logging out and back in
Backup Codes
When you enable 2FA, most services provide backup codes. These are one-time-use codes for when you cannot access your 2FA device. Store these securely in your password manager and/or a physical secure location. Without them, you may lose access to your account if your phone is lost or broken.
Phase 3: VPN Selection and Usage
What a VPN Does (and Does Not Do)
A VPN does:
- Encrypt your internet traffic between your device and the VPN server
- Hide your IP address from websites you visit
- Protect data on public Wi-Fi from local eavesdropping
- Allow access to geo-restricted content
- Prevent your ISP from seeing which specific sites you visit
A VPN does NOT:
- Make you anonymous (the VPN provider can see your traffic)
- Protect against malware or phishing
- Protect accounts with weak passwords
- Make you invisible to law enforcement (with proper legal process)
- Protect data after it leaves the VPN server
Choosing a VPN Provider
Look for:
- No-logs policy (independently audited)
- Strong encryption (WireGuard or OpenVPN protocols)
- Kill switch feature (blocks internet if VPN disconnects)
- Jurisdiction outside surveillance alliances (preferably)
- Transparent ownership and business model
- Regular independent security audits
Recommended VPN providers:
| VPN |
Cost |
Key Features |
Audit Status |
| Mullvad |
$5.50/month |
No email needed, anonymous payment |
Audited |
| ProtonVPN |
Free tier / $5-10/month |
Swiss jurisdiction, open source |
Audited |
| IVPN |
$6-10/month |
No email needed, transparent |
Audited |
| Surfshark |
$2-4/month |
Unlimited devices, good value |
Audited |
| NordVPN |
$3-5/month |
Large server network |
Audited |
Avoid: Free VPNs from unknown providers (your data is often the product).
When to Use a VPN
- Always on public Wi-Fi (coffee shops, airports, hotels)
- When accessing sensitive accounts on unfamiliar networks
- When you want to prevent ISP tracking
- When traveling internationally (access home services)
Phase 4: Phishing Recognition
What is Phishing?
Phishing is an attempt to trick you into revealing sensitive information (passwords, credit card numbers, personal data) by impersonating a legitimate entity through email, text, phone, or websites.
Common Phishing Indicators
Email phishing red flags:
Text/SMS phishing (smishing):
- Unexpected texts from unknown numbers
- Links to shortened URLs
- Urgent requests to verify accounts
- "You've won" messages
- Package delivery notifications you were not expecting
Phone phishing (vishing):
- Callers claiming to be from the IRS, Social Security, or police
- Threats of arrest or legal action
- Requests for payment via gift cards or wire transfer
- Caller ID spoofing (shows a legitimate number but is not)
- Pressure to act immediately without time to verify
What to Do If You Suspect Phishing
- Do NOT click links or open attachments
- Do NOT reply to the message
- Verify independently (call the organization using a number from their official website, not the one in the message)
- Report phishing emails (forward to the organization and to reportphishing@apwg.org)
- Delete the message
- If you already clicked or entered information, change passwords immediately and enable 2FA
Phase 5: Social Engineering Awareness
Common Social Engineering Tactics
| Tactic |
Method |
Example |
| Pretexting |
Creating a false scenario |
"I'm from IT, I need your password to fix an issue" |
| Baiting |
Offering something enticing |
USB drive left in a parking lot with malware |
| Tailgating |
Following someone into a secure area |
Walking into a building behind an employee |
| Quid pro quo |
Offering a service for information |
"Free tech support" that installs malware |
| Authority |
Impersonating someone in power |
"The CEO needs this wire transfer done immediately" |
| Scarcity/Urgency |
Creating time pressure |
"Only 2 left!" or "Act now or lose access" |
Defense Against Social Engineering
- Verify identity independently before sharing any information
- Be suspicious of unsolicited contacts (even if they know some personal information about you -- this is often available publicly)
- Slow down and think before acting on urgent requests
- Never share passwords, even with "IT support"
- Question unusual requests, even from seemingly legitimate sources
- Establish verification procedures for sensitive requests (callback numbers, code words)
Phase 6: Device Security
Smartphone Security
Computer Security
Smart Home Device Security
- Change default passwords on all IoT devices (cameras, speakers, routers)
- Keep firmware updated
- Use a separate Wi-Fi network for IoT devices (if your router supports it)
- Disable features you do not use (remote access, voice purchasing)
- Research device privacy policies before purchasing
Router Security
- Change default admin password
- Use WPA3 encryption (or WPA2 minimum)
- Change default network name (SSID) -- do not include personal information
- Enable automatic firmware updates
- Disable WPS (Wi-Fi Protected Setup)
- Consider a guest network for visitors
Phase 7: Privacy Settings
Social Media Privacy
Facebook:
- Set profile to "Friends Only" (not Public)
- Review who can see past posts (Limit Past Posts feature)
- Disable face recognition
- Review apps and websites connected to your account
- Disable location history
- Review tagged photos before they appear on your profile
Instagram:
- Set account to Private (if not a public figure or business)
- Disable activity status
- Review tagged photos before they appear
- Restrict who can message you
General Social Media:
- Do not share your full birthdate, address, or phone number
- Be cautious about check-ins and real-time location sharing
- Do not post vacation photos until after returning home
- Review friend/follower lists periodically
- Be cautious about quizzes and personality tests (data harvesting)
Browser Privacy
- Use a privacy-focused browser (Firefox, Brave) or harden your current browser
- Install uBlock Origin (ad and tracker blocker)
- Enable Do Not Track (limited effectiveness but worth enabling)
- Clear cookies regularly or use containers (Firefox Multi-Account Containers)
- Use private/incognito mode for sensitive searches
- Consider a privacy-focused search engine (DuckDuckGo, Startpage)
- Disable third-party cookies
- Review and limit browser extensions (each extension can see your browsing)
Phase 8: Data Breach Response
If Your Data Has Been Breached
Immediate actions (first 24 hours):
- Change passwords for the breached account immediately
- If the password was reused anywhere, change those passwords too
- Enable 2FA on the breached account (if not already active)
- Check for unauthorized transactions on financial accounts
- Monitor email for password reset requests you did not initiate
Within the first week:
- Place a fraud alert with one of the three credit bureaus (Equifax, Experian, TransUnion -- they are required to notify the other two)
- Review credit reports at AnnualCreditReport.com
- Consider a credit freeze (prevents new accounts being opened in your name)
- Check HaveIBeenPwned.com for other breaches involving your email
- Update security questions (if the breach included personal information)
- Monitor accounts closely for 6-12 months
Credit Freeze vs. Fraud Alert:
| Feature |
Credit Freeze |
Fraud Alert |
| Duration |
Until you lift it |
1 year (initial) or 7 years (extended) |
| Effect |
Blocks all new credit inquiries |
Requires additional verification |
| Cost |
Free |
Free |
| Effort to set up |
Must contact each bureau separately |
Contact one bureau, others are notified |
| To lift |
PIN or password required at each bureau |
Expires automatically |
Secure Communication Tools
| Tool |
Type |
Key Feature |
| Signal |
Messaging |
End-to-end encrypted, open source, minimal metadata |
| ProtonMail |
Email |
End-to-end encrypted, Swiss jurisdiction |
| Tuta (formerly Tutanota) |
Email |
End-to-end encrypted, German jurisdiction |
| Wire |
Messaging |
End-to-end encrypted, business and personal |
| iMessage |
Messaging |
End-to-end encrypted (Apple to Apple only) |
Personal Cybersecurity Checklist
Do This Today
Do This Week
Do This Month
Cybersecurity is not about being perfectly secure -- that is impossible. It is about making yourself a harder target than the next person. Implement these measures in order of priority, and each step significantly reduces your risk.
Process
- Gather information. Ask the user clarifying questions to understand their specific situation, goals, and constraints
- Analyze context. Review the information provided and identify key factors relevant to cybersecurity personal
- Develop recommendations. Apply domain expertise to create actionable guidance tailored to the user's needs
- Present structured output. Deliver findings in the output format below with clear next steps
- Address follow-ups. Answer additional questions and refine recommendations based on feedback
Output Format
## Cybersecurity Personal Analysis
### Assessment
[Key findings and observations]
### Recommendations
1. [Primary recommendation]
2. [Secondary recommendation]
3. [Additional suggestions]
### Action Items
- [ ] [First action step]
- [ ] [Second action step]
- [ ] [Follow-up task]
Edge Cases
- Incomplete information: Ask clarifying questions before proceeding with recommendations
- Conflicting requirements: Prioritize the most critical constraint and note trade-offs
- Out of scope requests: Redirect to appropriate specialized skill or professional resource
- Beginner vs advanced: Adjust depth and terminology based on user's experience level
Example
Input: "Help me with cybersecurity personal for my current situation"
Output:
Based on your situation, here is a structured approach to cybersecurity personal:
- Assessment: Evaluate your current state and identify key areas for improvement
- Strategy: Develop a targeted plan based on best practices
- Implementation: Execute the plan with specific, measurable steps
- Review: Monitor progress and adjust as needed
1---2name: cybersecurity-personal3description: Comprehensive guide to personal digital security covering password management strategies, two-factor authentication setup, VPN selection and usage, phishing recognition techniques, social engineering awareness, device security hardening, privacy settings for social media and browsers, data breach response procedures, and secure communication tools. Use when the user asks about cybersecurity personal, related techniques, best practices, or needs guidance in this domain. Do NOT use when the request is outside the scope of cybersecurity personal or requires a different specialized skill.4license: Apache-2.05---67# Personal Cybersecurity Guide89> **Disclaimer:** This skill provides general wellness and health information for educational purposes only. It does NOT constitute medical advice, diagnosis, or treatment recommendations. The information provided is not a substitute for professional medical judgment. Always consult a qualified healthcare professional before making decisions about your health, starting a new fitness program, or changing your diet. If you are experiencing a medical emergency, contact emergency services immediately.101112## When to Use1314**Use this skill when:**15- User asks about cybersecurity personal techniques or best practices16- User needs guidance on cybersecurity personal concepts17- User wants to implement or improve their approach to cybersecurity personal1819**Do NOT use when:**20- The request falls outside the scope of cybersecurity personal21- User needs a different specialized skill for their specific situation22- The topic requires professional consultation beyond general guidance2324## Questions to Ask First25261. How many online accounts do you estimate you have (email, banking, social media, shopping)?272. Do you currently use a password manager?283. Do you have two-factor authentication enabled on your most important accounts?294. Have you ever been a victim of a hack, phishing attack, or data breach?305. What devices do you use daily (phone, laptop, tablet, smart home devices)?316. Do you use public Wi-Fi frequently (coffee shops, airports, hotels)?327. What is your comfort level with technology?338. Do you handle sensitive information for work from personal devices?349. How many people have access to your devices or accounts?3510. What is your biggest cybersecurity concern (identity theft, privacy, financial fraud)?3637---3839## Phase 1: Password Management4041### Why Passwords Matter42Over 80% of data breaches involve compromised passwords. Reusing passwords across sites means one breach can compromise all your accounts.4344### Password Best Practices4546**Strong password characteristics:**47- Minimum 16 characters (longer is better)48- Mix of uppercase, lowercase, numbers, and special characters49- NOT based on personal information (birthdate, pet name, address)50- NOT a common word or phrase51- Unique for every account (no reuse)5253**Passphrase method (recommended):**54Create a memorable phrase with random words:55Example: "correct-horse-battery-staple" (but use your own random words)56Add complexity: "Correct-Horse-Battery-Staple-42!"5758### Password Managers5960**Why use a password manager:**61- Generates strong, unique passwords for every account62- Remembers them all so you do not have to63- Auto-fills login forms securely64- Alerts you to compromised passwords65- Works across all your devices6667**Recommended Password Managers:**6869| Manager | Cost | Platforms | Key Features |70|---------|------|----------|-------------|71| Bitwarden | Free / $10/year premium | All platforms | Open source, excellent free tier |72| 1Password | $36/year | All platforms | Travel mode, family sharing |73| Dashlane | $60/year | All platforms | VPN included, dark web monitoring |74| KeePassXC | Free | Desktop (cross-platform) | Offline, open source, full control |7576**Setting up a password manager:**771. Choose a manager and create your account782. Create a STRONG master password (this is the one password you must remember)793. Write your master password on paper and store it in a secure physical location804. Install the browser extension and mobile app815. Start saving passwords as you log into sites826. Gradually update weak or reused passwords with generated ones837. Enable two-factor authentication on the password manager itself8485### Passwords to Change First (Priority Order)861. Email accounts (email is the key to all other account recovery)872. Financial accounts (banking, investment, payment apps)883. Password manager master password894. Social media accounts905. Cloud storage (Google Drive, iCloud, Dropbox)916. Shopping accounts with saved payment information927. Work accounts938. All remaining accounts9495---9697## Phase 2: Two-Factor Authentication (2FA)9899### What is 2FA?100Two-factor authentication requires two different types of verification to access an account: something you know (password) plus something you have (phone, security key) or something you are (biometrics).101102### Types of 2FA (Ranked by Security)103104| Method | Security Level | Convenience | Notes |105|--------|---------------|-------------|-------|106| Hardware security key (YubiKey, Titan) | Highest | Medium | Physical device, phishing-resistant |107| Authenticator app (TOTP) | High | High | Time-based codes on your phone |108| Push notification | High | Very High | Approve/deny on phone app |109| SMS text message | Medium | Very High | Better than nothing, but vulnerable to SIM swap |110| Email code | Low-Medium | High | If email is compromised, 2FA is bypassed |111112### Setting Up 2FA113114**Priority accounts for 2FA:**1151. Email (Gmail, Outlook, etc.)1162. Financial accounts (banks, investment platforms)1173. Password manager1184. Social media1195. Cloud storage1206. Work accounts1217. Shopping accounts with stored payment info122123**Recommended authenticator apps:**124- Authy (cloud backup, multi-device sync)125- Google Authenticator126- Microsoft Authenticator127- 1Password (built into the password manager)128129**Setup process (typical):**1301. Go to account security settings1312. Find "Two-Factor Authentication" or "Two-Step Verification"1323. Choose your 2FA method1334. Follow the setup wizard (usually scan a QR code with your authenticator app)1345. Save backup codes in your password manager or a secure location1356. Test the setup by logging out and back in136137### Backup Codes138When you enable 2FA, most services provide backup codes. These are one-time-use codes for when you cannot access your 2FA device. Store these securely in your password manager and/or a physical secure location. Without them, you may lose access to your account if your phone is lost or broken.139140---141142## Phase 3: VPN Selection and Usage143144### What a VPN Does (and Does Not Do)145146**A VPN does:**147- Encrypt your internet traffic between your device and the VPN server148- Hide your IP address from websites you visit149- Protect data on public Wi-Fi from local eavesdropping150- Allow access to geo-restricted content151- Prevent your ISP from seeing which specific sites you visit152153**A VPN does NOT:**154- Make you anonymous (the VPN provider can see your traffic)155- Protect against malware or phishing156- Protect accounts with weak passwords157- Make you invisible to law enforcement (with proper legal process)158- Protect data after it leaves the VPN server159160### Choosing a VPN Provider161162**Look for:**163- No-logs policy (independently audited)164- Strong encryption (WireGuard or OpenVPN protocols)165- Kill switch feature (blocks internet if VPN disconnects)166- Jurisdiction outside surveillance alliances (preferably)167- Transparent ownership and business model168- Regular independent security audits169170**Recommended VPN providers:**171172| VPN | Cost | Key Features | Audit Status |173|-----|------|-------------|-------------|174| Mullvad | $5.50/month | No email needed, anonymous payment | Audited |175| ProtonVPN | Free tier / $5-10/month | Swiss jurisdiction, open source | Audited |176| IVPN | $6-10/month | No email needed, transparent | Audited |177| Surfshark | $2-4/month | Unlimited devices, good value | Audited |178| NordVPN | $3-5/month | Large server network | Audited |179180**Avoid:** Free VPNs from unknown providers (your data is often the product).181182### When to Use a VPN183- Always on public Wi-Fi (coffee shops, airports, hotels)184- When accessing sensitive accounts on unfamiliar networks185- When you want to prevent ISP tracking186- When traveling internationally (access home services)187188---189190## Phase 4: Phishing Recognition191192### What is Phishing?193Phishing is an attempt to trick you into revealing sensitive information (passwords, credit card numbers, personal data) by impersonating a legitimate entity through email, text, phone, or websites.194195### Common Phishing Indicators196197**Email phishing red flags:**198- [ ] Sender address does not match the claimed organization (hover over the "from" name)199- [ ] Generic greeting ("Dear Customer" instead of your name)200- [ ] Urgency or threat ("Your account will be closed in 24 hours!")201- [ ] Spelling and grammar errors202- [ ] Suspicious links (hover to see the actual URL before clicking)203- [ ] Unexpected attachments204- [ ] Requests for sensitive information (passwords, SSN, credit card)205- [ ] Too-good-to-be-true offers206- [ ] Slightly misspelled domains (amaz0n.com, paypa1.com, micros0ft.com)207208**Text/SMS phishing (smishing):**209- Unexpected texts from unknown numbers210- Links to shortened URLs211- Urgent requests to verify accounts212- "You've won" messages213- Package delivery notifications you were not expecting214215**Phone phishing (vishing):**216- Callers claiming to be from the IRS, Social Security, or police217- Threats of arrest or legal action218- Requests for payment via gift cards or wire transfer219- Caller ID spoofing (shows a legitimate number but is not)220- Pressure to act immediately without time to verify221222### What to Do If You Suspect Phishing2231. Do NOT click links or open attachments2242. Do NOT reply to the message2253. Verify independently (call the organization using a number from their official website, not the one in the message)2264. Report phishing emails (forward to the organization and to reportphishing@apwg.org)2275. Delete the message2286. If you already clicked or entered information, change passwords immediately and enable 2FA229230---231232## Phase 5: Social Engineering Awareness233234### Common Social Engineering Tactics235236| Tactic | Method | Example |237|--------|--------|---------|238| Pretexting | Creating a false scenario | "I'm from IT, I need your password to fix an issue" |239| Baiting | Offering something enticing | USB drive left in a parking lot with malware |240| Tailgating | Following someone into a secure area | Walking into a building behind an employee |241| Quid pro quo | Offering a service for information | "Free tech support" that installs malware |242| Authority | Impersonating someone in power | "The CEO needs this wire transfer done immediately" |243| Scarcity/Urgency | Creating time pressure | "Only 2 left!" or "Act now or lose access" |244245### Defense Against Social Engineering246- Verify identity independently before sharing any information247- Be suspicious of unsolicited contacts (even if they know some personal information about you -- this is often available publicly)248- Slow down and think before acting on urgent requests249- Never share passwords, even with "IT support"250- Question unusual requests, even from seemingly legitimate sources251- Establish verification procedures for sensitive requests (callback numbers, code words)252253---254255## Phase 6: Device Security256257### Smartphone Security258259- [ ] Enable screen lock (PIN minimum 6 digits, biometric preferred)260- [ ] Enable automatic updates (operating system and apps)261- [ ] Only install apps from official app stores262- [ ] Review app permissions regularly (revoke unnecessary access to camera, microphone, location, contacts)263- [ ] Enable Find My Device (for remote tracking and wiping)264- [ ] Enable automatic backup (encrypted)265- [ ] Disable Bluetooth and Wi-Fi auto-connect when not needed266- [ ] Use a VPN on public Wi-Fi267268### Computer Security269270- [ ] Enable full-disk encryption (BitLocker on Windows, FileVault on Mac)271- [ ] Set a strong login password272- [ ] Enable automatic operating system updates273- [ ] Install and maintain antivirus/antimalware software274- [ ] Enable firewall275- [ ] Back up data regularly (3-2-1 rule: 3 copies, 2 media types, 1 offsite)276- [ ] Lock screen when stepping away (Windows+L or Ctrl+Cmd+Q on Mac)277- [ ] Be cautious with USB drives from unknown sources278279### Smart Home Device Security280- Change default passwords on all IoT devices (cameras, speakers, routers)281- Keep firmware updated282- Use a separate Wi-Fi network for IoT devices (if your router supports it)283- Disable features you do not use (remote access, voice purchasing)284- Research device privacy policies before purchasing285286### Router Security287- Change default admin password288- Use WPA3 encryption (or WPA2 minimum)289- Change default network name (SSID) -- do not include personal information290- Enable automatic firmware updates291- Disable WPS (Wi-Fi Protected Setup)292- Consider a guest network for visitors293294---295296## Phase 7: Privacy Settings297298### Social Media Privacy299300**Facebook:**301- Set profile to "Friends Only" (not Public)302- Review who can see past posts (Limit Past Posts feature)303- Disable face recognition304- Review apps and websites connected to your account305- Disable location history306- Review tagged photos before they appear on your profile307308**Instagram:**309- Set account to Private (if not a public figure or business)310- Disable activity status311- Review tagged photos before they appear312- Restrict who can message you313314**General Social Media:**315- Do not share your full birthdate, address, or phone number316- Be cautious about check-ins and real-time location sharing317- Do not post vacation photos until after returning home318- Review friend/follower lists periodically319- Be cautious about quizzes and personality tests (data harvesting)320321### Browser Privacy322323- Use a privacy-focused browser (Firefox, Brave) or harden your current browser324- Install uBlock Origin (ad and tracker blocker)325- Enable Do Not Track (limited effectiveness but worth enabling)326- Clear cookies regularly or use containers (Firefox Multi-Account Containers)327- Use private/incognito mode for sensitive searches328- Consider a privacy-focused search engine (DuckDuckGo, Startpage)329- Disable third-party cookies330- Review and limit browser extensions (each extension can see your browsing)331332---333334## Phase 8: Data Breach Response335336### If Your Data Has Been Breached337338**Immediate actions (first 24 hours):**3391. Change passwords for the breached account immediately3402. If the password was reused anywhere, change those passwords too3413. Enable 2FA on the breached account (if not already active)3424. Check for unauthorized transactions on financial accounts3435. Monitor email for password reset requests you did not initiate344345**Within the first week:**346- Place a fraud alert with one of the three credit bureaus (Equifax, Experian, TransUnion -- they are required to notify the other two)347- Review credit reports at AnnualCreditReport.com348- Consider a credit freeze (prevents new accounts being opened in your name)349- Check HaveIBeenPwned.com for other breaches involving your email350- Update security questions (if the breach included personal information)351- Monitor accounts closely for 6-12 months352353**Credit Freeze vs. Fraud Alert:**354355| Feature | Credit Freeze | Fraud Alert |356|---------|--------------|-------------|357| Duration | Until you lift it | 1 year (initial) or 7 years (extended) |358| Effect | Blocks all new credit inquiries | Requires additional verification |359| Cost | Free | Free |360| Effort to set up | Must contact each bureau separately | Contact one bureau, others are notified |361| To lift | PIN or password required at each bureau | Expires automatically |362363### Secure Communication Tools364365| Tool | Type | Key Feature |366|------|------|------------|367| Signal | Messaging | End-to-end encrypted, open source, minimal metadata |368| ProtonMail | Email | End-to-end encrypted, Swiss jurisdiction |369| Tuta (formerly Tutanota) | Email | End-to-end encrypted, German jurisdiction |370| Wire | Messaging | End-to-end encrypted, business and personal |371| iMessage | Messaging | End-to-end encrypted (Apple to Apple only) |372373---374375## Personal Cybersecurity Checklist376377### Do This Today378- [ ] Check HaveIBeenPwned.com for your email addresses379- [ ] Install a password manager and start saving passwords380- [ ] Enable 2FA on your email accounts381- [ ] Update your phone's operating system to the latest version382383### Do This Week384- [ ] Change your most critical passwords (email, banking, social media)385- [ ] Enable 2FA on financial accounts386- [ ] Review privacy settings on social media387- [ ] Install uBlock Origin on your browser388- [ ] Set up automatic backups for your phone and computer389390### Do This Month391- [ ] Audit and update all account passwords (using password manager)392- [ ] Enable 2FA on all accounts that support it393- [ ] Review app permissions on your phone394- [ ] Set up a VPN for use on public Wi-Fi395- [ ] Check credit reports at AnnualCreditReport.com396- [ ] Review and limit browser extensions397- [ ] Change your router's default admin password398399Cybersecurity is not about being perfectly secure -- that is impossible. It is about making yourself a harder target than the next person. Implement these measures in order of priority, and each step significantly reduces your risk.400401402## Process4034041. **Gather information.** Ask the user clarifying questions to understand their specific situation, goals, and constraints4052. **Analyze context.** Review the information provided and identify key factors relevant to cybersecurity personal4063. **Develop recommendations.** Apply domain expertise to create actionable guidance tailored to the user's needs4074. **Present structured output.** Deliver findings in the output format below with clear next steps4085. **Address follow-ups.** Answer additional questions and refine recommendations based on feedback409410411## Output Format412413```template414## Cybersecurity Personal Analysis415416### Assessment417[Key findings and observations]418419### Recommendations4201. [Primary recommendation]4212. [Secondary recommendation]4223. [Additional suggestions]423424### Action Items425- [ ] [First action step]426- [ ] [Second action step]427- [ ] [Follow-up task]428```429430431## Edge Cases432433- **Incomplete information:** Ask clarifying questions before proceeding with recommendations434- **Conflicting requirements:** Prioritize the most critical constraint and note trade-offs435- **Out of scope requests:** Redirect to appropriate specialized skill or professional resource436- **Beginner vs advanced:** Adjust depth and terminology based on user's experience level437438439## Example440441**Input:** "Help me with cybersecurity personal for my current situation"442443**Output:**444445Based on your situation, here is a structured approach to cybersecurity personal:4464471. **Assessment:** Evaluate your current state and identify key areas for improvement4482. **Strategy:** Develop a targeted plan based on best practices4493. **Implementation:** Execute the plan with specific, measurable steps4504. **Review:** Monitor progress and adjust as needed