ATTENTION, PEOPLE WHOSE PASSWORD IS THEIR DOG’S NAME PLUS AN EXCLAMATION MARK!

PEOPLE WHO THINK “I’LL RECOGNISE THE PHISH” IS A SECURITY PROGRAMME! PEOPLE WITH A ROUTER BLINKING MYSTERIOUSLY IN THE CORNER LIKE A TINY, JUDGMENTAL AQUARIUM!

Are you tired of not being compromised?

Have you spent another peaceful evening letting the browser postpone an update, reusing the password from a site that sold novelty socks, and assuring yourself a backup probably exists somewhere because the computer has never screamed about it?

Then congratulations.

You qualify for the Five Number One Rules of Personal Cybersecurity That Isn’t Just Vibes — five controls, five Number Ones, and not a single magic shield sold in a black box with red LEDs.

“Wait,” you’re shouting at the screen, “they can’t all be Number One!”

That’s exactly what Big Numbering wants.

Security failures are specialists.

A unique password won’t stop an unpatched vulnerability.

A passkey won’t restore files encrypted by ransomware.

A tested backup won’t stop a compromised guest laptop reaching a payment system on the same network.

Doing a spectacular job on one buys no waiver from the other four.

Five doors: credential reuse, account takeover, software exploitation, unrecoverable loss, and sideways travel after a compromise.

The opposite habit is the golden hammer — one familiar tool pressed against every problem because its learning cost was already paid. Security hygiene is less flattering. It asks what actually failed, then picks the control that addresses that.

So here they are.

Five rules.

Five Number Ones.

No substitutions. No “but I have antivirus.” No ceremonial password change every calendar quarter because a policy from another century acquired a cape.


RULE #1: MAKE EVERY CREDENTIAL UNIQUE

Introducing PASSWORD-O-SAME-O™, the convenient system in which every door in your life opens with one heroic phrase.

Ships with a thrilling bonus feature: one unrelated breach becomes a try-that-everywhere event.

Install a password manager. Generate a unique, high-entropy credential for every account.

Start with email and financial logins — and start there for a specific reason. Email resets nearly everything else. Its compromise isn’t one bad login. It’s a spare key to every account that trusts it.

Credential stuffing is automated reuse of credentials exposed somewhere else entirely. It works for exactly one reason: the same password appears on more than one service.

The manager isn’t an accessory to this rule. It’s the thing that makes it survivable — it remembers the long separate credential so you don’t have to maintain an expanding cemetery of old variations.

The current NIST guidance gives useful boundaries, and some of them will annoy an old policy.

A password used as a single standalone factor: minimum 15 characters. A password used alongside MFA: minimum 8. Treat that second one as a floor, not an ambition.

Verifiers should permit at least 64 characters, accept spaces and Unicode, and reject anything found in breach blocklists.

Which makes a passphrase — several unrelated words — a fully supported option rather than a quirky uncle’s theory about security.

And two things the same standard now says to stop doing: no composition rules, and no scheduled password changes.

Forced uppercase, digits and symbols don’t become wisdom by being typed with great ceremony. A password change is triggered by evidence of compromise, not by a calendar demanding a fresh exclamation mark.

A password is not strong because it is memorable. It is useful because it is unique.

Reuse isn’t convenience. It’s a loyalty programme for strangers.


RULE #1: PUT PHISHING-RESISTANT MFA ON THE KEYS TO THE KINGDOM

NOW PRESENTING TWO-FACTOR-ISH: THE PROMPT THAT ARRIVES DURING DINNER!

Tap approve often enough and eventually something will be approved. This is not authentication. It’s a doorbell with aspirations.

Turn on MFA for the accounts that can reset, spend, administer, or deploy.

Email first. Then the password manager itself. Then financial accounts, then anything with administrative or cloud-infrastructure access.

Coverage is one question. Method is a completely separate one, and it’s where most of the value hides.

A hardware security key or a passkey using FIDO2/WebAuthn is phishing-resistant — the strongest tier. Its design means a fake login page can’t collect anything an attacker is able to replay. Not “is unlikely to.” Cannot.

Authenticator-app codes and on-device prompts sit in the middle. They stop bulk phishing and bots, but a targeted page or a push-fatigue attack can still get through. Number matching helps with fatigue; it doesn’t eliminate it.

SMS and voice codes beat no MFA. They’re also a last resort — phishing, SIM swaps and network-level interception all remain live.

And the gap between tiers is measured, not decorative. In research by Google with NYU and UC San Diego, SMS codes blocked 96% of bulk phishing but only 76% of targeted attacks. On-device prompts: 99% and 90%.

No participant using a security key exclusively was compromised by any targeted phishing attempt in that study.

Look at where the tiers separate. Against automated bulk attacks they’re all decent. Against somebody actually aiming at you, they aren’t remotely equivalent.

MFA is not a checkbox. It is a choice about which attack gets to keep working.

The strongest second factor is the one a fake login page can’t carry home in its lunchbox.


RULE #1: PATCH ON A CADENCE YOU CAN KEEP

From the makers of “I WILL RESTART LATER” comes “LATER: THE EXTENDED CUT” — featuring a browser update waiting patiently while the flaw it repairs enjoys an energetic social life.

Turn on automatic updates for the operating system, the browser, and anything internet-facing.

Then treat a vendor’s critical or actively exploited advisory as same-week work — not as an item filed beside the laundry, the taxes, and the annual dream of learning guitar.

The 2026 Verizon DBIR puts exploitation of a software vulnerability at 31% of breaches, its largest initial-access category. Credential abuse is 13%. Social engineering, 16%.

That isn’t a contest between patching and account hygiene. It’s the reason these controls arrive as a set.

But the tempo is the part worth internalising, because it has moved dramatically.

Median time between a patch shipping and active exploitation: 63 days in 2018–2019. Then 44. Then 32.

Then 5 days, in 2023.

A monthly patching ritual made sense against a 63-day clock. Against a five-day one it isn’t slower hygiene — it’s a different assumption about the world, and the world stopped agreeing.

The distribution within that year says the same thing. Of vulnerabilities eventually exploited after a patch shipped, 12% were hit within one day, 29% within a week, 56% within a month.

Meanwhile the DBIR reports a median 43 days to fully remediate a critical vulnerability — with only 26% fully remediated, down from 38% the year before.

So automate what you can, and give the short-fuse advisories immediate attention. And retire unsupported operating systems and hardware rather than trying to patch around their unsupportedness, which is not a thing that works.

The adjective doing all the work in “enable automatic updates” is automatic. A security system built on perfect future memory is cargo culting with a calendar invite.

Patch speed is not a virtue signal. It is a race against an observed clock.

The update is annoying for a moment. The exploit is inconvenient in a far more committed way.


RULE #1: KEEP A RESTORABLE BACKUP

BEHOLD THE BACKUP-SOMEWHERE™ — a state-of-the-art feeling that files must be safe because they’re important.

No restoration test required. No actual copy guaranteed. Just confidence, displayed in a soothing blue progress bar.

Maintain a backup that runs automatically and lives separately from the system it protects. Include at least one offline or immutable copy.

Then restore from it. Once. For real.

The test isn’t an optional extra on top of the backup — it is the backup, because recovery is the property you were trying to buy. Not the comforting existence of a folder named backup-final-really.

This rule limits the damage after the earlier rules fail. It doesn’t replace them.

MFA may stop the account takeover. Patching may close the software path. Neither recreates files once an attacker has encrypted the live copy and everything connected to it.

Keep the scope honest, too. Retention schedules, versioning and naming belong to data hygiene. Security hygiene needs one narrower, non-negotiable question:

Does an automatically maintained, separately stored, offline copy actually restore when asked?

The failure mode here is waiting to design the perfect backup architecture, and therefore never making the imperfect one that would have worked. The details can change later.

The restoration test can’t.

A backup is not a possession. It is a successful restoration waiting to happen.

Data that exists only in the place currently on fire hasn’t been backed up. It’s been narrated.


RULE #1: SEGMENT THE BLAST RADIUS

AND NOW, EVERYTHING-TO-EVERYTHING ULTRA™: why should a guest laptop, a smart bulb and a payment terminal endure the tragedy of boundaries?

Let every device meet every other device! What could possibly network sideways?

For a home or small business, use a separate wireless network, a VLAN, or the router’s built-in guest feature to keep guest devices and smart devices away from anything handling business data or payments.

Keep payment systems on their own segment.

That’s proportionate segmentation. Not a demand to convert the spare room into a data centre with a weather map.

Then use a separate elevated account for administrative tasks, rather than browsing all day from an admin login. Everyday activity shouldn’t carry unnecessary reach.

Segmentation has exactly one purpose, and it’s enough: a compromised guest laptop or smart device doesn’t automatically reach the systems holding customer data or payment information.

It won’t prevent the first compromise. It prevents that compromise from becoming every compromise.

Which is the whole architecture, stated once more. A password manager protects credentials. Phishing-resistant MFA protects authentication. Patching protects against known flaws. A backup protects recovery. Segmentation protects the paths between systems.

Asking any one of them to do all five isn’t a plan. It’s a decorative diagram of a plan.

Security is not only about keeping attackers out. It is about giving them fewer places to go.

The safest network isn’t the one with the most blinking lights. It’s the one where a bad device has a shorter story.


BUT WAIT, THERE’S MORE!

“What about a phone?”

Same rules. Automatic updates, unique credentials, MFA, a restorable backup, and network access matched to what it can actually reach.

“What about a smart home?”

Same rules. Those devices go on the separate network, not beside the accounts holding money and administrative authority. The brand changes. The blast radius doesn’t.

“What about the one service that only offers SMS?”

Same rules. SMS beats nothing and remains the weakest tier. Use it where it’s all that’s offered, and give your highest-value accounts the strongest method they support.

“What about a small team that ships code?”

Same rules, plus the supply chain. No secrets in source control — a committed key stays in history after you delete it. MFA on every account with write access to the repo or the pipeline. Routine dependency updates, and CI/CD secrets rotated on turnover.

“What about the perfect setup?”

Same rules. Don’t cargo-cult somebody else’s hardware key or router ritual. Ask which failure it prevents. Nothing gets to impersonate the whole architecture.

The details change.

The architecture doesn’t.


THE FIVE, WITHOUT THE RED LEDS

Make every credential unique, generated and stored by a password manager — length and blocklists rather than composition rules and scheduled churn.

Put the strongest available MFA on email, the password manager, money, and admin. Prefer passkeys and hardware keys; treat SMS as a last resort.

Enable automatic updates, and treat actively-exploited advisories as same-week work. Retire what can’t be patched.

Keep an automatic, separately stored backup with an offline copy — and prove it by restoring once.

Separate guest and smart devices from business data and payments, and keep elevated accounts out of daily browsing.


DO THIS TONIGHT

Open the password manager and kill the reuse on email and financial accounts first. Not all of them. Those.

Turn on the strongest available MFA for email, the manager, money, and anything that deploys or administers.

Do not start by agonising over the perfect app, key ring, or router. Start with the accounts whose reset flows and elevated access cascade into everything else.

Enable automatic updates on the operating system, browser, and anything facing the internet.

Then find the backup. Confirm it runs on its own, sits apart from the live system, has an offline copy — and can restore.

If it has never restored, that’s tonight’s task. Not an item for the imaginary quarter in which everybody has spare afternoons.

Then open the router. Create the guest network. Move the guest and smart devices onto it. Keep payments and business data off it.

At every step, ask one question:

If this one thing is compromised, what does it reach next?

The answer points at a unique credential, a stronger second factor, a patch, a restoration path, or a boundary.

That’s security hygiene. Not fear, not folklore, and not an exhausted person trying to remember every warning forever.

For the low, low price of doing the unglamorous thing before the emergency, the complete Five Number One system is yours.

No subscription. No secret hacker handshake. No USB drive mailed in a velvet case.

Just five controls that refuse to cover for one another.

Operators are no longer standing by.

The operator is whoever gets the 3 a.m. email.