# GET YOURSELF SECURED **An interactive security field manual for people, businesses, organisations, government teams, and defence environments.** [![Version](https://img.shields.io/badge/version-2026.3-31d7a4?style=for-the-badge)](#mission-map) [![Missions](https://img.shields.io/badge/missions-133-f4b860?style=for-the-badge)](#mission-map) [![Modules](https://img.shields.io/badge/modules-13-7aa2ff?style=for-the-badge)](#mission-map) [![XP](https://img.shields.io/badge/available_XP-2545-ef6f6c?style=for-the-badge)](#rank-system) [Launch the interactive academy](https://parthxd3-operations.parthxd3.chatgpt.site/#security-academy)
> [!IMPORTANT] > This field manual improves security and privacy but cannot guarantee safety. Tailor controls to your threat model, accessibility needs, legal duties, employer rules, data classification, and formally authorized government or defence policy. It is not a substitute for professional incident response, legal advice, or an approved security programme. ## Start Here: The Universal Baseline 1. Use unique credentials from a password manager and prefer passkeys where available. 2. Turn on strong multi-factor authentication for every important account. 3. Learn to pause and verify suspicious messages, links, requests, and downloads. 4. Keep devices, browsers, apps, routers, and smart devices supported and updated. 5. Maintain isolated backups and prove that important data and services can be restored. 6. Know who owns the decision, how incidents are reported, and which authority applies. These priorities follow current CISA and NIST guidance, then expand into privacy, governance, supply-chain assurance, response, recovery, and mission resilience. ## Choose Your Playbook Every role-specific playbook includes the Universal Baseline plus missions written for that operating context. | Track | Operating focus | Included missions | |---|---|---:| | **Baseline** | Identity / devices / recovery | 95 | | **Personal** | Identity / privacy / safety | 110 | | **Business** | Continuity / fraud / suppliers | 128 | | **Organisation** | Governance / scale / assurance | 129 | | **Government** | Public trust / policy / continuity | 132 | | **Defence** | Mission / classification / resilience | 132 | ### Audience Briefings - **Universal Security Baseline:** Start with the controls that protect ordinary accounts, devices, communications, networks, data, and recovery paths. - **Personal Security Playbook:** Protect your identity, money, private communications, home technology, and ability to recover without turning daily life into a full-time security job. - **Business Resilience Playbook:** Reduce the most common operational risks with accountable ownership, strong access controls, recoverable backups, supplier checks, and an incident plan people can actually use. - **Organisation Security Programme:** Coordinate governance, identity, assets, data, vendors, monitoring, response, and improvement across teams and shared technology. - **Government Security Practice:** Apply approved policy, official reporting paths, data classification, auditable administration, supply-chain assurance, and continuity requirements to public systems and services. - **Defence Mission Assurance:** Protect mission systems through authorized controls, strict trust boundaries, classified-data handling, resilient operations, evidence preservation, and command-approved escalation. ## Simple Security Journey 28 beginner-friendly steps arranged in 6 short phases. Complete one action at a time; the interactive academy automatically opens the next step. ### Phase 1 // Protect your digital keys > Stop one stolen password from unlocking your whole life. **Suggested time: 30-45 minutes.** - [ ] **Adopt a reputable password manager:** Store credentials in an encrypted password manager instead of notes, spreadsheets, chat messages, or reused memory patterns. - [ ] **Use a unique secret for every account:** Replace reused passwords, starting with email, banking, cloud storage, social media, and your password manager. - [ ] **Enable MFA on critical accounts:** Start with primary email, password manager, banking, cloud storage, developer accounts, social media, and mobile carrier accounts. - [ ] **Store backup codes offline or encrypted:** Keep one recovery-code copy in an encrypted vault or locked physical location, separate from your everyday device. ### Phase 2 // Lock your phone and computer > Keep supported devices encrypted, updated, and difficult to open. **Suggested time: 45-60 minutes.** - [ ] **Install OS and app updates promptly:** Enable automatic security updates and replace devices that no longer receive vendor patches. - [ ] **Use a strong device lock:** Choose a longer PIN or password, shorten auto-lock, and use biometrics for convenient local unlock where appropriate. - [ ] **Confirm device encryption:** Keep the screen lock enabled and verify storage encryption on devices where it is not automatic. - [ ] **Keep the operating system supported and updated:** Enable automatic security updates for the OS, browser, drivers, and major applications; replace unsupported versions. - [ ] **Enable full-disk encryption:** Turn on BitLocker, FileVault, LUKS, or the supported platform equivalent and store the recovery key separately. ### Phase 3 // Browse and message safely > Recognize the common tricks used to steal access, money, and files. **Suggested time: 30-45 minutes.** - [ ] **Keep the browser updated automatically:** Enable automatic browser updates and restart when an update is waiting. - [ ] **Keep extensions to a minimum:** Remove extensions you do not need and review each remaining extension's publisher, update history, and permissions. - [ ] **Verify unexpected requests out of band:** Do not use the message's link or phone number. Open the known site yourself or contact the person through a trusted channel. - [ ] **Treat attachments and shared documents as untrusted:** Confirm the sender and context before opening files, enabling macros, granting OAuth access, or signing in to view a document. - [ ] **Verify every unusual sensitive request:** Pause before sending money, credentials, codes, files, or urgent access; confirm through a known independent channel. ### Phase 4 // Secure accounts and home Wi-Fi > Close easy entry points around social accounts, routers, and wireless access. **Suggested time: 45-60 minutes.** - [ ] **Change default router administrator credentials:** Set a unique admin password and disable remote administration unless you have a specific secured need. - [ ] **Use WPA3 or WPA2-AES:** Choose WPA3-Personal when all devices support it, otherwise WPA2-AES, with a long unique Wi-Fi passphrase; do not use WEP or legacy WPA. - [ ] **Keep router firmware supported and updated:** Enable automatic updates or check the vendor regularly; replace hardware that no longer receives security fixes. - [ ] **Review audience and discovery settings:** Limit who can see posts, find you by phone or email, tag you, or view your contacts and friend list. - [ ] **Enable strong MFA and login alerts:** Use a passkey or security key when supported and review alerts for unfamiliar logins. ### Phase 5 // Prepare for loss or compromise > Make sure a lost device, broken account, or ransomware event is recoverable. **Suggested time: 45-60 minutes.** - [ ] **Follow a 3-2-1 backup plan:** Keep three copies of important data, on two storage types, with one offline or off-site; encrypt sensitive backups and test restores. - [ ] **Create an encrypted, tested backup:** Back up critical data and authenticators, protect the backup account with MFA, and test recovery before replacing the phone. - [ ] **Enable find, lock, and remote erase:** Turn on the platform's recovery service, verify the account credentials, and record the device identifier or serial number. - [ ] **Write a one-page incident plan:** List how to freeze payments, secure email and phone accounts, revoke sessions, restore backups, contact trusted people, preserve evidence, and report abuse. ### Phase 6 // Keep yourself secure > Use a short routine so security does not quietly decay over time. **Suggested time: 10 minutes each month.** - [ ] **Install maintained software from official sources:** Verify the publisher and domain, remove unused applications, and replace software that no longer receives patches. - [ ] **Lock devices whenever they leave your control:** Use automatic locking, keep devices with you in public, and remotely lock or erase a lost device. - [ ] **Collect and share less data:** Delete files, accounts, scans, and messages you no longer need; avoid providing optional identity fields and restrict public records where lawful. - [ ] **Review permissions twice a year:** Audit apps, browser sites, cloud integrations, sharing links, location history, advertising settings, and third-party data sharing. - [ ] **Run a quarterly security review:** Check updates, backups, recovery contacts, exposed data, old accounts, connected devices, and the next three highest-risk improvements. ## Mission Map | # | Module | Focus | Missions | XP | |---:|---|---|---:|---:| | 01 | [Passwords and Recovery](#passwords) | Make every credential unique, recoverable, and difficult to replay. | 9 | 175 | | 02 | [MFA and Passkeys](#mfa) | Add a phishing-resistant layer to every account that matters. | 8 | 155 | | 03 | [Browser and Search](#browser) | Reduce tracking and shrink the attack surface of your daily gateway. | 10 | 200 | | 04 | [Email Defence](#email) | Protect the account that can reset almost everything else. | 8 | 145 | | 05 | [Social Media](#social) | Publish deliberately and make impersonation harder. | 8 | 150 | | 06 | [Networks and Routers](#networking) | Secure the infrastructure every device quietly trusts. | 10 | 190 | | 07 | [Mobile Devices](#mobile) | Protect the device that carries your identity, location, and authenticators. | 10 | 200 | | 08 | [Personal Computers](#computers) | Harden the workstation where your most valuable work lives. | 10 | 195 | | 09 | [Smart Home and IoT](#smart-home) | Keep convenience devices away from identity and critical infrastructure. | 10 | 195 | | 10 | [Sensible Computing](#habits) | Turn security from a product into a calm, repeatable habit. | 12 | 225 | | 11 | [Governance and Risk](#governance) | Turn security from scattered tools into owned, measurable decisions. | 12 | 225 | | 12 | [Incident Response and Resilience](#resilience) | Prepare calm decisions, preserve evidence, and restore the mission safely. | 13 | 245 | | 13 | [Software and Security Hardware](#technology) | Choose maintained, verifiable controls and deploy specialist hardware lawfully. | 13 | 245 | ## Rank System | Completion | Rank | Operating idea | |---:|---|---| | 0-19% | Initiate | Establish the basics without chasing perfection. | | 20-39% | Sentinel | Protect the accounts and devices with the largest impact. | | 40-64% | Guardian | Build recovery, isolation, and repeatable review habits. | | 65-84% | Vanguard | Harden edge cases and reduce unnecessary exposure. | | 85-100% | Fortress | Maintain the system and adapt it to a personal threat model. | Priority is not severity. **Core** missions have the widest benefit, **Recommended** missions improve resilience, and **Advanced** missions need more context or maintenance. ## 01 // Passwords and Recovery > Make every credential unique, recoverable, and difficult to replay. **9 missions / 175 XP** - [ ] **Adopt a reputable password manager**   `CORE`   **+20 XP** TRACK: ALL TRACKS Store credentials in an encrypted password manager instead of notes, spreadsheets, chat messages, or reused memory patterns.
WHY: A manager makes unique credentials practical and reduces reuse across accounts. Modern browser-integrated managers can also be appropriate when the device account is strongly protected. - [ ] **Use a unique secret for every account**   `CORE`   **+20 XP** TRACK: ALL TRACKS Replace reused passwords, starting with email, banking, cloud storage, social media, and your password manager.
WHY: A breach at one service should not unlock the rest of your digital life. - [ ] **Use long random passwords or passphrases**   `CORE`   **+20 XP** TRACK: ALL TRACKS Let your manager generate passwords of at least 16 characters. When memorization is required, use a long passphrase made from several unrelated words.
WHY: Length and unpredictability matter more than forced symbol substitutions or frequent cosmetic changes. - [ ] **Prefer passkeys when available**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Create passkeys on trusted devices for important services and protect the device account with strong recovery controls.
WHY: Properly implemented passkeys are phishing-resistant and do not send a reusable password to the service. - [ ] **Treat recovery answers like passwords**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Generate random answers for security questions and save them in your manager; do not use facts discoverable from social media.
WHY: Public biographical details make truthful recovery answers easy to guess. - [ ] **Avoid signing in on public or borrowed devices**   `CORE`   **+20 XP** TRACK: ALL TRACKS Use your own trusted device. If an emergency forces you to use another device, avoid sensitive accounts, do not save credentials, sign out, and change the password later from a trusted device.
WHY: Private browsing does not protect against malware, keyloggers, or device administrators. - [ ] **Create a credential breach routine**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS When a service reports a breach, change that account's password, revoke sessions, review recovery methods, and replace any reused credential immediately.
WHY: Fast containment limits account takeover and credential-stuffing attacks. - [ ] **Back up your password vault recovery path**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Keep an encrypted export or documented emergency-access plan in a physically secure place and test that it can be restored.
WHY: Strong security should not turn device loss or incapacity into permanent account loss. - [ ] **Separate high-value and everyday identities**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Use distinct email addresses or profiles for recovery-critical accounts, work, shopping, newsletters, and public communities.
WHY: Compartmentalization limits profiling, spam, and the impact of one compromised identity. ## 02 // MFA and Passkeys > Add a phishing-resistant layer to every account that matters. **8 missions / 155 XP** - [ ] **Enable MFA on critical accounts**   `CORE`   **+20 XP** TRACK: ALL TRACKS Start with primary email, password manager, banking, cloud storage, developer accounts, social media, and mobile carrier accounts.
WHY: A second factor can stop an attacker who has obtained your password. - [ ] **Choose phishing-resistant authentication**   `CORE`   **+20 XP** TRACK: ALL TRACKS Prefer passkeys or FIDO2/WebAuthn security keys when a service supports them.
WHY: These authenticators bind sign-in to the legitimate site and resist credential replay. - [ ] **Use an authenticator app when passkeys are unavailable**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Use a maintained TOTP authenticator and protect its backup or sync account with strong authentication.
WHY: App-generated codes usually provide stronger protection than SMS, though they can still be phished. - [ ] **Treat SMS as a fallback, not the goal**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Replace SMS MFA with a passkey, security key, or authenticator app where possible; keep SMS rather than disabling MFA entirely when no stronger choice exists.
WHY: SIM swapping and message interception make SMS weaker, but it is generally better than password-only access. - [ ] **Store backup codes offline or encrypted**   `CORE`   **+20 XP** TRACK: ALL TRACKS Keep one recovery-code copy in an encrypted vault or locked physical location, separate from your everyday device.
WHY: Recovery codes prevent lockout when a phone or key is lost without weakening normal sign-in. - [ ] **Register a second security key or recovery device**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Keep a spare authenticator in a separate secure location and label it without exposing account details.
WHY: Redundancy protects against loss, theft, and hardware failure. - [ ] **Review sessions and authenticators quarterly**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Remove old devices, stale passkeys, unused app passwords, and unknown sessions from account security settings.
WHY: Old access paths often survive long after a device is sold, lost, or reassigned. - [ ] **Test recovery before an emergency**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Confirm that backup codes, alternate authenticators, and recovery contacts work without removing your current access.
WHY: An untested recovery plan is only a theory. ## 03 // Browser and Search > Reduce tracking and shrink the attack surface of your daily gateway. **10 missions / 200 XP** - [ ] **Keep the browser updated automatically**   `CORE`   **+20 XP** TRACK: ALL TRACKS Enable automatic browser updates and restart when an update is waiting.
WHY: Browsers process hostile internet content, so delayed security patches carry real risk. - [ ] **Enable HTTPS-only mode**   `CORE`   **+20 XP** TRACK: ALL TRACKS Turn on the browser's built-in HTTPS-only setting and leave sites that cannot provide a secure connection when sensitive data is involved.
WHY: HTTPS protects traffic in transit, although it does not prove a site is trustworthy. - [ ] **Keep extensions to a minimum**   `CORE`   **+20 XP** TRACK: ALL TRACKS Remove extensions you do not need and review each remaining extension's publisher, update history, and permissions.
WHY: Extensions can read or modify pages and may become dangerous after ownership or permission changes. - [ ] **Use reputable content and tracker blocking**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Enable built-in tracking protection or one well-maintained content blocker; avoid stacking many overlapping extensions.
WHY: Reducing third-party scripts limits tracking and exposure to malicious advertising. - [ ] **Verify downloads before opening them**   `CORE`   **+20 XP** TRACK: ALL TRACKS Use the vendor's official site or app store, confirm the domain, and scan unexpected files with your endpoint protection or a reputable multi-engine service when appropriate.
WHY: Search ads, cloned sites, and bundled installers are common malware delivery paths. - [ ] **Review browser privacy settings**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Block third-party cookies where practical, clear unnecessary site permissions, and disable background access you do not use.
WHY: Old permissions and cross-site identifiers can expose data long after a visit. - [ ] **Choose a search provider that fits your privacy needs**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Review retention, personalization, account linking, and jurisdiction instead of relying only on a provider's marketing label.
WHY: Search queries can reveal health, financial, political, and personal interests. - [ ] **Consider encrypted DNS**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Use a trusted DNS-over-HTTPS or DNS-over-TLS resolver when it improves your network privacy and does not conflict with workplace or family safety controls.
WHY: Encrypted DNS reduces local observation and tampering but moves trust to the chosen resolver. - [ ] **Separate activities with browser profiles**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Use distinct profiles or browsers for work, personal accounts, research, and higher-risk browsing.
WHY: Compartmentalization limits cookie sharing and reduces the blast radius of a compromised profile. - [ ] **Use Tor only when its threat model fits**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Use the official Tor Browser for anonymity-sensitive browsing, understand its limits, and avoid changing defaults without a clear reason.
WHY: Tor can reduce network-level linkability, but account logins, downloads, behavior, and endpoint compromise can still identify you. ## 04 // Email Defence > Protect the account that can reset almost everything else. **8 missions / 145 XP** - [ ] **Harden your primary email first**   `CORE`   **+20 XP** TRACK: ALL TRACKS Use a unique password, phishing-resistant MFA, current recovery methods, and login alerts on the inbox used for account recovery.
WHY: Control of primary email often enables password resets across many services. - [ ] **Separate recovery mail from subscriptions**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Keep high-value account recovery away from newsletters, public profiles, shopping, and low-trust signups.
WHY: Separation reduces phishing noise and hides your most valuable login identifier. - [ ] **Use aliases for signups**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Give services unique aliases when your provider supports them and disable an alias if it starts receiving abuse.
WHY: Aliases reveal which service shared or leaked an address and make unwanted mail easier to contain. - [ ] **Verify unexpected requests out of band**   `CORE`   **+20 XP** TRACK: ALL TRACKS Do not use the message's link or phone number. Open the known site yourself or contact the person through a trusted channel.
WHY: Sender names, domains, invoices, and reply chains can all be spoofed or compromised. - [ ] **Limit automatic remote content**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Disable automatic remote images for untrusted senders when your mail client supports it.
WHY: Remote content can confirm that an address is active and reveal timing or network metadata. - [ ] **Treat attachments and shared documents as untrusted**   `CORE`   **+20 XP** TRACK: ALL TRACKS Confirm the sender and context before opening files, enabling macros, granting OAuth access, or signing in to view a document.
WHY: Malicious attachments and fake cloud-share pages are common initial-access techniques. - [ ] **Audit connected apps and forwarding rules**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Remove unused OAuth applications, app passwords, delegates, filters, and forwarding addresses.
WHY: Attackers often create hidden mail rules or retain access through an authorized third-party app. - [ ] **Choose a safer channel for sensitive data**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Use approved end-to-end encrypted or access-controlled tools for secrets, identity documents, and confidential files; set expiry and access limits where possible.
WHY: Ordinary email can be forwarded, retained indefinitely, or read on an insecure recipient device. ## 05 // Social Media > Publish deliberately and make impersonation harder. **8 missions / 150 XP** - [ ] **Review audience and discovery settings**   `CORE`   **+20 XP** TRACK: ALL TRACKS Limit who can see posts, find you by phone or email, tag you, or view your contacts and friend list.
WHY: Default settings often favor reach and discovery over privacy. - [ ] **Assume every post can become public**   `CORE`   **+20 XP** TRACK: ALL TRACKS Avoid publishing information that would cause harm if copied, indexed, screenshotted, or viewed outside the intended audience.
WHY: Privacy controls cannot prevent recipients, platform errors, legal requests, or future policy changes from exposing content. - [ ] **Remove location and identifying metadata**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Disable unnecessary geotagging and review photos for EXIF data, addresses, badges, tickets, screens, reflections, and predictable routines.
WHY: Images can reveal more than the visible subject. - [ ] **Reduce app permissions**   `CORE`   **+20 XP** TRACK: ALL TRACKS Deny contact, microphone, camera, photo, call-log, and location access unless the feature genuinely needs it.
WHY: Unnecessary permissions expand both platform collection and the impact of account or app compromise. - [ ] **Revoke unused connected apps**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Audit games, quizzes, sign-in integrations, bots, and marketing tools connected to each social account.
WHY: Third-party access can outlive the app you originally authorized. - [ ] **Enable strong MFA and login alerts**   `CORE`   **+20 XP** TRACK: ALL TRACKS Use a passkey or security key when supported and review alerts for unfamiliar logins.
WHY: Popular accounts are valuable for scams, impersonation, and recovery attacks. - [ ] **Create an impersonation response plan**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Know each platform's reporting process, reserve key usernames when practical, and tell close contacts how you will verify urgent requests.
WHY: A clear verification path makes cloned-profile scams less effective. - [ ] **Delete or lock dormant accounts**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Export anything needed, remove personal data, revoke apps, and close accounts you no longer monitor.
WHY: Abandoned profiles can leak history or be hijacked without you noticing. ## 06 // Networks and Routers > Secure the infrastructure every device quietly trusts. **10 missions / 190 XP** - [ ] **Change default router administrator credentials**   `CORE`   **+20 XP** TRACK: ALL TRACKS Set a unique admin password and disable remote administration unless you have a specific secured need.
WHY: Default or exposed management access can give an attacker control of the whole network. - [ ] **Use WPA3 or WPA2-AES**   `CORE`   **+20 XP** TRACK: ALL TRACKS Choose WPA3-Personal when all devices support it, otherwise WPA2-AES, with a long unique Wi-Fi passphrase; do not use WEP or legacy WPA.
WHY: Modern Wi-Fi encryption protects local traffic and resists casual access. - [ ] **Keep router firmware supported and updated**   `CORE`   **+20 XP** TRACK: ALL TRACKS Enable automatic updates or check the vendor regularly; replace hardware that no longer receives security fixes.
WHY: Internet-facing routers are attractive targets and unsupported models accumulate known flaws. - [ ] **Disable unused WPS, UPnP, and management services**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Turn off convenience services you do not need and document any port forwards that remain.
WHY: Each exposed discovery or management feature adds attack surface. - [ ] **Isolate guests and smart devices**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Place visitors and untrusted IoT devices on a guest network or separate VLAN that cannot reach personal computers and storage.
WHY: Segmentation prevents one weak device from freely scanning higher-value systems. - [ ] **Use public Wi-Fi defensively**   `CORE`   **+20 XP** TRACK: ALL TRACKS Prefer mobile data for sensitive work, verify the network name, disable sharing, keep HTTPS enabled, and forget the network afterward.
WHY: Hotspots can be impersonated, monitored, or configured to expose nearby devices. - [ ] **Use a VPN for a defined reason**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Choose a reputable provider when you need protection from the local network or approved remote access; remember the VPN provider can observe metadata and a VPN does not make unsafe sites trustworthy.
WHY: A VPN moves trust and changes network visibility; it is not a universal anonymity or malware shield. - [ ] **Review connected devices monthly**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Name known devices, remove stale reservations, investigate unknown clients, and rotate Wi-Fi credentials after unauthorized access.
WHY: An inventory makes unusual connections visible before they become normal background noise. - [ ] **Choose DNS deliberately**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Compare your ISP, router, workplace, filtered, and encrypted DNS options for privacy, security, logging, and reliability.
WHY: DNS choices affect who sees queries and which malicious or inappropriate domains can be blocked. - [ ] **Audit inbound exposure**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Remove unnecessary port forwards, verify host firewalls, and use an authenticated overlay or VPN instead of directly exposing admin panels.
WHY: Services reachable from the internet are continuously scanned and attacked. ## 07 // Mobile Devices > Protect the device that carries your identity, location, and authenticators. **10 missions / 200 XP** - [ ] **Install OS and app updates promptly**   `CORE`   **+20 XP** TRACK: ALL TRACKS Enable automatic security updates and replace devices that no longer receive vendor patches.
WHY: Mobile exploits often target known flaws that already have fixes. - [ ] **Use a strong device lock**   `CORE`   **+20 XP** TRACK: ALL TRACKS Choose a longer PIN or password, shorten auto-lock, and use biometrics for convenient local unlock where appropriate.
WHY: Biometrics can improve everyday lock use but should be backed by a strong device secret and understood in your legal and threat context. - [ ] **Confirm device encryption**   `CORE`   **+20 XP** TRACK: ALL TRACKS Keep the screen lock enabled and verify storage encryption on devices where it is not automatic.
WHY: Encryption reduces data exposure when a powered-off device is lost or stolen. - [ ] **Review permissions and privacy dashboards**   `CORE`   **+20 XP** TRACK: ALL TRACKS Remove background location, contacts, photo-library, Bluetooth, microphone, and accessibility access that apps do not need.
WHY: Excessive permissions reveal sensitive behavior and increase the impact of a compromised app. - [ ] **Install apps from trusted sources**   `CORE`   **+20 XP** TRACK: ALL TRACKS Use the platform store or verified developer distribution, inspect the publisher, and avoid pirated or repackaged apps.
WHY: Sideloaded and counterfeit apps can bypass platform review and update controls. - [ ] **Create an encrypted, tested backup**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Back up critical data and authenticators, protect the backup account with MFA, and test recovery before replacing the phone.
WHY: A usable backup turns theft or failure into a recovery task rather than permanent loss. - [ ] **Enable find, lock, and remote erase**   `CORE`   **+20 XP** TRACK: ALL TRACKS Turn on the platform's recovery service, verify the account credentials, and record the device identifier or serial number.
WHY: Fast remote action can protect data and improve the chance of recovery. - [ ] **Treat unknown USB ports as data connections**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Use your own charger, a power-only cable, or a trusted data blocker and reject unexpected trust prompts.
WHY: A USB connection may carry data as well as power. - [ ] **Know the signs of stalkerware**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Watch for unknown device administrators, accessibility services, profiles, account sessions, location sharing, unusual heat, or battery use; seek specialist help if personal safety is involved.
WHY: Someone with physical or account access may install monitoring tools, and removing them can alert an abuser. - [ ] **Separate work and personal data**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Use managed work profiles, separate user spaces, or dedicated devices when the sensitivity justifies it.
WHY: Isolation limits accidental sharing and the reach of a compromised app or account. ## 08 // Personal Computers > Harden the workstation where your most valuable work lives. **10 missions / 195 XP** - [ ] **Keep the operating system supported and updated**   `CORE`   **+20 XP** TRACK: ALL TRACKS Enable automatic security updates for the OS, browser, drivers, and major applications; replace unsupported versions.
WHY: Patch delay leaves known vulnerabilities available to commodity attacks. - [ ] **Enable full-disk encryption**   `CORE`   **+20 XP** TRACK: ALL TRACKS Turn on BitLocker, FileVault, LUKS, or the supported platform equivalent and store the recovery key separately.
WHY: Encryption protects files when a powered-off computer or drive is stolen. - [ ] **Use a standard account for daily work**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Keep administrator privileges separate and approve elevation only for expected changes.
WHY: Reduced privileges limit what accidental or malicious software can change. - [ ] **Keep the firewall and endpoint protection active**   `CORE`   **+20 XP** TRACK: ALL TRACKS Use the maintained built-in protections or a trusted managed alternative and investigate alerts instead of disabling controls permanently.
WHY: These layers block common malicious behavior and unexpected network exposure. - [ ] **Follow a 3-2-1 backup plan**   `CORE`   **+20 XP** TRACK: ALL TRACKS Keep three copies of important data, on two storage types, with one offline or off-site; encrypt sensitive backups and test restores.
WHY: Backups must survive ransomware, theft, hardware failure, and account loss. - [ ] **Connect only trusted removable hardware**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Avoid unknown USB devices, disable automatic execution, and use dedicated transfer workflows for untrusted media.
WHY: Malicious or compromised peripherals can emulate keyboards, networks, or storage devices. - [ ] **Install maintained software from official sources**   `CORE`   **+20 XP** TRACK: ALL TRACKS Verify the publisher and domain, remove unused applications, and replace software that no longer receives patches.
WHY: Outdated viewers, plugins, installers, and pirated apps create avoidable entry points. - [ ] **Lock the screen and minimize sharing**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Use a short automatic lock, require sign-in on wake, and disable file, printer, remote desktop, and discovery services you do not use.
WHY: Physical access and unnecessary local services can bypass otherwise strong account security. - [ ] **Isolate high-risk work**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Use a sandbox, virtual machine, disposable environment, or dedicated device for untrusted files and specialist tools.
WHY: Containment reduces the chance that one risky task reaches personal data and credentials. - [ ] **Add lightweight breach detection**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS For systems you own, consider monitored canary files or tokens that alert when unexpectedly opened; never place real secrets in them.
WHY: Early warning can shorten the time between intrusion and response. ## 09 // Smart Home and IoT > Keep convenience devices away from identity and critical infrastructure. **10 missions / 195 XP** - [ ] **Check support life before buying**   `CORE`   **+20 XP** TRACK: ALL TRACKS Review the vendor's update policy, data practices, breach history, account security, and what happens if its cloud service closes.
WHY: An inexpensive device can become a permanent unsupported computer inside your home. - [ ] **Replace default credentials and enable MFA**   `CORE`   **+20 XP** TRACK: ALL TRACKS Give every device account a unique password and protect the controlling cloud account with strong MFA.
WHY: Default credentials and shared vendor accounts are common takeover paths. - [ ] **Apply firmware updates**   `CORE`   **+20 XP** TRACK: ALL TRACKS Enable automatic updates where trustworthy, check manually otherwise, and retire devices that stop receiving fixes.
WHY: IoT devices can remain online for years while known vulnerabilities accumulate. - [ ] **Put IoT on an isolated network**   `CORE`   **+20 XP** TRACK: ALL TRACKS Use a guest network or VLAN and allow access to personal devices only when the feature requires it.
WHY: A compromised camera or plug should not be able to scan laptops and storage. - [ ] **Choose strict privacy and retention settings**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Opt out of model training and third-party sharing where possible, shorten cloud retention, and delete recordings you do not need.
WHY: Home devices can capture voices, routines, visitors, children, and precise occupancy patterns. - [ ] **Physically disable sensors when practical**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Use hardware shutters, microphone switches, or power controls for cameras and assistants during sensitive moments or long periods of disuse.
WHY: A physical control remains effective even when software is misconfigured or compromised. - [ ] **Keep critical functions locally operable**   `CORE`   **+20 XP** TRACK: ALL TRACKS Ensure locks, alarms, heating, smoke detection, and essential appliances remain safe if the internet, vendor, or account fails.
WHY: Cloud dependency should not turn an outage or compromise into a physical safety event. - [ ] **Maintain an IoT inventory**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Record device, owner, network, account, update status, and disposal date; remove devices you no longer use.
WHY: You cannot patch, isolate, or retire equipment you have forgotten. - [ ] **Monitor unusual IoT traffic**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Use router logs or network monitoring to identify unexpected destinations, bandwidth spikes, or devices active at unusual times.
WHY: Behavior changes can reveal compromise or unwanted data collection. - [ ] **Prefer local control where it genuinely works**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Choose documented local APIs and deny internet access to devices that operate correctly without it.
WHY: Local operation can reduce cloud exposure, but only when updates and secure management remain possible. ## 10 // Sensible Computing > Turn security from a product into a calm, repeatable habit. **12 missions / 225 XP** - [ ] **Verify every unusual sensitive request**   `CORE`   **+20 XP** TRACK: ALL TRACKS Pause before sending money, credentials, codes, files, or urgent access; confirm through a known independent channel.
WHY: Business email compromise and impersonation succeed by creating urgency and borrowing trust. - [ ] **Read the destination, not just the display text**   `CORE`   **+20 XP** TRACK: ALL TRACKS Inspect domains carefully, use bookmarks for critical services, and open account apps directly instead of following unexpected links or popups.
WHY: HTTPS and polished design can exist on a convincing phishing site. - [ ] **Lock devices whenever they leave your control**   `CORE`   **+20 XP** TRACK: ALL TRACKS Use automatic locking, keep devices with you in public, and remotely lock or erase a lost device.
WHY: An unlocked session can bypass passwords and MFA entirely. - [ ] **Protect screens and conversations in public**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Position screens carefully, use a privacy filter when justified, hide authentication codes, and avoid sensitive calls in exposed spaces.
WHY: Observation is a low-tech way to collect high-value information. - [ ] **Control cameras and microphones**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Review app access, close unused meeting software, use hardware covers or mute controls where practical, and check the background before calls.
WHY: Sensors can expose private spaces through mistakes, excessive permissions, or compromise. - [ ] **Review permissions twice a year**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Audit apps, browser sites, cloud integrations, sharing links, location history, advertising settings, and third-party data sharing.
WHY: Permissions accumulate while your needs and the services themselves change. - [ ] **Use payment methods with strong fraud controls**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Prefer options with transaction alerts, dispute protection, and virtual or limited-use numbers where available; never treat cryptocurrency as automatically anonymous or reversible.
WHY: Good controls reduce exposure and improve recovery when merchant data is stolen. - [ ] **Collect and share less data**   `CORE`   **+20 XP** TRACK: ALL TRACKS Delete files, accounts, scans, and messages you no longer need; avoid providing optional identity fields and restrict public records where lawful.
WHY: Data that does not exist cannot be leaked from your device or account. - [ ] **Compartmentalize high-impact activities**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Separate work and personal identities, devices, browser profiles, storage, and admin accounts according to risk.
WHY: Boundaries stop one mistake or compromise from reaching everything. - [ ] **Write a one-page incident plan**   `CORE`   **+20 XP** TRACK: ALL TRACKS List how to freeze payments, secure email and phone accounts, revoke sessions, restore backups, contact trusted people, preserve evidence, and report abuse.
WHY: A short checklist improves decisions when stress is high and time matters. - [ ] **Run a quarterly security review**   `RECOMMENDED`   **+15 XP** TRACK: ALL TRACKS Check updates, backups, recovery contacts, exposed data, old accounts, connected devices, and the next three highest-risk improvements.
WHY: Security degrades quietly as devices, accounts, and circumstances change. - [ ] **Define your personal threat model**   `ADVANCED`   **+25 XP** TRACK: ALL TRACKS Identify what you protect, likely adversaries, realistic consequences, and controls you can sustain; seek qualified help for stalking, domestic abuse, targeted activism, or high-risk professional work.
WHY: The strongest checklist is the one adapted to your real risks and capacity. ## 11 // Governance and Risk > Turn security from scattered tools into owned, measurable decisions. **12 missions / 225 XP** - [ ] **Map critical services and crown-jewel assets**   `CORE`   **+20 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE List the services, identities, systems, data, facilities, suppliers, and operational dependencies whose loss would cause the greatest harm; name an owner for each.
WHY: Priorities become defensible when teams know what must keep working and who is accountable for it. - [ ] **Assign executive and operational accountability**   `CORE`   **+20 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Give a senior leader responsibility for security risk and define named owners for identity, endpoints, networks, data, suppliers, response, and recovery.
WHY: Controls drift when responsibility is shared in theory but owned by nobody in practice. - [ ] **Build a current and target security profile**   `RECOMMENDED`   **+15 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Use an accepted framework such as NIST CSF 2.0 to record current outcomes, target outcomes, gaps, priorities, owners, and review dates.
WHY: A profile turns a broad framework into a roadmap shaped by mission, risk tolerance, and resources. - [ ] **Inventory data and processing flows**   `CORE`   **+20 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Document what sensitive data is collected, why it is needed, where it flows, who can access it, where it is stored, how long it is retained, and how it is deleted.
WHY: Security and privacy decisions fail when hidden copies, integrations, and retention paths are unknown. - [ ] **Define classification and handling rules**   `CORE`   **+20 XP** TRACK: ORGANISATION / GOVERNMENT / DEFENCE Create approved labels and handling rules for storage, transmission, printing, sharing, remote access, removable media, retention, and destruction.
WHY: Consistent handling rules connect data sensitivity to enforceable behaviour and technical controls. - [ ] **Run a joiner, mover, and leaver process**   `CORE`   **+20 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Provision least privilege from approved roles, review access when duties change, and revoke accounts, sessions, tokens, keys, and physical access promptly at departure.
WHY: Stale access and privilege accumulation create durable paths around otherwise strong controls. - [ ] **Separate and govern privileged access**   `CORE`   **+20 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Use separate administrator identities, phishing-resistant MFA, just-in-time elevation where possible, approval for sensitive actions, and auditable privileged sessions.
WHY: Administrative access has an outsized blast radius and deserves stronger controls than everyday work. - [ ] **Assess suppliers by access and impact**   `RECOMMENDED`   **+15 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Tier suppliers by the data, systems, networks, facilities, and continuity dependencies they can affect; require evidence proportionate to that risk.
WHY: A supplier can inherit your trust without inheriting your safeguards unless requirements are explicit. - [ ] **Procure secure and verifiable technology**   `RECOMMENDED`   **+15 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Evaluate secure defaults, MFA and SSO support, logging, vulnerability disclosure, patch commitments, data controls, export paths, support life, and independent assurance before purchase.
WHY: Buying decisions can prevent years of compensating controls and opaque residual risk. - [ ] **Operate a vulnerability lifecycle**   `CORE`   **+20 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Maintain asset coverage, receive vulnerability intelligence, prioritize by exposure and mission impact, patch or mitigate within defined targets, verify closure, and document exceptions.
WHY: A scanner produces findings; a lifecycle reliably reduces exploitable risk. - [ ] **Set a logging and time baseline**   `RECOMMENDED`   **+15 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Centralize useful identity, admin, endpoint, network, application, and cloud events; synchronize time, protect logs, define retention, and alert on high-value behaviours.
WHY: Response and accountability depend on trustworthy evidence collected before an incident begins. - [ ] **Map legal, regulatory, and command authority**   `ADVANCED`   **+25 XP** TRACK: GOVERNMENT / DEFENCE Record the approved policies, competent authorities, reporting timelines, classification rules, records duties, procurement constraints, and escalation chain that apply to each system.
WHY: Public-sector and defence controls must be technically sound and exercised under the correct authority. ## 12 // Incident Response and Resilience > Prepare calm decisions, preserve evidence, and restore the mission safely. **13 missions / 245 XP** - [ ] **Keep a personal incident wallet**   `CORE`   **+20 XP** TRACK: PERSONAL Keep offline contact details and steps for your bank, mobile carrier, primary email, device recovery, identity reporting, trusted support, and local emergency services.
WHY: A compromised phone or account should not remove the information needed to recover it. - [ ] **Maintain an approved incident response plan**   `CORE`   **+20 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Define incident categories, authority, roles, evidence handling, containment choices, internal and external communications, recovery criteria, and plan ownership.
WHY: A concise approved plan reduces delay, improvisation, and contradictory decisions under pressure. - [ ] **Name response roles and alternates**   `CORE`   **+20 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Assign incident command, technical lead, legal and privacy advice, communications, business continuity, evidence custody, and executive decisions with trained alternates.
WHY: Response stalls when every urgent decision must first discover who is allowed to make it. - [ ] **Prepare out-of-band communications**   `RECOMMENDED`   **+15 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Maintain a tested communication path that does not depend on the primary identity, messaging, network, or collaboration system being investigated.
WHY: Compromised platforms may expose response conversations or become unavailable at the worst time. - [ ] **Preserve evidence with a documented chain**   `RECOMMENDED`   **+15 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Record times and observations, retain original alerts and messages, avoid unnecessary changes, and use authorized forensic or law-enforcement support for serious cases.
WHY: Good evidence supports diagnosis, recovery, reporting, insurance, disciplinary action, and legal process. - [ ] **Pre-authorize containment options**   `RECOMMENDED`   **+15 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Document who may isolate endpoints, disable identities, block traffic, suspend integrations, shut down services, or move to manual operations, including safety and mission constraints.
WHY: Containment is faster and less damaging when authority and trade-offs were considered in advance. - [ ] **Prove restoration from known-good backups**   `CORE`   **+20 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Test representative restores, verify integrity and dependencies, measure recovery time, and keep at least one backup protected from ordinary administrator compromise.
WHY: A backup is only a recovery capability after a successful restore has been demonstrated. - [ ] **Define minimum viable operations**   `RECOMMENDED`   **+15 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Identify essential services, safe degraded modes, manual workarounds, staffing, facilities, communications, and the order in which dependencies must return.
WHY: Recovery should restore mission outcomes, not merely power systems back on. - [ ] **Run scenario-based tabletop exercises**   `RECOMMENDED`   **+15 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Exercise realistic account compromise, supplier failure, ransomware, data exposure, cloud outage, and physical disruption scenarios; track decisions and corrective actions.
WHY: Exercises reveal unclear authority and brittle dependencies before a real incident does. - [ ] **Maintain a notification matrix**   `ADVANCED`   **+25 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE With qualified legal and policy owners, map which incidents may require notice to regulators, CERTs, customers, partners, insurers, law enforcement, leadership, or command channels and by when.
WHY: Reporting duties vary by jurisdiction, contract, sector, data type, and mission; guessing during response creates avoidable harm. - [ ] **Prepare ransomware decisions before infection**   `ADVANCED`   **+25 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Protect recovery infrastructure, preselect specialist contacts, understand legal and sanctions constraints, preserve evidence, and define executive decision authority without assuming payment will restore systems or confidentiality.
WHY: Extortion combines technical, operational, legal, financial, and safety risks that cannot be resolved by a single improvised choice. - [ ] **Convert incidents into tracked improvements**   `RECOMMENDED`   **+15 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE After recovery, document the timeline, root and contributing causes, control gaps, decisions, human factors, owners, deadlines, and verification for corrective actions.
WHY: A blame-free review prevents the same weakness from surviving the incident that exposed it. - [ ] **Exercise classified and mission escalation paths**   `ADVANCED`   **+25 XP** TRACK: GOVERNMENT / DEFENCE Use only approved channels, facilities, personnel, marking, sanitization, evidence custody, and command authority when an incident may involve classified, operational, or national-security information.
WHY: Ordinary response habits can create a second incident when applied across restricted security boundaries. ## 13 // Software and Security Hardware > Choose maintained, verifiable controls and deploy specialist hardware lawfully. **13 missions / 245 XP** - [ ] **Write requirements before choosing a tool**   `CORE`   **+20 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Define the problem, users, threat model, data sensitivity, platforms, accessibility, recovery needs, administration, integrations, budget, and support horizon before comparing products.
WHY: A famous product can still be the wrong control for your risks and operating model. - [ ] **Treat source availability as evidence, not a guarantee**   `RECOMMENDED`   **+15 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Consider reviewability, build provenance, maintainer activity, vulnerability response, release signing, independent assessment, architecture, and deployment configuration together.
WHY: Open and closed products can both be secure or insecure; outcomes depend on design, maintenance, verification, and operation. - [ ] **Verify maintenance and support life**   `CORE`   **+20 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Check recent releases, security advisories, supported platforms, patch cadence, responsible disclosure, end-of-life commitments, and a realistic replacement path.
WHY: An abandoned privacy or security tool can become a new source of exposure. - [ ] **Inspect permissions and data flows**   `CORE`   **+20 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Understand what a tool can access, what leaves the device or organisation, where it is processed, who receives it, how long it is retained, and which controls are available.
WHY: A tool cannot protect privacy when its own access and processing are poorly understood. - [ ] **Test export, recovery, and deletion**   `RECOMMENDED`   **+15 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Confirm usable exports, backup and recovery, key ownership, account deletion, data return, migration, and what happens if the vendor, subscription, or cloud service disappears.
WHY: Security includes the ability to recover and leave without losing control of important data. - [ ] **Deploy hardware-backed security keys where justified**   `RECOMMENDED`   **+15 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Use standards-based phishing-resistant keys for high-value identities, enroll a protected spare, record ownership, and test recovery before rollout.
WHY: Hardware-backed authentication can strongly resist credential phishing while a spare prevents one lost key becoming a lockout. - [ ] **Control and encrypt removable media**   `RECOMMENDED`   **+15 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Use approved encrypted media, maintain custody, scan or isolate transfers, restrict use by policy, and sanitize or destroy media according to data sensitivity.
WHY: Portable storage crosses physical and network boundaries easily and is simple to lose, copy, or replace. - [ ] **Use trusted power, cables, and transfer accessories**   `RECOMMENDED`   **+15 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Carry trusted chargers and cables; when only power is needed in an untrusted setting, use a reputable charge-only cable or data-blocking adapter that has been tested for the device.
WHY: Unknown accessories and ports can expose data interfaces or behave differently from their appearance. - [ ] **Match physical privacy controls to exposure**   `RECOMMENDED`   **+15 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Use screen filters, camera shutters, secure storage, tamper evidence, visitor controls, or acoustic privacy only where the environment and threat model justify them.
WHY: Simple physical controls can reduce observation and tampering without creating unnecessary friction everywhere. - [ ] **Require fleet administration and audit capability**   `ADVANCED`   **+25 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE For managed technology, require role-based administration, SSO and MFA, configuration enforcement, audit logs, inventory, update control, alerting, data location choices, and supported offboarding.
WHY: A tool that works for one person may become unmanageable or unauditable across an organisation. - [ ] **Place security appliances within defined trust boundaries**   `ADVANCED`   **+25 XP** TRACK: BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Harden management interfaces, separate administration, patch firmware, restrict telemetry, back up configuration, monitor health, and avoid treating any appliance as an automatic trust anchor.
WHY: Routers, firewalls, sensors, and gateways are privileged computers and can become high-impact failure points. - [ ] **Do not deploy jammers, spoofers, or covert interception devices**   `CORE`   **+20 XP** TRACK: PERSONAL / BUSINESS / ORGANISATION / GOVERNMENT / DEFENCE Never use radio, GPS, mobile, microphone, surveillance, or interception equipment without explicit legal authority, safety assessment, qualified operators, and formal approval; choose lawful shielding, zoning, policy, and detection controls instead.
WHY: Interference and interception can be illegal, dangerous, operationally disruptive, and harmful to emergency or public communications. - [ ] **Verify provenance for high-assurance systems**   `ADVANCED`   **+25 XP** TRACK: GOVERNMENT / DEFENCE Follow approved acquisition and assurance processes for component origin, firmware, cryptography, secure boot, updates, tamper controls, maintenance access, supply-chain risk, and acceptance testing.
WHY: High-assurance environments require evidence that technology remains trustworthy across acquisition, deployment, maintenance, and retirement. ## Supplied Guide Coverage All 6 supplied files and their 94 major topics are indexed in the interactive Guide Library. Retired product lists are represented through current selection criteria rather than copied as permanent recommendations. ### README (2).md // Complete Personal Security Checklist The original account, device, network, communication, smart-home, and everyday safety checklist, rebuilt as current missions. **All primary sections incorporated.** **Topics:** Passwords / Two-factor authentication / Browser and search / Email / Social media / Networking / Mobile devices / Personal computers / Smart home / Sensible computing ### 0_Why_It_Matters.md // Why Privacy and Security Matter A plain explanation of data collection, surveillance, cybercrime, profiling, and why privacy protects ordinary people. **Every argument and major heading incorporated.** **Topics:** The current situation / Government surveillance / Cybercrime / Corporate data collection / What data is collected / What happens to collected data / The nothing-to-hide question ### 2_TLDR_Short_List.md // Rapid-Start Short List The fastest useful actions from the original short list, reorganized into the guided beginner journey. **Personal checklist, software, and hardware sections incorporated.** **Topics:** Authentication / Browsing / Phone / Email / Networking / Devices / Security software / Browser extensions / Mobile apps / Online tools / Productivity tools / Security hardware ### 4_Privacy_And_Security_Links.md // Privacy and Security Learning Library Every resource category from the original link collection, with a safer method for checking authority, date, jurisdiction, and maintenance. **All resource categories incorporated.** **Topics:** Foundations / How-to guides / Blogs / Books / Podcasts / Videos / Data and APIs / Academic journals / Implementations and standards / Government cybersecurity organisations / Anonymous services / Online tools / Mega guides / Other security lists ### 5_Privacy_Respecting_Software.md // Privacy-Respecting Software and Services Every software category from the original catalogue, converted from permanent product recommendations into current selection tests. **All software and service categories incorporated.** **Topics:** Password managers / Two-factor authentication / File encryption / Encrypted messaging / Encrypted email / Email aliases / Self-hosted email / Mail clients / Browsers / Search engines / Browser extensions / Mobile apps / Online tools / Virtual private networks / Self-hosted VPN / Self-hosted network security / Mix networks / Proxies / DNS / Firewalls / Network analysis / Cloud hosting / Digital notes / Cloud productivity suites / Backup and sync / File drop services / Social networks / Video platforms / Blogging platforms / News readers and aggregation / Payment methods / Anti-virus and malware prevention / Mobile operating systems / PC operating systems / Windows defences / macOS defences / Home automation / AI voice assistants / Alternatives to Google services / Additional self-hosted tools / Analytics platforms / How to choose and review ### 6_Privacy_and-Security_Gadgets.md // Privacy and Security Hardware Every hardware category from the original gadget guide, filtered through safety, legality, compatibility, support, and real-world usefulness. **All hardware categories incorporated.** **Topics:** Basic physical controls / DIY security products / Specialist privacy gadgets / Network security hardware / DIY networking hardware / Hardware-encrypted storage / USB data blockers and trusted cables / FIDO security keys / Hardware wallets ## Resource Intelligence Vault The supplied guides are preserved here as maintainable decision frameworks. Product ownership, defaults, support status, and laws change, so this edition uses evidence checks instead of a permanent whitelist. ### INTEL 01 // Why Privacy and Security Matter > Privacy protects agency, safety, dignity, opportunity, and freedom from manipulation; security keeps the systems carrying those interests dependable. - **Aggregation changes sensitivity:** A location point, purchase, contact, or search may look harmless alone. Combined over time, ordinary data can reveal health, relationships, routines, beliefs, finances, and vulnerabilities.
DECISION TEST: Assess complete data flows, not isolated fields. - **Cybersecurity is not all of privacy:** Strong encryption and access control can prevent unauthorized use, while excessive collection or harmful authorized processing can still create privacy risk.
DECISION TEST: Ask whether the data should be collected and retained at all. - **Consequences differ by person and mission:** The same exposure may mean spam for one person, physical danger for another, fraud for a business, or operational harm for a public or defence organisation.
DECISION TEST: Model realistic impact, adversaries, and capacity. - **Proportion beats fear:** Use controls that reduce meaningful risk and can be sustained. Escalate to qualified support for stalking, abuse, targeted intrusion, regulated data, or mission systems.
DECISION TEST: Prefer maintainable layers and tested recovery. ### INTEL 02 // TLDR Rapid Start > A modern replacement for the short list: secure the highest-impact paths first, then build depth. - **Identity first:** Protect primary email, password manager, financial, cloud, mobile carrier, developer, and administrator identities with unique credentials and phishing-resistant MFA where available.
DECISION TEST: Recovery methods and active sessions are part of the account. - **Update and reduce exposure:** Patch supported devices and applications, remove abandoned software and accounts, restrict permissions, and disable services you do not use.
DECISION TEST: Unsupported technology needs a retirement or isolation plan. - **Pause and verify:** Confirm unusual requests for money, credentials, codes, access, sensitive files, or urgent action through a known independent channel.
DECISION TEST: Polish, caller ID, HTTPS, and familiar names do not prove identity. - **Recover before you need to:** Keep protected recovery codes and contacts, maintain isolated backups, and test restoration and account recovery.
DECISION TEST: A successful restore is the proof of a backup. ### INTEL 03 // Trusted Guidance and Learning > Use primary standards, competent national authorities, and maintained references; verify the date, jurisdiction, audience, and scope before acting. - **Frameworks organise outcomes:** NIST CSF 2.0 and the NIST Privacy Framework help organisations govern, identify, protect, detect, respond, recover, and manage privacy risk without prescribing one product stack.
DECISION TEST: Tailor a current and target profile to mission and risk. - **Baselines accelerate action:** CISA performance goals provide high-impact cross-sector practices that can be prioritized by smaller organisations and critical services.
DECISION TEST: A baseline begins the programme; it does not replace sector duties. - **National guidance governs reporting:** Use the official CERT, regulator, law-enforcement, and sector authority for your jurisdiction, including CERT-In guidance for Indian government entities.
DECISION TEST: Record approved contacts and timelines before an incident. - **Maintenance is a trust signal:** Prefer resources that identify owners, publication dates, revision history, scope, references, and a correction path.
DECISION TEST: Revalidate saved advice and links at least annually. ### INTEL 04 // Privacy-Respecting Software Selection > Choose software by evidence and fit, not by a permanent whitelist. Products, ownership, defaults, and maintenance change. - **Security model:** Review encryption boundaries, authentication, recovery, update integrity, vulnerability handling, isolation, and independent assurance relevant to the actual deployment.
DECISION TEST: Understand which parties and components must be trusted. - **Privacy model:** Review collection, purpose, sharing, retention, deletion, telemetry, advertising, training use, jurisdiction, and controls for users and administrators.
DECISION TEST: Prefer data minimization and clear, enforceable defaults. - **Operational fit:** Check supported platforms, accessibility, usability, backup, export, admin controls, logs, integrations, offline behaviour, training burden, and support life.
DECISION TEST: A secure tool that people cannot operate safely will be bypassed. - **Open source in context:** Source access can improve reviewability and autonomy, but it does not prove secure design, active review, reproducible builds, safe defaults, or timely maintenance.
DECISION TEST: Use multiple evidence signals and verify the shipped artifact. ### INTEL 05 // Privacy and Security Hardware > Use physical controls to strengthen authentication, storage, observation resistance, and network boundaries without relying on novelty or unlawful interference. - **Authentication hardware:** Standards-based security keys can provide phishing-resistant authentication. Enroll protected spares, maintain custody, and test recovery.
DECISION TEST: Confirm protocol, platform, account, and organisational compatibility. - **Storage and transfer:** Use approved encryption, trusted removable media, controlled transfer paths, secure key custody, inventory, and verified sanitization for the data sensitivity involved.
DECISION TEST: Hardware encryption claims still require architecture and recovery review. - **Physical privacy:** Privacy screens, camera shutters, secure cases, tamper evidence, cable controls, and trusted charging accessories can address specific observation or access risks.
DECISION TEST: Deploy only where the exposure justifies the friction. - **Specialist equipment:** Network sensors, shielding, forensic equipment, and high-assurance devices need trained operators, maintenance, policy, and explicit authority. Avoid jammers, spoofers, covert interception, and unsafe anti-surveillance devices.
DECISION TEST: Legality, safety, authorization, and mission impact come first. ## Incident Quick Card When something feels wrong: **disconnect if needed, preserve evidence, secure primary email, revoke sessions, rotate exposed credentials, contact financial providers, restore from known-good backups, and report through the relevant official channel.** Do not confront a suspected stalker or abuser through a monitored device; use a safer device and specialist support. ## Maintenance Cycle - **Weekly:** install waiting updates and inspect security alerts. - **Monthly:** check backups, unknown sessions, connected devices, financial alerts, and critical service health. - **Quarterly:** review permissions, recovery methods, dormant accounts, suppliers, exceptions, and the next three unfinished Core missions. - **Yearly:** exercise incident and recovery plans, replace unsupported technology, and refresh threat, privacy, and mission-risk profiles. ## Primary Guidance - [CISA Secure Our World](https://www.cisa.gov/secure-our-world) - [NIST SP 800-63B-4 Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html) - [NIST Guidance for Syncable Authenticators](https://pages.nist.gov/800-63-4/sp800-63b/syncable/) - [NIST Cybersecurity Framework 2.0](https://www.nist.gov/cyberframework) - [NIST Privacy Framework](https://www.nist.gov/privacy-framework) - [NIST SP 800-207 Zero Trust Architecture](https://csrc.nist.gov/pubs/sp/800/207/final) - [CISA Cross-Sector Cybersecurity Performance Goals](https://www.cisa.gov/cybersecurity-performance-goals) - [CISA Choosing Secure and Verifiable Technologies](https://www.cisa.gov/resources-tools/resources/choosing-secure-and-verifiable-technologies) - [CERT-In Guidelines for Government Entities](https://cert-in.org.in/guidelinesgovtentities.jsp) - [Original Personal Security Checklist](https://github.com/parthxd3/Personal-Security-Checklist) ## About This Edition This 2026-07-15 edition rebuilds all six supplied Personal Security Checklist, privacy, quick-start, resource, software, and hardware files into a current, maintainable field manual. Legacy recommendations involving retired tools, blanket open-source or VPN claims, Flash, ActiveX, weak password-length targets, unqualified cryptocurrency anonymity, jammers, or spoofers were replaced with risk-based and authorization-aware guidance. The field manual is educational, not a substitute for professional incident response, legal advice, domestic-abuse support, competent authority, command approval, or an organisation-specific security programme. ---
Secure what matters. Test recovery. Keep improving.