Frequently Asked Questions

What's the difference between a password and a passphrase?

Password: A typical combination of characters (letters, numbers, symbols) like "Tr0pic@l92!"

Passphrase: A sequence of words like "Purple Mountain Dancing Tiger" that's easier to remember but equally secure when long enough.

Passphrases are increasingly popular because they're easier to remember while maintaining good security. The key is length - a passphrase with 16+ characters is very strong.

Should I use antivirus software?

Yes, antivirus software is an important part of a layered security approach. Modern operating systems include built-in protection (Windows Defender, macOS security), but additional antivirus can provide extra protection.

Recommended approach:

  • Use your OS's built-in security features
  • Keep everything updated
  • Consider additional antivirus for high-risk usage
  • Regular backups are just as important

Is public Wi-Fi safe to use?

Public Wi-Fi is generally not safe for sensitive activities. Hackers can easily intercept data on unsecured networks.

Safe practices:

  • Avoid public Wi-Fi for banking, shopping, or sensitive work
  • Use a VPN (Virtual Private Network) if you must access public Wi-Fi
  • Disable auto-connect features
  • Use mobile hotspot from your phone when possible
  • Enable two-factor authentication for important accounts

How do I know if my account has been hacked?

Warning signs:

  • Unexpected emails about password changes
  • Unable to log in to your account
  • Unfamiliar activity in your account
  • Email forwarding rules you didn't set
  • Money missing from linked accounts

Immediate steps:

  1. Change your password immediately
  2. Enable two-factor authentication
  3. Review account activity and remove unauthorized access
  4. Check linked accounts (email, banking, social media)
  5. Run antivirus scans on your devices
  6. Monitor accounts for fraudulent activity

How often should I back up my data?

Backup frequency depends on how important your data is and how often it changes:

  • Daily: Business critical data, active work files
  • Weekly: Important personal files, documents
  • Monthly: Photos, less frequently used files

Best practice: Use automated backup solutions that back up continuously or daily. Follow the 3-2-1 rule: Keep 3 copies of important data, on 2 different media types, with 1 copy offsite.

How do I protect my children online?

Multi-layer approach:

  • Set up parental controls on devices
  • Establish clear internet use rules
  • Have regular conversations about online safety
  • Know your children's online friends
  • Monitor without invading privacy
  • Create a safe environment to report uncomfortable situations
  • Use age-appropriate content filters

Prevention and communication are more effective than surveillance alone.

What should a small business do first for security?

Top priority actions:

  1. Assess: Understand what data you have and its value
  2. Passwords: Enforce strong passwords and password manager use
  3. Updates: Keep all systems and software updated
  4. Backups: Implement regular automated backups
  5. Training: Train employees on security basics
  6. Monitoring: Implement basic security monitoring

Start with these fundamentals, then progressively enhance security based on your risk assessment.

What is two-factor authentication (2FA)?

Two-factor authentication adds a second layer of verification when logging in:

  • Factor 1: Something you know (password)
  • Factor 2: Something you have (phone, authenticator app) or are (fingerprint)

Methods: SMS code, authenticator apps, security keys, biometric

Security keys are the most secure option, followed by authenticator apps, then SMS.

Action: Enable 2FA on critical accounts (email, banking, social media).

How do I know if a website is secure?

Look for these signs:

  • HTTPS: URL starts with "https://" not "http://"
  • Lock icon: Usually appears in the address bar
  • Certificate: Click the lock to view security certificate details
  • Domain name: Verify the domain matches the organization

Warning signs: Mismatched domains, expired certificates, missing HTTPS

HTTPS encrypts data in transit but doesn't guarantee the site isn't malicious. Always verify you're on a legitimate site before entering sensitive information.

How can I identify phishing emails?

Red flags:

  • Suspicious sender email address
  • Urgent language or threats
  • Requests for passwords or personal information
  • Unexpected attachments or links
  • Poor spelling or grammar
  • Generic greeting instead of your name
  • Mismatched or suspicious links

What to do: Don't click links or download attachments. Verify through official channels. Report to your IT department or the company's security team.

Didn't find your answer?

Submit your cybersecurity question and our experts will respond within 48 hours.