ONLINE PRIVACY CyberArtical Editorial Team

The security habits worth keeping, and three worth dropping

A hand holding a phone showing a fingerprint scanning screen, resting above a laptop keyboard

Habits are the right unit for personal security, because anything requiring sustained attention eventually stops happening. But a habit is only worth having if the guidance still supports it, and several of the most established ones have been formally retired — not softened, but written out. Here are the habits that do the work, the ones to stop, and how to arrange things so most of it happens without you.

Retired by the agencies themselves

  • Periodic password changes: NIST SP 800-63B-4 — verifiers "SHALL NOT require subscribers to change passwords periodically", only on evidence of compromise.
  • Character mixes: verifiers "SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types)."
  • Avoiding public Wi-Fi: FTC — "connecting through a public Wi-Fi network is usually safe" because "most websites do use encryption."
  • Still current — CISA: turn on automatic updates so devices "install updates without any input from us as soon as the update is available."
  • Still current — CISA: question providers who do not offer automatic updates, because "It’s your information they’re putting at risk!"

What a habit has to earn its place

Two tests. It has to address something that actually happens to people, and it has to survive being done badly on a bad week.

Most abandoned security routines fail the second test. Anything requiring a monthly action, a spreadsheet, or a decision every time will lapse. The best habits are the ones you configure once and then merely refrain from undoing.

The habits that do the work

  • Automatic updates, everywhere. CISA’s instruction is to remove the human from the loop entirely, so updates install as soon as they are available. CISA also says to question providers who do not offer them, because "It’s your information they’re putting at risk!"
  • Reading the address before you act on a message. The FBI’s rule is to check "for misspellings or wrong domains within a link (e.g., if an address that should end in ‘.gov’ ends in ‘.com’ instead)". The FTC’s stronger version is to type the address yourself.
  • Verifying on a channel the sender did not choose. CISA: "Look up another way to contact the company or person directly." This single habit defeats most of what arrives in an inbox.
  • Heeding browser warnings. The FTC says it in three words; NCSC treats the ability to click through certificate warnings as something to remove entirely.
  • A password manager and unique passwords. CISA’s consumer standard is at least 16 characters, random, and unique to each account — which is only achievable with a manager.
  • The strongest second factor a service offers. Passkeys where available, an authenticator app otherwise, SMS only as a last resort.

Three habits to stop

  1. Rotating your passwords on a schedule. NIST is explicit that verifiers shall not require periodic changes, and that a forced change belongs only where there is evidence of compromise. The reason is behavioural: forced rotation produces predictable transformations and weaker choices.
  2. Building passwords out of character substitutions. NCSC’s assessment of the P@ssw0rd! approach is that criminals know these tricks too, so "your password won’t be significantly stronger, but it will be harder for you to remember." Length and uniqueness are what count.
  3. Refusing to use public Wi-Fi. The FTC’s current position is that public Wi-Fi is usually safe, and it contrasts this explicitly with the past. The risk moved to the destination site — fake, encrypted sites operated by scammers — which avoiding a network does nothing about.

Two more that quietly do nothing

Hiding your Wi-Fi network name and filtering by device address. Neither the FTC nor CISA lists either among home network controls. The FTC’s actual list is WPA3 or WPA2 Personal encryption, unique admin username, password and network name, firmware updates, remote management off, WPS and UPnP off, the router firewall on, logging out of the admin account, and a guest network.

Also: setting a private browsing window and treating it as an anti-tracking measure. The FTC’s description is that it may delete history after a session but "doesn’t block websites from seeing your online activity."

Arranging it so it runs without you

  1. Turn on automatic updates on every device and in your browser, then stop thinking about patching.
  2. Put a password manager in place and let it generate and store credentials. The habit becomes "use the manager" rather than "invent a password".
  3. Enrol the strongest second factor on email and money accounts once. It does not need maintaining.
  4. Set your devices to lock automatically, with at least a six-digit passcode — which on modern phones is also what enables encryption.
  5. Back up, and keep the backup drive disconnected between backups. CISA: "Avoid leaving the external drive connected when not actively backing up your data."
  6. Put one annual review in the calendar for the things that genuinely need revisiting: privacy settings, extensions, dormant accounts, and whether any of your second factors can be upgraded.

What habits cannot compensate for

No routine protects you from a company you use being breached, and no routine makes a convincing message obviously fake in the moment. The tells people were taught to look for — clumsy phrasing, obvious spelling errors — have stopped being reliable, so a habit built on spotting them will fail quietly rather than loudly.

So the last habit is knowing where to go when something gets through: the FTC’s fraud report site for scams, IdentityTheft.gov if personal data has been used against you, and the FBI’s IC3 for internet crime. Knowing the route in advance is worth more than any amount of vigilance on the day.

Sources: NIST SP 800-63B-4 · NCSC UK — Three random words · FTC — Are public Wi-Fi networks safe? · CISA — Update software · FTC — How to secure your home Wi-Fi network

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from NIST, NCSC UK, CISA and the FTC. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories