What is Cybersecurity?
You lock your front door when you leave the house. Cybersecurity is the same idea — but for your digital life. This lesson explains what it is, why it matters, and who is actually trying to get in.
Every time you use a phone, log into a website, send an email, or pay for something online, you are operating in digital space. That space has real value — your money, your photos, your messages, your identity. Cybersecurity is the practice of protecting all of that from people who want to steal, damage, or exploit it.
You don't have to be a tech expert to be a target
A common mistake people make is thinking "I'm not important enough to be hacked." That is not how it works. Attackers aren't always looking for a specific person — they cast wide nets. Automated tools scan millions of accounts looking for weak passwords, old software, or anyone who clicks the wrong link. Regular people get hit every day.
Who are the attackers?
Mostly criminals after money. Sometimes it's identity thieves, scammers, or even people you know. Nation-state hackers exist but rarely target everyday people.
What do they want?
Money (directly or through stolen accounts), your personal information to sell, access to your device, or to use your account to attack others.
How do they get in?
Tricking you into clicking something, guessing or stealing your password, exploiting old software, or using information you posted publicly.
Why cybersecurity matters now
More of your life is online than ever. Banking, healthcare records, government IDs — all digital. A breach can take months and thousands of dollars to recover from.
The three things security tries to protect
Security professionals talk about the CIA triad — three goals that every security decision tries to balance:
- Confidentiality — Only the right people can see your information. Your bank balance is not public.
- Integrity — Your information is accurate and hasn't been tampered with. The amount in your bank account is the real number.
- Availability — Your information and services are there when you need them. You can log in when you need to, not just when attackers haven't shut the system down.
You don't need to memorize this — just know that security isn't only about keeping secrets. It's also about making sure nothing is changed without your knowledge and that things work when you need them.
This is a concepts-first course. You won't need to install anything or run any programs. By the end you'll have real, practical habits — not just theory — that will protect you starting today.
How the Internet Works
You can't protect something you don't understand. This lesson gives you just enough of a mental model of the internet to understand how attackers use it against you — no technical degree required.
The internet is just computers talking to each other
When you open a website, your computer sends a message to another computer (a server) somewhere in the world asking for that page. The server sends the page back. That's it. Every email, video, purchase, and login is some version of this: messages traveling between computers.
Those messages travel through physical cables under oceans, through wireless signals, and through routers in buildings and homes. At each step, your data could theoretically be seen by someone in between — which is why encryption matters (more on that shortly).
IP addresses and why they matter
Every device connected to the internet has an IP address — a number that acts like a mailing address. When you visit a website, that site can see your IP address. Your internet provider (ISP) can see every site you visit. This is important to understand: browsing the internet is not automatically private.
What HTTPS means
When a website address starts with https://, the S stands for secure. The connection between your browser and that website is encrypted — scrambled so that even if someone intercepts the data in transit, they can't read it. A site with just http:// (no S) sends your data in plain text. Never enter a password or payment information on a site without HTTPS.
HTTPS only means your connection to the site is encrypted. It does NOT mean the website itself is trustworthy or legitimate. Scam websites use HTTPS too. Always verify you're on the right site, not just a secure connection to the wrong site.
DNS — the internet's phone book
When you type google.com, your computer doesn't actually know where Google is. It asks a DNS server to translate that name into an IP address. Attackers sometimes exploit DNS to redirect you to a fake website — you type a real address, and get sent somewhere else. This is called DNS poisoning or a DNS hijack.
Routers and your home network
Your home router is the gate between all your devices and the internet. Every phone, laptop, TV, and smart device in your home connects through it. If an attacker gets into your router, they can see all traffic on your network. This is why router security — keeping its software updated and using a strong password — matters more than most people realize.
Your Digital Identity
Your digital identity is everything online that represents you — your accounts, your data, your reputation. Understanding what makes it up is the first step to protecting it.
What is your digital footprint?
Every time you use the internet, you leave traces. These traces make up your digital footprint. There are two kinds:
- Active footprint — things you intentionally post: social media updates, comments, profile information, reviews you write.
- Passive footprint — data collected about you without you actively sharing it: which sites you visit, how long you spend there, your location, what ads you click.
Together, these create a surprisingly detailed picture of who you are, where you live, what you buy, who you know, and what you believe. Advertisers use this to target you. Criminals use this to target you too.
The accounts that matter most
Not all accounts are equal. Some are so important that if an attacker gets in, they can use that one account to access everything else. These are your high-value accounts:
Email account
If someone has your email, they can reset the password to almost every other account you own. Your email is the master key to your digital life.
Phone number
Used for two-factor authentication and account recovery everywhere. Attackers can steal your phone number through a "SIM swap" attack.
Bank & financial accounts
Direct access to your money. Also used to verify identity for loans and other financial actions.
Google / Apple ID
Tied to your devices, purchases, photos, location history, and often your payment method. A breach here is severe.
Have I already been breached?
There's a good chance your email address and password have already appeared in a data breach from some site you used years ago. You can check for free at haveibeenpwned.com — a legitimate, widely trusted service run by a security researcher. Just enter your email address and it will tell you which known breaches included your data.
If you find your email in a breach: change the password for that site immediately, and change it on any other site where you used the same password.
Go to haveibeenpwned.com and enter your email address. It's free, safe, and takes 10 seconds. If your email shows up in breaches, don't panic — just start with the highest-priority accounts and work your way down.
Phishing & Social Engineering
The most effective attacks don't break through technology — they trick people. Phishing is responsible for the majority of successful breaches worldwide. Learning to spot it is your single most valuable security skill.
What is phishing?
Phishing is when an attacker pretends to be someone you trust — your bank, Amazon, the IRS, a friend — to trick you into giving up your password, clicking a malicious link, or handing over personal information. The name comes from "fishing": they cast a hook and wait for someone to bite.
Social engineering is the broader category — any attack that manipulates human psychology rather than hacking technical systems. Phishing is the most common form, but it also includes phone calls (called vishing) and text messages (called smishing).
How to recognize a phishing attempt
From: security@paypa1.com
Subject: URGENT: Your account has been suspended
Dear Customer,
We have detected unusual activity on your account. Your account will be permanently closed in 24 hours unless you verify your information immediately.
Click here to verify your account → http://paypa1-secure.net/verify
PayPal Security Team
Red flags in that example:
- The sender domain is
paypa1.com(the letter L replaced with the number 1) — notpaypal.com - Urgent, threatening language designed to make you panic and act without thinking
- The link goes to
paypa1-secure.net— not PayPal's real domain - A real company will never suspend your account with only 24 hours notice via email
The golden rule
If an email, text, or call creates urgency and asks you to click a link or provide information — stop. Close the email. Open a new browser tab and go directly to the company's real website by typing the address yourself. Call the company using a number from their official website, not a number given in the message.
Never click a link in an email to log in. Always navigate there yourself.
Regular phishing is sent to millions of people at random. Spear phishing is targeted — the attacker researches you first (using your social media, LinkedIn, public records) and crafts a message that feels personal and real. "Hey, I saw you just started at Company X — here's the onboarding form" — sent by someone pretending to be HR. These are much harder to spot.
Malware & Viruses
Malware is software designed to harm you. It gets on your device through downloads, email attachments, or infected websites — and it can do everything from slowing your computer down to locking all your files until you pay a ransom.
Types of malware you should know
| Type | What it does | Common source |
|---|---|---|
| Virus | Attaches to files and spreads when you open them, damaging data | Email attachments, pirated software |
| Ransomware | Encrypts all your files and demands payment to unlock them | Phishing emails, malicious downloads |
| Spyware | Secretly records what you do — keystrokes, passwords, browsing | Free software bundles, fake apps |
| Trojan | Disguises itself as a legitimate program to get you to install it | Fake software downloads, cracked apps |
| Adware | Floods you with ads; often bundles spyware | Free apps, browser extensions |
| Rootkit | Hides deeply in your system to give attackers persistent, hidden access | Compromised downloads, drive-by attacks |
Ransomware: the threat that has shut down hospitals
Ransomware deserves special attention because it's one of the most devastating threats today — and it hits regular people, not just corporations. You download what looks like a legitimate file. It runs in the background. Then one day you turn on your computer and every file — photos, documents, everything — is locked with a message demanding payment in cryptocurrency to get it back.
There is often no recovery if you don't have a backup. Paying the ransom doesn't guarantee you'll get your files back. The best defense is prevention and backups.
How malware gets on your device
- Opening an email attachment you weren't expecting
- Downloading software from unofficial or sketchy sites
- Installing a browser extension that turns malicious
- Clicking on a malicious ad (called malvertising)
- Visiting a compromised website that exploits old browser software
- Plugging in a USB drive you found or were given by someone you don't trust
Keep your operating system and apps updated. Use reputable antivirus software. Only download from official sources. Never open attachments you weren't expecting. Back up your important files to an external drive or cloud storage regularly — a backup is the only true ransomware recovery.
Passwords & Credential Theft
Stolen or weak passwords are the number one way attackers get into accounts. This lesson explains exactly how passwords get stolen and why the approach most people take doesn't work.
How attackers steal passwords
There are several ways your password can end up in an attacker's hands — and most of them don't require any skill on their part:
- Data breaches — A site you use gets hacked and its password database is stolen. If the site stored passwords poorly, attackers can crack them.
- Phishing — You type your password into a fake site that looks real.
- Credential stuffing — Attackers take usernames and passwords from one breach and automatically try them on other sites. If you use the same password everywhere, one breach compromises everything.
- Brute force — Automated tools try every possible combination. Short, simple passwords fall in seconds.
- Keyloggers — Malware on your device records every key you press, including passwords as you type them.
Why "Password123" gets cracked instantly
Modern computers can test billions of password guesses per second. Common words, names, dates, and simple substitutions (replacing O with 0, E with 3) are tried first because attackers know people use them. A password like Summer2024! sounds complex but falls in seconds — it follows a pattern everyone uses.
"password" → cracked instantly
"Password1" → cracked in under 1 second
"P@ssw0rd!" → cracked in under 1 minute
"correct-horse-battery-staple" → centuries at current speeds
"x7$Kp!qL9mW#2vR" → effectively uncrackable
The password reuse trap
The most dangerous habit in digital security is using the same password across multiple sites. When any site you've ever used is breached, attackers immediately try that username and password combination on Gmail, banks, Amazon, and hundreds of other sites. This is automated and happens within hours of a breach. One breach cascades into total account loss.
The solution — and it's the only real solution — is to use a unique password for every single account. The next lesson covers how to actually do this without going insane.
Don't reuse passwords across sites. Don't use personal info (birthdays, names, pets). Don't store passwords in a text file on your desktop. Don't share passwords over email or text. Don't use "forgot password" security questions with real answers — those answers are often publicly available on social media.
Strong Passwords & Password Managers
You need a unique, strong password for every account — and you have dozens of accounts. No human can memorize all of them. Password managers solve this. Here's how they work and why you should trust them.
What is a password manager?
A password manager is an app that generates and stores all your passwords in an encrypted vault. You only need to remember one thing: your master password. The app handles everything else — creating long, random, unique passwords for every site and filling them in automatically when you log in.
What makes a password actually strong?
Two things: length and randomness. A 20-character random string is essentially uncrackable with current technology. Password managers generate these automatically. You don't need to see them or remember them — the manager stores and fills them.
Trusted password managers
| Manager | Cost | Notes |
|---|---|---|
| Bitwarden | Free / $10/yr premium | Open source, audited, highly recommended for most people |
| 1Password | $36/yr | Excellent design, great family plan, very popular |
| Dashlane | Free / $33/yr | Good interface, includes dark web monitoring |
| Apple Keychain | Free (Apple devices) | Built-in, solid, but limited to Apple ecosystem |
| Google Password Manager | Free (Chrome/Android) | Convenient but ties you to Google's ecosystem |
"But what if the password manager gets hacked?"
This is the most common concern. Here's the reality: reputable password managers encrypt your vault with your master password before it ever leaves your device. Even if the company's servers are breached, attackers get encrypted data they can't read without your master password. Storing all your passwords in a manager is dramatically safer than reusing weak passwords across sites.
Your master password
This one password must be memorized — it's the only one you'll ever need to. Make it a passphrase: four or more random words strung together. Something like correct-horse-battery-staple or purple-river-cloud-seven. Long, random, memorable. Never use this password anywhere else.
Start with Bitwarden — it's free and takes about 10 minutes to set up. Install the browser extension, import or add your most important accounts, and let it generate new strong passwords as you go. Don't try to do everything at once. Start with your email and bank accounts.
Two-Factor Authentication
Two-factor authentication (2FA) is the single most impactful thing you can add to your accounts after a strong password. Even if an attacker has your password, 2FA stops them cold.
What is two-factor authentication?
Authentication is proving you are who you say you are. Most sites use one factor: something you know (your password). Two-factor authentication adds a second factor — something you have (your phone) or something you are (your fingerprint).
Even if an attacker has your correct username and password, they still can't get in without the second factor. It turns a compromised password from a catastrophe into a non-event.
Types of 2FA — from weakest to strongest
| Type | How it works | Security level |
|---|---|---|
| SMS code | A 6-digit code texted to your phone | Weak — SIM swapping can intercept texts |
| Email code | A code emailed to you | Weak — if email is compromised, so is this |
| Authenticator app | App generates a code that refreshes every 30 seconds | Strong — highly recommended |
| Hardware key | Physical USB/NFC device you plug in or tap | Strongest — nearly unphishable |
| Passkey | Cryptographic key stored on your device; biometric verification | Strongest — the future standard |
Authenticator apps you should use
Download one of these on your phone. They generate codes without needing internet or cell signal:
- Authy — Free, backs up your codes (important if you lose your phone)
- Google Authenticator — Simple, widely supported
- Microsoft Authenticator — Works well with Microsoft accounts especially
Where to enable 2FA first
Prioritize your most critical accounts: your primary email, your Google or Apple ID, your bank accounts, and any financial services. Most major platforms support it — look in account settings for "Security" or "Two-step verification."
Save your backup codes
When you enable 2FA, sites give you backup codes to use if you lose access to your phone. Save these somewhere safe — printed and stored physically, or in your password manager. Losing your phone without backup codes can lock you out of your accounts permanently.
A common scam: someone calls pretending to be from your bank or Google support and says they need to verify your identity by having you read them the code that just appeared on your phone. That code is real — they triggered a login attempt. Reading it to them hands them access. Legitimate companies will never ask for your 2FA code.
Safe Browsing & Public Wi-Fi
Your browser is your window to the internet — and a major attack surface. Public Wi-Fi makes things worse. This lesson covers how to browse safely and what to do when you're not on your home network.
Browser safety basics
Your browser keeps you safer than you might realize — but only if you let it. Here's what to keep in mind:
- Keep your browser updated. Browser updates patch security vulnerabilities. Running an old version is like leaving a known door unlocked.
- Pay attention to warnings. When your browser warns you that a site is unsafe or the certificate is invalid, believe it. Don't click through.
- Use a browser extension like uBlock Origin. It blocks malicious ads and trackers, reducing your exposure to malvertising.
- Don't install random browser extensions. Extensions have access to everything you do in your browser. Only install from reputable sources and only what you actually need.
What is a VPN and do you need one?
A VPN (Virtual Private Network) encrypts your internet traffic and routes it through a server in another location. This hides your activity from your ISP and from anyone snooping on the same network — like on public Wi-Fi.
VPNs are useful but not magic. They don't make you anonymous on the internet. They don't protect you from phishing or malware. The VPN company can see your traffic instead of your ISP. Use a trustworthy, paid VPN — free VPNs often sell your data.
Public Wi-Fi: the real risk
Coffee shops, airports, hotels — open Wi-Fi networks are convenient and dangerous. On an unsecured network, other people on the same network can potentially see your traffic. Attackers can also set up fake networks with names like "Starbucks Free WiFi" — you connect thinking it's legitimate, and they see everything.
Never access your bank or any financial account on public Wi-Fi without a VPN. Never log into accounts on a public computer. If you must use public Wi-Fi regularly, get a VPN. Your phone's cellular data is significantly safer than open Wi-Fi — use it when you need to do something sensitive.
HTTP vs HTTPS — checking the padlock
Before entering any sensitive information on a website, check that the address bar shows https:// and a padlock icon. In modern browsers, the padlock is always visible on secure sites. If it's missing, or if you see a warning about the connection, do not enter any information on that page.
Keeping Devices Updated
Software updates aren't just about new features. Most updates patch security vulnerabilities that attackers actively exploit. Running old software is one of the most common ways devices get compromised.
What is a vulnerability?
A vulnerability is a flaw in software — a bug that attackers can exploit to do things the software wasn't meant to allow. When researchers or attackers discover a vulnerability, the software company races to release a patch that fixes it. The update you keep dismissing is often that patch.
Between the time a vulnerability is discovered and the time you apply the patch, you are exposed. Attackers know about known vulnerabilities and actively scan for unpatched systems. This window of exposure is called the patch gap.
What to keep updated
- Your operating system (Windows, macOS, iOS, Android) — this is the most critical. Enable automatic updates.
- Your browser — modern browsers update silently and frequently. Make sure auto-update is on.
- Your apps — especially anything that accesses the internet: email clients, productivity apps, communication tools.
- Your router firmware — most people never do this. Log into your router's admin panel every few months and check for firmware updates.
- Your phone — iOS and Android release security patches regularly. Don't skip them.
End of life software
When a software version reaches its end of life, the manufacturer stops releasing security patches for it. Using end-of-life software means vulnerabilities discovered after that date are never fixed. If you're running Windows 10 (which reached end of life in October 2025), an old iPhone that can't update, or any other unsupported software — you are running with known, unpatched holes that attackers actively exploit.
Enable automatic updates for your OS, browser, and apps. This removes the decision entirely and eliminates the patch gap. Yes, updates occasionally cause minor issues — but that risk is far smaller than running known-vulnerable software.
Your Data & Who Wants It
You are the product. Every free app, every free service collects data about you. This lesson explains who is collecting your data, what they do with it, and how to limit what you give away.
The data economy
When a service is free — social media, email, search engines, apps — you are generally paying with your data. Companies collect information about what you do, what you buy, what you search for, where you go, and who you talk to. They use this to build an advertising profile and sell access to advertisers who want to reach people like you.
This isn't inherently criminal. But it means that enormous databases of detailed personal information exist about most people — and those databases are targets for attackers. A breach at a data broker or advertising company can expose information you never even knowingly shared.
Types of data companies collect
What you do
Websites you visit, searches you make, videos you watch, ads you click, time you spend on each page.
Where you go
Your home, work, where you shop, where you worship, where your kids' school is. Apps with location access build a full picture.
Who you are
Name, age, income range, relationship status, health conditions, political views — inferred from behavior or directly shared.
Who you know
Your contacts, your relationships, who you communicate with and how often. Apps with contact access harvest this immediately.
App permissions: what to actually allow
Every permission an app asks for is a data collection opportunity. Camera, microphone, location, contacts — grant these only to apps that genuinely need them to function, and use the most restrictive option available (for example, "only while using the app" instead of "always" for location).
- A flashlight app does not need your contacts or location.
- A game does not need your camera or microphone.
- A weather app needs your location once — not constant background access.
Review your app permissions periodically. On iPhone: Settings → Privacy. On Android: Settings → Apps → Permissions.
Use a separate email address for signups and newsletters — not your primary email. Use a VPN to hide your browsing from your ISP. Use a privacy-focused browser like Firefox or Brave. Use a privacy-focused search engine like DuckDuckGo. Each step reduces your footprint.
Social Media Safety
Social media is the richest source of personal information attackers use to craft convincing scams, guess security questions, and build profiles for identity theft. What you post publicly matters more than most people realize.
What attackers harvest from social media
Think about what's typically on a public social media profile:
- Your full name, birthday, hometown
- Where you work or go to school
- Your family members' names
- Your pet's name (a very common password ingredient)
- Where you are — and when you're not home
- Your political and religious views
- Your friends and their relationships to you
Every piece of this is useful to an attacker. Your pet's name answers a common security question. Your birthday and hometown combined with your name is enough to start an identity theft attempt. A post saying you're on vacation tells a local burglar your house is empty.
Privacy settings are not optional
Go through the privacy settings on every social platform you use. Set your posts to friends only. Remove your birthday from public view. Disable location sharing in posts. Don't allow strangers to see your friends list — it's a social engineering goldmine.
Think before you post
Ask yourself: if a stranger saw this, what could they learn about me? A photo of your new car with the license plate visible. A post tagged at your home. A photo of your kids with their school name on a jersey. These seem harmless individually but create a detailed profile in aggregate.
Fake accounts built to collect data from people who accept requests from strangers are extremely common. A profile with few posts, a profile picture of an attractive person, and mutual friends you barely know — these are red flags. Don't accept requests from people you don't know in real life.
Third-party app connections
Every time you use "Login with Facebook" or "Login with Google," you're granting that app access to some of your social profile data. Periodically review which apps have access to your social accounts and revoke anything you no longer use. On Facebook: Settings → Apps and Websites. On Google: myaccount.google.com → Third-party apps.
Your Security Checklist
You've covered the concepts. Now turn them into action. This checklist is ordered by impact — do the top items first. Each one makes a real difference.
🔑 Accounts & Passwords
🔒 Two-Factor Authentication
🖥 Devices & Software
🌐 Browsing & Network
📱 Social Media & Privacy
Where to go from here
You now understand how threats work and have the practical habits that protect most people from most attacks. Cybersecurity doesn't require perfection — it requires being harder to attack than the next person. The checklist above achieves that.
If you want to go deeper, these are legitimate next areas to explore:
- Home network security — securing your router, setting up a guest network for IoT devices
- Backups — the 3-2-1 backup strategy (3 copies, 2 different media, 1 offsite)
- Privacy tools — Tor browser, encrypted messaging (Signal), encrypted email (ProtonMail)
- Threat modeling — thinking systematically about who specifically might target you and why