130+ security best practices across 8 categories. Track your progress below.
In today's interconnected world, cybersecurity is no longer optional—it is essential. Every day, millions of cyber attacks target individuals and organizations, ranging from phishing scams to ransomware and identity theft. A single compromised account can lead to financial loss, reputational damage, and emotional distress.
This comprehensive checklist is designed to help you systematically evaluate and improve your security posture across all critical areas. By following these 130+ best practices, you can significantly reduce your risk of becoming a victim of cybercrime.
The 3-2-1 backup strategy is the gold standard for data protection. It means keeping 3 copies of your data (the original plus two backups), stored on 2 different types of storage media, with at least 1 backup stored offsite. This strategy protects against hardware failure, theft, natural disasters, and ransomware attacks.
Modern variations recommend adding a "1-0-0" rule: 1 offline backup, 0 errors verified, and 0 trust for cloud-only solutions. Always test your backups by performing regular restore drills.
SPF (Sender Policy Framework) specifies which mail servers are authorized to send email on behalf of your domain. It prevents sender address forgery.
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to your emails, allowing recipients to verify that the message was not altered in transit and genuinely originated from your domain.
DMARC (Domain-based Message Authentication, Reporting, and Conformance) builds on SPF and DKIM, providing instructions to receiving mail servers on how to handle emails that fail authentication checks (none, quarantine, or reject).
No. Your checklist progress is saved only in your browser's localStorage. No data is sent to any server. Clearing your browser data will reset your progress.
We recommend reviewing the checklist at least quarterly, or whenever you set up a new device, change jobs, or experience a security incident. Technology and threats evolve rapidly, so staying current is essential.
Not necessarily. Some items may not apply to your specific situation (e.g., enterprise email authentication for personal users). Focus on the items relevant to your threat model and risk tolerance. However, the more items you complete, the more secure you will be.
A password manager securely stores all your passwords in an encrypted vault, requiring you to remember only one master password. It generates strong, unique passwords for each account, eliminating the dangerous practice of password reuse. Popular options include Bitwarden, 1Password, and KeePass.