Why building habits before a breach matters
Most people think about digital security reactively — after an unauthorized charge appears, after a password is stolen, or after an email account sends spam to everyone in their contacts. By that point, the damage is already in progress.
The practices that provide the most protection aren't complicated. They're straightforward habits that take minutes to set up but offer durable, ongoing coverage. Whether you're new to thinking about online safety or looking to shore up gaps, the list below covers the steps most worth taking — and why each one holds up over time. For a broader foundation, the Internet Essentials hub covers how to navigate the web wisely from the ground up.
These are preventive habits, not guarantees
No set of digital safety practices can guarantee that you'll never experience fraud, a breach, or account compromise. What these steps do is reduce your exposure and speed up your response when something does go wrong. Think of them as layers of protection rather than a single solution.
Seven digital safety practices to build now
Start with two changes, not ten
Trying to overhaul all your digital habits at once often leads to none of them sticking. Pick the two practices in this list that address your biggest gaps — likely account alerts and a password manager — and get those working before moving on. Consistency matters more than comprehensiveness.
Turn on real-time alerts for every financial account
Most banks, credit unions, and credit card issuers allow you to set up push notifications or email alerts for transactions above a threshold you choose. Setting that threshold to one dollar means you see every charge as it happens — not when your statement arrives weeks later.
This single habit is often what separates someone who catches fraud within hours from someone who discovers it months after the damage is done. Log into each financial account's settings and look for a section labeled Notifications or Alerts. Enable both transaction alerts and login notifications wherever the option exists.
A one-dollar alert threshold means you see every charge as it posts — not weeks later.
Use a password manager instead of memorizing credentials
Password reuse remains one of the leading causes of account compromise. When one site suffers a breach, attackers test those same credentials across hundreds of other services automatically — a technique called credential stuffing.
A password manager generates and stores long, unique passwords for every account, so you only need to remember one strong master passphrase. Most also flag if a saved password appears in a known data breach. See our guide to password habits for a deeper breakdown of what puts accounts at risk and how to fix it.
Credential stuffing turns one breached site into dozens of compromised accounts if you reuse passwords.
Enable two-factor authentication on priority accounts
Two-factor authentication (2FA) requires a second proof of identity — typically a time-sensitive code — in addition to your password. Even if an attacker has your password, they cannot log in without that second factor.
Start with the accounts that matter most: email, banking, and any account tied to payment information. Authenticator apps (which generate codes locally on your device) are generally more secure than SMS-based codes, though either option is significantly better than no 2FA at all. Our article on why strong passwords still get compromised explains why this layer matters even when your credentials are solid.
An authenticator app adds a second lock that a stolen password alone cannot open.
Know where to report fraud before you need to
In a crisis, hunting for the right reporting channel wastes critical time. Bookmark these resources now:
- Federal Trade Commission (FTC): ReportFraud.ftc.gov for identity theft and consumer fraud.
- Internet Crime Complaint Center (IC3): ic3.gov for cybercrime and online scams.
- Your state attorney general's office: handles local consumer fraud complaints.
- Your bank's fraud line: typically printed on the back of your debit or credit card.
Reporting quickly doesn't guarantee recovery, but it creates an official record and helps authorities identify patterns affecting other consumers.
Bookmarking fraud reporting resources now means faster action when every minute matters.
Audit app permissions on your devices periodically
Apps frequently request access to your location, contacts, microphone, or camera — often beyond what their core function requires. Those permissions can persist long after you've stopped using the app actively.
On both iOS and Android, you can review which apps hold which permissions in your device's Privacy or Permissions settings. Revoke access that seems unnecessary, and delete apps you no longer use. For a structured approach to finding and closing these gaps, the Online Safety Audit checklist walks through the full process.
Unused apps holding active permissions are a silent data leak you can close in minutes.
Place a credit freeze if you're not actively borrowing
A credit freeze restricts access to your credit report, making it significantly harder for someone to open new accounts in your name. You can place and lift a freeze for free at each of the three major credit bureaus — Equifax, Experian, and TransUnion — at any time.
Unlike a fraud alert, which flags your file for additional verification, a freeze outright blocks most new credit inquiries. If your personal information has ever appeared in a data breach — which, statistically, is likely for many Americans — a credit freeze is one of the most concrete protective steps available. It's worth reviewing alongside broader strategies for protecting personal information online.
A credit freeze blocks most new credit inquiries entirely — and it costs nothing to place or lift.
Reduce your digital footprint on data broker sites
Data brokers are companies that collect, package, and sell personal information — your name, address, phone number, relatives, and more — often without your knowledge. This information can be used by scammers to make phishing attempts sound convincingly personal.
You can request removal from many of these databases directly, though the process is manual and requires repetition over time. Our digital footprint audit guide outlines how to find where your information appears and what removal steps look like in practice.
Personal data on broker sites makes phishing attacks more convincing — removal reduces that risk.
Putting it into practice
The most effective digital safety routine is one you'll actually maintain. None of these steps require technical expertise — they require intention and a few hours of initial setup. Once in place, most of them run quietly in the background, alerting you when something looks off or blocking threats before they reach you.
If you have children who use devices or online accounts, extending these habits to their digital lives is equally important. Our overview of keeping children safer online covers the specific considerations for younger users. And if you want to take stock of where your personal information already exists across the web, start with a practical digital footprint audit to see the full picture before deciding where to focus.




