Cybersecurity basics
Cybercriminals use emails, QR codes and fraudulent calls to obtain personal information, login details and payment details. A few simple precautions can help protect you and your data.
Scam emails and websites, manipulated QR codes and callers posing as customer support are common threats online. The following tips explain how you can protect your accounts, devices and data, shop safely online and recognise attempts to manipulate you.
Passwords and account security
Never enter sensitive information, such as passwords or credit card details, on a website that you have accessed via a link in an email or text message. Type in the website's official address yourself. Only enter passwords on official websites that you have opened by typing the address directly into your browser. Never access e-banking, social media or webmail through a Google search, as adverts at the top of the results may lead to fake websites that imitate legitimate providers. Use a different password for every online service. Passwords should contain at least twelve characters and include a combination of upper- and lower-case letters, numbers and special characters. Wherever possible, enable two-factor authentication and use a password manager to store your login details. Change your password immediately if you suspect that someone else may know it.
Social media
Protect your accounts by using strong, unique passwords and enabling two-factor authentication. Regularly check your privacy settings and only share information that you would be comfortable making public. Be particularly cautious about links and attachments sent in direct messages, even if they appear to come from someone you know.
Protecting your devices
Keep the operating systems, software and apps on all your devices up to date and enable automatic security updates. Protect your mobile device with a PIN, password or biometric authentication. Enable location tracking and remote erase so that you can locate the device or delete its data if it is lost. Only install the software and apps that you need, and download them only from official app stores or the manufacturer's website. On smart-home devices such as cameras, televisions and speakers, change the default passwords and install updates regularly. Make sure these devices connect to the internet through a router with its firewall enabled rather than directly. Devices connected directly to the internet require additional protection.
Shopping online
Before placing an order, check the legal notice on the retailer's website and make sure the information is complete and plausible. It should include a contact address, telephone number and commercial register number. The NCSC recommends reading reviews from other customers before buying. If an online shop or company has no reviews, it may be new, so take extra care. Create a unique password for each customer account and, where possible, opay by invoice rather than in advance. Never provide your password, credit card details or security codes in order to receive money, for example when selling an item on an online marketplace.
Backing up your data
Back up your important data regularly and make it part of your routine. Keep at least one backup offline on an external storage device, such as an external hard drive. You can also use your device's built-in backup functions or a reputable cloud backup service. Depending on your device, the available options may include File History in Windows 11, Time Machine in macOS, Google One on Android, or Samsung Cloud on Samsung devices. Where possible, follow the 3-2-1 rule: store three copies of your data on two different types of storage, with one copy kept in a different location.
QR codes
Inspect QR codes carefully before scanning them. Check whether a sticker has been placed over the original code. Never enter login details on a website that you have accessed via a QR code. If a QR code leads to a malicious website, immediately inform the person or organisation responsible for the location where you found it.
Social engineering
Do not let anyone pressure you into acting quickly. Time pressure, urgency and threats are all common warning signs. Trust your instincts and consider whether what you are being asked to do makes sense in the circumstances. Treat instructions from people claiming to represent the police, a bank or a public authority with caution. Legitimate organisations will never unexpectedly ask you to disclose passwords or security codes, nor will they pressure you into making an urgent payment. End the conversation if the requests become increasingly unusual or demanding. If you are in any doubt, verify an unexpected request through a separate, independent channel. Do not use an email address or telephone number provided in the original email or text message. Instead, use the contact details published on the organisation's official website.
