Phishing
- Verify sender addresses before acting
- Don't click links in unsolicited mail
- Use email filtering and MFA
Spear Phishing
- Be skeptical of unexpected, personalized requests
- Verify through a second channel
- Limit personal info shared online
Watering Hole
- Keep browser and plugins updated
- Use ad and script blockers
- Avoid suspicious or niche sites
Drive-By Downloads
- Patch OS, browser and plugins
- Run reputable antivirus or EDR
- Disable autoplay and unused plugins
Credential Stuffing
- Never reuse passwords across accounts
- Use a password manager
- Enable MFA on every account
Strong Auth
- Turn on multi-factor everywhere
- Prefer app or hardware keys over SMS
- Rotate exposed credentials fast
Stay Skeptical
- Treat unexpected requests as suspect
- Confirm urgency through another channel
- Slow down before clicking
Reduce Exposure
- Share less personal data publicly
- Audit account permissions regularly
- Keep software current and minimal