← All articles
habits

6 Small Security Habits That Make a Big Difference

You don’t need to overhaul your entire digital life to be meaningfully safer online. Six habits — most of which take minutes to set up — change the picture significantly. Here’s what they actually do, and why they work.

Behavent Team

Behavent Team

10 min read

Most security advice arrives as an overwhelming list. Use unique passwords everywhere. Enable two-factor authentication. Keep your software updated. Check your privacy settings. Monitor your accounts. Back everything up. It's not wrong — but presented all at once, it's paralysing, and paralysed advice gets ignored.

So here's a different approach: six habits, ordered by how much protection they give you relative to how much effort they take. More importantly, each one comes with the context you actually need to understand what it does and why it works — not just a checkbox to tick.

“The habits with the highest protection tend to require the least ongoing effort. That's not a coincidence — it's by design.”

The six habits

Habit 01 — Use a password manager — and let it do the work

A study of 19 billion leaked passwords found that 94% were reused or duplicated across services. The average person reuses the same password 14 times. This is the root cause of most account takeovers — not sophisticated hacking, but the mechanical testing of known credentials against every other service the victim uses. It's called credential stuffing, and it's automated, continuous, and extraordinarily effective.

A password manager generates a unique, random password for every account and fills it in automatically when you log in. You remember one password: the master password that opens your vault. When a service you use is breached, that breach exposes credentials that work nowhere else. Your passwords are encrypted on your device before they reach the manager's servers. The free options are genuinely excellent: Bitwarden gives you unlimited passwords across unlimited devices at no cost, with full encryption and independent security audits.

ℹ️

Worth knowing

The master password is the one credential that matters most. The 2022 LastPass breach is the instructive case: encrypted vaults were stolen, and by 2026 documented losses from accounts with weak master passwords have reached $438 million. Make it long (four or more random words works well), unique, and protect it with two-factor authentication.

💡

Do this today

Download Bitwarden and use it for the next three accounts you log into. The vault fills naturally as you use it — you don't need to migrate everything at once.

Habit 02 — Turn on two-factor authentication — and use an app, not SMS

Two-factor authentication (2FA) adds a second verification step beyond your password — typically a six-digit code that changes every 30 seconds. Studies suggest that 80% of account breaches could have been prevented if the victim had 2FA enabled. Even if an attacker has your exact password, they can't get in without that second factor.

There's a meaningful difference between 2FA methods. SMS-based 2FA is significantly weaker than app-based 2FA due to SIM swapping: an attacker calls your mobile carrier, impersonates you, and convinces them to transfer your phone number. In 2024, the FBI recorded nearly $26 million in losses from SIM-swap attacks in the US alone. An authenticator app generates codes locally on your device without touching the mobile network at all.

Our recommendation is Authy over Google Authenticator: Authy keeps an encrypted backup of your 2FA accounts and syncs across multiple devices. Google Authenticator has historically been a single point of failure — lose your phone without a backup and you're locked out of every account using it.

ℹ️

Worth knowing

Start with your most critical accounts: your primary email first (because it's the recovery mechanism for almost everything else), then your banking app. Your email account being compromised gives an attacker a path to reset passwords on every account that uses it for recovery.

⚠️

SMS 2FA is still worth enabling

If a service only offers SMS-based 2FA and not an authenticator app, still turn it on. SMS 2FA blocks the vast majority of automated attacks even if it's vulnerable to the more targeted SIM-swap technique. Don't let the imperfect option stop you from using it.

💡

Do this today

Download Authy, then go to your primary email provider's security settings and enable two-factor authentication using the app. Takes about three minutes. Then do your banking app.

Habit 03 — Keep your devices and apps updated — automatically

Software updates exist for two reasons: new features, and security patches. When researchers or attackers discover a vulnerability in an operating system or application, the developer fixes it and releases an update. Until you install that update, your device is running with a known weakness — and attackers actively scan for unpatched systems.

The time between a vulnerability being discovered and it being actively exploited has compressed dramatically. Today, critical vulnerabilities are often exploited within 24 to 72 hours of public disclosure. Automatic updates remove the decision entirely — your device installs security patches in the background, usually overnight, without requiring any action from you.

ℹ️

Worth knowing

Prioritise: operating system first, browser second, apps that handle sensitive information third (banking, email, healthcare). Your browser is particularly important — it's the primary surface through which web-based attacks reach your device, and browser vendors patch vulnerabilities frequently.

💡

Do this today

iPhone: Settings → General → Software Update → Automatic Updates → turn on all options. Android: Settings → Software Update → Auto Download and Install. Mac: System Settings → General → Software Update → turn on Automatic Updates. Windows: Settings → Windows Update → Advanced Options → enable all automatic update options.

Habit 04 — Pause before you click — especially when something feels urgent

Phishing — emails, texts, and calls impersonating trusted organisations — is responsible for the majority of account takeovers. The technique works not because people are careless, but because it exploits a specific cognitive bias: urgency short-circuits careful reasoning. When we feel time pressure, we shift from deliberate thinking to fast-response thinking. Phishing attacks are engineered to trigger exactly that shift.

The defence is a deliberate pause. When something unexpected arrives asking you to click a link or enter credentials: stop. Check the actual sender domain, not the display name. Go directly to the organisation's website by typing it yourself rather than following any link. If the issue is real, you'll see it there. That pause — even just ten seconds — breaks the urgency mechanism the attack depends on.

ℹ️

Worth knowing

Password managers provide an underappreciated layer of phishing protection: they autofill credentials only on the exact domain they were saved for. If you land on a convincing fake paypa1.com instead of paypal.com, your manager won't fill in your PayPal credentials. You'll notice the fields are empty. That's a signal worth paying attention to.

💡

Do this today

Next time you get an unexpected email from a bank, delivery company, or government agency, practise going directly to their website instead of using the link. Build the habit before it matters — when an attack actually arrives, the instinct will already be there.

Habit 05 — Review what your apps can access — and revoke what they don't need

App permissions accumulate quietly over years. Most people grant permissions at installation without reading them and never revisit them. On a phone with several years of installed apps, the permission landscape can be remarkably broad.

This matters for two reasons. First, permissions represent genuine access — an app with microphone permission can record audio when running. Second, many apps share permission-derived data with analytics partners, advertising networks, and data brokers. A useful rule of thumb: an app should only have access to capabilities its core function requires. A calculator has no legitimate reason to access your contacts. A flashlight has no legitimate reason to access your location.

ℹ️

Try this — it's eye-opening

Open Google Maps on your phone, tap your profile photo, and select Timeline. If location history is enabled, you'll see a day-by-day record of everywhere you've been — going back potentially years. You'll see your home address, your workplace, your gym, your regular coffee stop, your doctor's suburb. That data exists because apps with location permission share it, and Google Maps assembles it into a remarkably complete portrait of your daily life.

⚠️

Precise vs approximate location — the difference matters

Most apps that ask for location don't actually need to know exactly where you are. A weather app needs your suburb, not your street address. Switching apps from "Precise Location" to "Approximate Location" gives them enough to function while reducing what they — and their data partners — can infer about your daily routine.

💡

Do this today

Open Google Maps → profile photo → Timeline and decide whether you want that history kept. iPhone: Settings → Privacy & Security → Location Services — review every app with "Always" or "While Using" access. Android: Settings → Privacy → Permission Manager → Location. Do the same for Microphone and Camera.

Habit 06 — Back up the things that would be hardest to lose

Ransomware encrypts your files and demands payment for the decryption key. Hardware failure destroys data without warning. A lost or stolen device takes with it everything not stored elsewhere. In each scenario, the difference between a recoverable incident and a genuine loss is whether your data exists somewhere other than the affected device.

The 3-2-1 backup rule is the practical standard: three copies of important data, on two different types of storage, with one copy stored somewhere physically separate. In practice for most people, this means cloud backup for your phone and either cloud storage or an external drive for your computer — with the external drive stored somewhere other than next to the computer.

ℹ️

Worth knowing

For ransomware protection specifically, cloud backup is more resilient than an always-connected external drive, because cloud services typically keep version history — meaning you can restore files from before the encryption occurred. An always-connected external drive often gets encrypted alongside the main device.

💡

Do this today

Check whether iCloud (iPhone), Google Photos (Android), or OneDrive is enabled for automatic photo backup. Then check your computer: Time Machine on Mac, or File History on Windows, connected to an external drive or backed up to cloud storage.

How these six habits stack up

Habit

Time to set up

Ongoing effort

Protection level

Password manager

10–15 min

Very low

Very high

Two-factor authentication

3–5 min per account

Very low

Very high

Automatic updates

2 min

None

High

Pause before clicking

No setup

Very low

High

App permission review

15 min

Occasional

Medium–high

Back up your data

10 min

None once set

High

The pattern is consistent: the highest-protection habits are the ones you set up once and rarely touch again. Password managers, automatic updates, and cloud backup all provide sustained, compounding protection for minimal ongoing effort. The only habit on this list that requires active attention is the phishing pause — and even that becomes instinctive with practice.

You don't need to do all of this at once. Pick the first one, do it today, and come back for the next. A year from now, all six running together will have made a measurable difference to your daily digital security posture.

💡

Your Behavent Score

These habits are exactly what Behavent tracks — and explains

Each of the six habits above maps directly to one or more Behavent domains: Daily Habits, Device Health, Think Before You Click, Privacy Control, Spot the Threat, Bounce Back. Your Behavent Score reflects how these are holding up right now, not just how they were set up six months ago.

Behavent's assessments go one layer deeper than a checklist — explaining not just what to do, but why it matters in your specific situation. Your score tells you where to focus, and updates as your habits improve.

🚀

Want to know which of these habits you're already doing well — and which to focus on first?

Your Behavent Score tells you exactly where you stand.

#habits#password-manager#two-factor-auth#security#privacy
Behavent Team

Behavent Team

The team behind Behavent. We believe better daily habits make everyone safer online. No jargon, no fearmongering — just clear, honest guidance you can actually use.

Was this article helpful?

Your feedback is private — only our team sees it.