Cybersecurity Essentials
Most security advice is either useless or terrifying. This page is neither. Test a password below, find tools worth your time, and see what the famous breaches actually teach you — in plain English, usable by anyone, without the fear-selling.
Password Strength Tester
See how a password holds up — calculated in your browser, nothing is sent anywhere.
- Add uppercase letters (A-Z)
- Add lowercase letters (a-z)
- Add numbers (0-9)
- Add symbols (!@#$%^&*)
- Make it at least 12 characters
Why this matters
Strength is only half the job. A strong password reused across five sites is one breach away from being useless on all five. Unique beats clever.
The practical fix: let a password manager generate and remember long random passwords, and turn on two-factor authentication on your email first. Email is the master key to everything else.
Tools, Sorted by What You’re Protecting
Not a shopping list. These are the ones worth the five minutes it takes to set them up.
Your Phone
- Bitwarden — free password manager, syncs across phone, desktop and browser.
- Authy — two-factor codes that survive losing your phone, unlike most authenticator apps.
- Signal — end-to-end encrypted messaging, on by default, no configuration.
- Brave or Firefox Focus — mobile browsing without the tracker load.
Your Money
- Your bank’s own app — use its 2FA instead of SMS codes. SIM swapping is real and SMS is the weak link.
- Credit freeze — free at all three bureaus, blocks new accounts opened in your name. The single highest-value hour you can spend.
- Virtual card numbers — offered by most major issuers. One number per merchant, kill it if it leaks.
- Malwarebytes — catches the banking trojans that antivirus misses.
Your Accounts
- haveibeenpwned.com — free, no signup. Enter your email, see which breaches you’re already in.
- A password manager — Bitwarden (free) or 1Password (paid, more polish). Either beats reuse.
- Passkeys — where offered, they replace the password entirely and can’t be phished.
- Recovery setup — backup email and phone on your primary account, done before you need it.
Your Family
- Family password manager plan — Bitwarden and 1Password both offer them. Kids learn the habit early.
- Built-in family sharing — Apple, Google and Microsoft all ship it free. Screen time, purchase approval, content limits.
- A code word — low tech, works. If someone calls claiming to be family in trouble, ask for it. Defeats voice-cloning scams.
- One rule taught well — nobody legitimate ever asks for a one-time code. Nobody.
Your Business
- Cloudflare — DDoS protection, WAF, SSL. The free tier covers most small sites.
- Wordfence — if you run WordPress, this is table stakes.
- NIST Cybersecurity Framework — free, and it scales down to a two-person shop.
- A written incident response plan — who calls whom, in what order. CISA publishes templates. Write it before you need it.
Six Things People Get Wrong
Common advice that hasn’t aged well.
Myth“I’m too small to be a target.”
RealityNobody chose you. Attacks are automated and indiscriminate — scanners sweep the entire internet looking for anything unpatched. Being small doesn’t make you invisible, it makes you cheaper to compromise.
Myth“Complex passwords beat long ones.”
RealityLength wins. A four-word passphrase is stronger than P@ssw0rd! and you can actually remember it. And unique beats both — a perfect password reused everywhere fails everywhere at once.
Myth“Password managers are a single point of failure.”
RealityThey are, and it’s still the better trade. The alternative — reused passwords across dozens of sites — is dozens of points of failure, each one outside your control.
Myth“Public WiFi will get me hacked.”
RealityMostly outdated. Nearly everything is HTTPS now, which encrypts the traffic regardless of the network. The real modern risk is your own device being out of date, not the coffee shop router.
Myth“Incognito mode makes me anonymous.”
RealityIt clears local history. That’s the whole feature. Your ISP, your employer, and every site you visit see exactly the same thing they always did.
Myth“I’d recognize a phishing email.”
RealityYou’d recognize a bad one. The good ones now come from a real compromised account, in an existing thread, in fluent English, referencing a project you’re actually working on. Verify through a second channel — that’s the defense, not intuition.
Famous Breaches, Explained Plainly
What actually happened, and the one thing worth taking from each.
Equifax
2017 · 147 million people
A known flaw in a web framework had a patch available for two months. Equifax didn’t apply it on one server. Attackers walked in and spent 76 days quietly pulling out names, Social Security numbers, birth dates and addresses.
Takeaway: the gap between “patch exists” and “patch applied” is where most breaches live. Turn on automatic updates everywhere you can.
Uber
2016 · 57 million riders and drivers
Attackers found credentials sitting in a private code repository, used them to reach a cloud storage account, and took the data. Uber then paid the attackers 100,000 dollars to call it a bug bounty and stayed quiet for a year.
Takeaway: secrets in code get found. And the cover-up did more legal damage than the breach.
SolarWinds
2020 · roughly 18,000 organizations
Attackers compromised the build system for a network monitoring tool and added a backdoor to a signed, legitimate software update. Every customer who installed it — including multiple US federal agencies — installed the backdoor themselves.
Takeaway: your security is inherited from every vendor in your stack. Trusted software is still someone else’s attack surface.
Change Healthcare
2024 · roughly 190 million people
Ransomware operators got in through a remote access portal that had no multi-factor authentication on it. Pharmacies across the US couldn’t process prescriptions for weeks. The ransom was paid. The data leaked anyway.
Takeaway: one account without MFA took down a chunk of national healthcare infrastructure. There is no such thing as a low-priority login.
Start Here — Three Things, One Afternoon
If you do nothing else on this page, do these.
Turn on 2FA for your email
Not your bank — your email. It’s the account that can reset every other account you own. Protect it first, and everything downstream gets harder to steal. Five minutes.
Install a password manager and move ten accounts into it
Don’t try to migrate everything at once — you’ll quit. Do your email, bank, and the eight sites you actually log into. The rest can wait. Twenty minutes.
Check yourself at haveibeenpwned.com
Free, instant, no account needed. Anywhere it says you’ve been breached, change that password — and change it anywhere else you reused it. Two minutes.
Keep going
We cover this stuff every week — the breaches, the tools, and what actually changes for normal people. Both sides of every story, no fear-selling.
