1. PASSWORDS
Passwords are the first line of defense against unauthorized access to your data. You would be remiss to have your date of birth, your child’s name, your wedding date, or any other publicly available information about yourself as your password. Passwords must be complex to raise the level of difficulty for bad actors. A good password would comprise of upper- and lower-case alphabet, numbers, and special characters. You can use mnemonics to remember complex passwords. You can use passphrase instead of just a single word—yes, type the full sentence, with the space and punctuation. Some online services have character limits as part of their password requirements.
Useful Links
How Secure Is My Password – https://www.security.org/how-secure-is-my-password/
Password Generator – https://passwordsgenerator.net
2. 2FA (Second-Factor Authentication)
This is an added layer of security in protecting your data, and it involves a random string of numbers that have been programmed to work with only your account and is generated every 30 seconds and expires at the end of the countdown. If your password gets compromised, the 2FA was introduced to keep out unauthorized access. Please note that if you lose your 2FA key, even you would not be able to access your data. You can use your phone number as 2FA via SMS or Phone call, you can also use any of the authenticator apps available on the mobile app stores.
Useful Links
Google Authenticator – https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&hl=en
https://apps.apple.com/us/app/google-authenticator/id388497605
3. OTP (One-Time Password)
When signing up for a digital service or account, and you enter your email address or phone number, you would usually get an OTP (one-time password) which is basically a way for the service to verify that you are the owner of the email address or phone number, or at the very least, that the said credential is operational. Sometimes, when you need to make changes to the same accounts, an OTP is generated to be sure you are the one initiating the changes. DO NOT SHARE any OTP Code that comes into your phone or email with a third-party, especially if you did not initiate the said changes.
4. ENCRYPTION
If you or your organization work with sensitive data, you should take encryption of all your data as priority. This involves rendering all data unreadable for anyone who does not possess the decryption key (think of it as a more complex password, usually a very long and random string of characters). If your computer or mobile device falls into unauthorized hands, the data on the devices will be useless as they can’t be read without a decryption key. Setting up a policy to ensure compliance in your organization would go a long way in keeping bad actors at bay, as there is a great benefit employing defense in depth.
5. SECURITY SOFTWARE
Another layer in securing your data is security software, and these comprises of Internet Security, Anti-virus, Anti-Malware, Anti-Spyware, and Anti-Ransomware software. They all seek to address various aspects of bad actors’ point of attack on your devices and ultimately your data. Investing in the right security software to add another layer of protection for your data is good practice.
