Skip to content

40 β€” Security Hygiene β€” The 20% That Stops 80%

Level: Beginner Β· Time: ~18 min Β· Prerequisites: Lesson 39 β€” Purple Team Drills and Detection Validation


Why this matters

Look at how real intrusions succeed and the list is almost insultingly dull: a service that was never patched, a password reused from a breach three years ago, an account with no second factor, a backup that turned out not to exist. Almost none of them required the attacker to be clever. The uncomfortable arithmetic is that hygiene done consistently beats advanced tooling done occasionally β€” a well-configured SIEM watching an unpatched, singly-authenticated estate is a very good record of a successful breach. This lesson is the short list that removes most of the opportunity, and the routine that makes it survivable for a normal person with a job to do.

One framing before the list: hygiene is engineering and process, not a character judgement. When a colleague clicks a phishing link, the interesting question is not about them β€” it is why the link was delivered, why one click was enough, and why nobody was notified in five minutes. Blame is not a control.


The ten items, and what each one is for

Item Why it matters What it stops Time to do
Patch everything, with automatic updates where possible most successful exploitation is of a flaw whose fix already exists known-vulnerability exploitation, the single largest initial-access category an hour to set up, near-zero to keep
Multi-factor authentication on the accounts that matter a stolen password stops being enough on its own credential stuffing, password spraying, most phishing minutes per account
Backups with one copy offline or immutable, and a restore you have tested turns a destructive incident into an inconvenience ransomware impact, accidental deletion, destructive insider action an hour to set up, one test a year
No local administrator rights for daily use, and a separate admin account limits what a single compromised session can do malware installation, driver-level attacks, wide lateral movement an afternoon, once
A password manager makes unique passwords per site practical rather than aspirational reuse, which is what makes one breach become five an hour to migrate
Full-disk encryption on laptops and phones the device leaving your control no longer means the data does theft and loss built into most modern systems, an hour to verify
Screen lock, and never leaving a live session unattended a walk-up attacker needs no exploit at all shoulder-surfing, unattended-session abuse, physical access seconds
Easy phishing reporting plus awareness turns every employee into a sensor instead of a victim dwell time β€” reports arrive in minutes, not months minutes per person
Delete or disable unused accounts and services every forgotten account and listening service is an unowned way in credential reuse, old-service exploitation, forgotten test accounts an hour a quarter
Keep firmware and routers current the device in front of everything is also a computer that needs patching router compromise, using your own gateway against you an hour a year, plus a check list

Two of these deserve the longer explanation.

Email is the master key. Almost every other service you use will let you reset its password through your mailbox. That means compromising email is not a single account loss β€” it is a route into every account that trusts it. So practical ordering is email first, then cloud and identity, then finance, then remote access, then administrative accounts. And the highest-value upgrade in this entire list is a phishing-resistant factor on that mailbox: a passkey or hardware security key, which cannot be relayed by a fake login page and has no one-time code to steal. Lesson 20 covers deployment; everything else in the list is worth less than this one item.

Backups are the difference between an incident and an existential event. Everything else on the list reduces the chance of a bad day; backups determine whether the bad day is survivable. The requirements are specific and each one is there for a reason: at least three copies, on two kinds of media, with one offline or immutable so that malware with your credentials cannot encrypt or delete it, and a restore you have actually tested β€” because an untested backup is a hypothesis, and the worst moment to discover it was wrong is during an incident. Lesson 21 covers the design.


Personal hygiene versus organisational hygiene

What an individual can fix What needs a process, an owner and a budget
Fixing your own MFA, password manager, device encryption, screen lock, updates on your equipment estate-wide patching, identity policy, backup infrastructure, account lifecycle
Timescale an evening weeks, with a decision-maker
Blocker your own attention competing priorities and no single owner
Evidence you can check it yourself needs reporting and review to be believed

Most people reading this lesson can do the left column tonight, and should. But an organisation's hygiene is not the sum of its employees' good intentions: it is the right column, which needs a named owner, a date and money β€” and it needs someone to keep it true after the person who set it up has moved on. That gap is precisely why the next three lessons exist: Lesson 41 for the home network, Lesson 42 for the lab, and Lesson 43 for the small business playbook. Detection, meanwhile, is Lesson 44, and the response playbooks for when hygiene was not enough are Lesson 45.


The routine that makes it sustainable

A big annual clean-up fails. A small pass that always happens does not. Two scheduled sessions are enough.

Monthly, 30 minutes:

  1. Install pending updates on every device you own and check that automatic updates are actually enabled rather than assumed.
  2. Open the backup destination and confirm there is a recent, complete copy β€” including the offline or immutable one.
  3. Check the accounts with a second factor: anything new without one gets it, and anything that uses SMS only is on the list to upgrade.
  4. Review who has access: any account, sharing link or device you no longer need.
  5. Check the router and any other internet-facing box for firmware updates.
  6. Skim your sign-in history and recent-security-events page for anything you do not recognise.

Annually, two to three hours:

  1. Restore test. Recover real files, or a whole machine, from backup into a scratch location and open them. Write down the date.
  2. Access review. Every account you own, who or what can reach it, and whether the administrative privileges are still justified.
  3. Remove the dead wood. Old accounts, trial services, devices, forwarding rules, application passwords, and API keys nobody remembers creating.
  4. Re-check encryption and lock screens on any device added during the year.
  5. Update your recovery plan: who you would contact, what you would do first, and where the instructions live if your laptop is gone.
  6. Review the numbers from the next section, and decide the one thing you will fix before the next review.

[!TIP] Put both passes in the calendar as recurring appointments with a reminder, and treat the annual restore test like an appointment you cannot move. A hygiene routine that depends on remembering to do it is a routine that stops in month three.


Measure it, do not assert it

"We have antivirus" and "we are too small to be targeted" are the two sentences that most reliably precede an incident. Replace assertions with numbers that can be checked.

Metric worth watching Why it is the right number
Percentage of assets patched within a stated window a stated window makes it a commitment; the percentage makes it measurable
Percentage of accounts with a second factor, by tier email and admin tiers should be at or near all, and you will see where the gap is
Date of the last successful restore test an untested backup is a hope; the date is the evidence
Number of accounts with local administrator rights the smaller this number, the smaller every compromise becomes
Number of unused accounts removed this quarter shows whether the lifecycle is a process or a good intention
Median time from phishing report to containment the honest measure of how much your reporting route is worth

Anti-metrics to avoid, and why:

  • "We have antivirus." A control you installed is not a measurement of whether it works.
  • "We are too small to be targeted." Most intrusions are opportunistic and untargeted; size is not a defence.
  • "We blocked X attacks this month." A number that goes up when you add a noisy sensor tells you nothing about your exposure.
  • "Everyone has completed training." Completion is attendance; report rate and click rate over time are behaviour.

Anti-patterns

  • Relying on a single control. One control is one failure away from none. Two MFA-enforced accounts and an unencrypted laptop is not a defence-in-depth story; it is a coin flip.
  • Security theatre. Recurring activity that changes nothing an attacker experiences β€” a policy nobody reads, a training quiz completed in four minutes, a risk register with no owners. It creates the feeling of progress and consumes the budget that would have paid for a real fix.
  • Complexity so heavy that people disable it. If the policy makes the work impossible, it will be bypassed, and the bypass will be quiet and undocumented. Usable security is not a compromise on security β€” unworkable security is a prediction of non-compliance.
  • A blame culture. Punishing the person who clicked is how you get zero reports and therefore zero early warnings. You need a reporting route people are not afraid to use, because the fastest detection you will ever have is a colleague who says "I think I did something wrong, ten minutes ago".
  • One big clean-up a year. A heroic weekend of patching and tidying decays within weeks. Small, regular passes hold; annual clean-ups fade, and they usually only happen after something has gone wrong.

Habits, no blame, and the checklist

Habits beat heroics because the attacker's advantage is repetition: they only have to find the one unpatched host, while you have to hold the whole estate. A monthly pass that takes thirty minutes reliably outperforms a project that would fix everything perfectly and never gets rescheduled after the first quarter.

The no-blame reporting culture is a security control, not a nicety. Reports arrive sooner when people are not punished for making them, and earlier is the whole game: a report at ten minutes is a password reset plus an MFA reset; the same report found six weeks later, in a log review, is an incident with legal obligations attached.

SECURITY HYGIENE β€” personal and small team checklist
Review date: __ / __ / ____        Next review: __ / __ / ____

  [ ]  1. Updates installed; automatic updates verified as ON
  [ ]  2. Email account protected with MFA (passkey or hardware key preferred)
  [ ]  3. MFA on cloud, finance, VPN and administrative accounts
  [ ]  4. Backups: three copies, two media, one offline or immutable
  [ ]  5. Restore tested this year β€” date tested: __ / __ / ____
  [ ]  6. No local admin rights for daily use; separate admin account exists
  [ ]  7. Password manager in use; no password reused between accounts
  [ ]  8. Full-disk encryption enabled on laptop and phone
  [ ]  9. Screen lock on, short timeout, no unattended sessions
  [ ] 10. Phishing report route known, one click, and no blame attached

  Numbers this month:  patched in window __%  |  accounts with 2FA __%
                       last restore test __/__/__  |  unused accounts removed __

  The one thing I will fix before the next review: ______________________

Attack it / Defend it

The attack How it works The control that stops it
Credential stuffing passwords leaked from another breach, replayed against your accounts unique passwords from a manager, plus MFA on anything that matters
Password spraying one common password against many accounts, under lockout thresholds MFA first, and MFA on the email account before anything else
Exploiting an unpatched service a flaw with a fix that was never applied automatic updates, plus a stated patch window you can measure
Phishing with a fake login page a convincing page collects the password and the one-time code phishing-resistant factors, and a reporting route that produces minutes, not months
Ransomware encrypts everything it can reach and demands payment offline or immutable backup with a tested restore, and no standing local admin rights
A stolen laptop physical access to a device that was never locked full-disk encryption, screen lock, and remote device management
Session left unlocked someone sits at your machine and acts as you, with no exploit at all screen lock on a short timeout, and locking when you leave
A forgotten account or service an old account or listening service nobody owns is reused to get in quarterly review that deletes and disables, and an inventory of what is actually exposed
Your own router used against you firmware that was never updated, on the device in front of everything current firmware, changed default credentials, and no unnecessary exposure to the internet
Malware surviving on one control alone the endpoint tool did not detect it, and nothing else was in the way several independent layers, so no single detection has to be perfect

Key takeaways

  • Almost every intrusion uses the basics: an unpatched service, a reused password, no second factor, no backup. Hygiene done consistently beats advanced tooling done occasionally.
  • Email is the master key, because it is the reset route for everything else β€” so it gets a second factor first, and ideally a phishing-resistant one.
  • Backups decide whether a bad day is survivable. Three copies, two media, one offline or immutable, and a restore you have actually performed.
  • Measure, do not assert. Patched-in-window percentage, accounts with a second factor, the date of the last restore test, the count of accounts with local admin, unused accounts removed.
  • Habits beat heroics, and no blame beats punishment. Useable policy gets followed, and reporters who are not punished report sooner, which is where detection actually starts.

Check yourself

  1. Why is the email account the first thing to protect, and what kind of second factor does the most for it?
  2. State the backup requirement as three copies, two media and one offline or immutable β€” and explain what a restore test adds that the backup itself does not.
  3. Give one metric that genuinely measures hygiene and one anti-metric that only sounds like it, and say why the anti-metric misleads.
  4. Your organisation's new policy makes a routine task take three times as long. What will happen, and what does that tell you about how to write it?
  5. Someone reports a phishing click ten minutes after doing it. Why is that outcome better for the organisation than the same click discovered in a log review six weeks later?

Next

Lesson 41 β€” Securing a Home Network