Home / Uncategorized / Security recommendations

Security recommendations

Good afternoon! Marta here at the controls.

Passwords are the first line of defense in our digital life, and yet we keep making basic mistakes with them. Using the same password for everything, choosing obvious combinations like “123456” or “contraseña”, or basing them on easily obtainable personal information (pet name, date of birth) is like putting a toy padlock on the door of your house. The current recommendation is to use long passwords, unique for each service and preferably full phrases instead of single words. “MiPerroTobyLadra3VecesAlDia!” is much more secure and easier to remember than “Mpt3vad!”.

Password managers are your best allies in this battle. Apps such as LastPass, 1Password, Bitwarden or the manager built into your browser can generate complex, unique passwords for each service, and you only need to remember one master password. It is like having a personal bodyguard who handles all your keys and only asks you to remember the code of the safe where it keeps them. Yes, it takes an initial effort to set everything up, but once done, you will wonder how you lived without it.

Two-factor authentication (2FA) adds an extra layer of security by requiring, in addition to your password, a second element to verify your identity. It can be a code sent by SMS, generated by an app such as Google Authenticator or Microsoft Authenticator, or even a physical key like YubiKey. It is like having a door with two different locks: even if someone gets the key to one, they still will not be able to get in. Enabling 2FA on your most important accounts (email, social networks, online banking) should be an absolute priority.

Software updates are those annoying notifications that many of us keep postponing, but they are crucial for security. Many updates fix vulnerabilities that cybercriminals already know about and are actively exploiting. Every day you go without updating is one more day your device has a back door wide open. It is like ignoring a notice that the lock on your house is faulty and anyone can open it with a simple paperclip: nothing may happen today, but do you really want to take that risk?

Phishing remains one of the most effective techniques for cybercriminals, precisely because it exploits the weakest link in the security chain: the human factor. These attacks have evolved from those obvious “Nigerian prince” emails to sophisticated imitations of legitimate communications from banks, messaging services or even your own coworkers. The golden rule is to distrust any message that asks you for sensitive information or urges you to click on links, especially if it creates a sense of urgency. When in doubt, contact the supposedly sending organization directly through its official channels, rather than replying to the suspicious message.

Device encryption is a basic but effective measure that many users do not know about or do not implement. Both Windows (with BitLocker), macOS (with FileVault) and mobile systems offer options to encrypt all the content of the device. This means that, even if someone physically steals your computer or phone, they will not be able to access your data without the password. It is like having a safe instead of a locked drawer: even if they take it away, they will not be able to see what is inside.

Backups are your safety net when everything else fails. Whether it is a ransomware attack, a hardware failure or simply human error, having up-to-date copies of your important data can save you from a monumental headache. The 3-2-1 rule is a good starting point: three copies of your data, on two different types of storage, with one copy outside your physical location (for example, in the cloud). It is like having an evacuation plan for your data: you hope you never need it, but you will be glad you have it if the worst happens.

Privacy on social networks is another aspect many neglect. Regularly reviewing the privacy settings of your profiles, being aware of what you share publicly and thinking twice before posting personal information are habits that can prevent everything from identity theft to awkward situations at work or in your personal life. Remember that on the internet, once something is published, it potentially remains forever, even if you delete it from your profile. It is like speaking in a full theater: even if you later ask everyone to forget what you said, you never know who has heard and remembered it.

Public WiFi networks are fertile ground for “man-in-the-middle” attacks, where an attacker intercepts the communication between your device and the server you are connecting to. Avoid performing sensitive operations (such as online banking or shopping) while connected to these networks, or use a VPN (Virtual Private Network) that encrypts your traffic. It is like talking on the phone in the middle of a crowded square: anyone could be listening, unless you use an encrypted language that only the recipient can understand.

In conclusion, digital security is not a product you buy once, but a set of habits and practices you must integrate into your daily life. It may seem overwhelming at first, but as with any habit, once established it becomes automatic. And remember, it is not about turning yourself into an impenetrable fortress (that is practically impossible), but about being a hard enough target that attackers prefer to look for easier victims. In the world of digital security, you do not need to be faster than the bear; you only need to be faster than the other hiker. See you next time, digital friends!