Get your digital house in order - stay safe
For grassroots organizers and community leaders digital safety isn’t just personal—it’s collective. The work often involves coordinating people, sharing information, and organizing around issues that matter, which can make you and your networks more visible. A single compromised account can expose contacts, disrupt communication, or erode trust across an entire group. This isn’t about being perfectly secure—it’s about reducing risk, protecting your network, and staying operational so you can continue to organize, communicate, and build effectively without unnecessary disruption.
There’s no way to guarantee 100% safety online.
If someone is highly skilled and determined, they may still find a way in.
But—
👉 These habits reduce your risk significantly
👉 They help you avoid the most common attacks
👉 They allow you to operate and communicate online effectively
🧩 THE 5 AREAS THAT COVER EVERYTHING
1. Accounts & Passwords
2. Devices (Phone + Computer)
3. Online Behavior (Email, Social, Browsing)
4. Information You Share
5. Protection & Recovery
1️⃣ 🔑 Accounts & Passwords (Your Foundation)
📝 Writing Passwords Down (Less Risky When Done Correctly)
How to Do It with Lower Risk
Use a notebook (not loose paper)
Store it in a private, secure place:
Drawer
Safe
Locked cabinet
What Increases Risk
Labeling it “Passwords”
Leaving it visible
Carrying it around daily
👉 Simple Rule
Physical security lowers risk—but doesn’t eliminate it
🔐 Use a Password Manager (Lower Risk Overall)
Stores passwords securely
Generates strong, unique passwords
Reduces reuse (a major breach risk)
👉 Simple Rule
This is one of the lowest-risk ways to manage passwords
🧠 Use Long, Unique Passwords
Use long phrases (recommended by NIST)
Make every password different
👉 Simple Rule
Long and unique lowers risk significantly
⚖️ Convenience vs Risk (Cookies, Saved Passwords & Pop-Ups)
This is where everyday behavior quietly increases exposure.
What’s Happening (Often Very Fast)
When you log into a site, your browser may quickly ask:
“Save password?”
“Stay signed in?”
Cookie or tracking preferences
👉 These prompts appear quickly—and are easy to click through without thinking
Why It Matters
When you accept these:
Your device stores login/session data
You may stay logged in longer than intended
Sites may collect more data than necessary
👉 Convenience increases exposure
Lower-Risk Situations
Your personal device
Device is locked and updated
Account is low sensitivity
Higher-Risk Situations
Shared computers
Public or work devices
Sensitive accounts (email, banking)
Lower-Risk Approach
Be Intentional with “Save Password”
Don’t click “save” automatically
Avoid saving sensitive accounts in browsers
Use a password manager instead
Pay Attention to Pop-Ups (Cookies & Data Use)
When a site asks:
“Accept all cookies”
“Manage preferences”
👉 You usually have a choice
Lower-risk approach:
Select only what’s needed for the site to function
Avoid accepting tracking/marketing cookies unless necessary
Slow Down the Click
Take a second before clicking “Accept” or “Save”
👉 Simple Rule
You don’t have to accept everything—choose only what you need
2️⃣ 📱💻 Devices (Phone + Computer)
Phone (Most Important)
Lock it (PIN, Face ID, fingerprint)
Keep updates ON
Only install apps from official stores
Review app permissions (contacts, location, camera)
Computer
Turn on automatic updates
Use built-in protection (like Windows Defender)
Restart regularly
Avoid
Installing random apps or extensions
Clicking links from text messages
👉 Simple Rule
Your phone is your identity—treat it like your wallet
🛡️ Privacy Screens (Lower Risk in Public)
What They Do
Limit who can see your screen from the side
When It Helps
Travel (planes, trains)
Cafes, shared spaces
Offices with open seating
👉 Simple Rule
Protect your screen as well as your passwords
3️⃣ 🌐 Online Behavior (Where Most Risks Happen)
📧 Email
Check full sender address
Hover over links before clicking
Don’t open unexpected attachments
👉 If unsure → go directly to the website yourself
🔎 Searching / Browsing
Use trusted, known websites
Bookmark important sites
Don’t automatically trust the first result
When visiting a site:
Look for HTTPS
Check the domain name carefully
⚠️ HTTPS secures the connection—but does NOT confirm the site is legitimate
👉 Simple Rule
Always verify the site—not just the lock icon
📘 Social Media (Facebook, etc.)
Separate Personal vs Business
Personal → private, limited info
Business → public, no personal details
Do This
Review privacy settings regularly
Be selective with connections
Back up your data (posts, photos, contacts)
Avoid
Mixing personal info into public pages
Accepting unknown requests
Responding to urgent money messages
👉 Simple Rule
Control what you share—and keep a copy
💬 Messaging (WhatsApp, Texts)
Turn on 2-step verification
Verify unusual requests another way
👉 Simple Rule
Even if it looks familiar—confirm it
4️⃣ 🪪 Information You Share
Do This
Only provide real info when required by trusted companies
Limit app access to your data
Avoid
Using real birthday/address on public profiles
Oversharing:
Travel in real time
Location
Personal routines
👉 Simple Rule
If it’s public, it can be used
5️⃣ 🛡️ Protection & Recovery (What Saves You)
Backups
Turn on automatic backups (iCloud, Google, etc.)
Back up important platforms when possible
👉 If it’s not backed up, it’s gone
Public Wi-Fi
Avoid sensitive logins when possible
Use a VPN if needed
Financial Protection
Turn on alerts
Review accounts regularly
Account Recovery
Secure your email (strong password + 2FA)
Use safe recovery options
👉 Simple Rule
Most attacks happen through access—not hacking
🧭 Managing This (Keep It Simple)
These protections need light, ongoing attention.
Weekly (5–10 minutes)
Update devices
Scan emails/messages
Delete anything suspicious
Monthly (10–15 minutes)
Review key accounts
Check activity and settings
Make sure backups are working
Occasionally
Review app permissions
Remove unused apps/accounts
👉 Simple Rule
Small, consistent checks reduce long-term risk
🔒 Optional Tools (Extra Layer — Not Required)
VPN
Helps protect your connection on public Wi-Fi
Antivirus Suites (e.g., Norton 360)
Adds extra protection (malware, identity monitoring)
👉 Helpful—but habits matter more
🚨 Common Scams (Quick Awareness)
“Your account is locked—click here”
Urgent money requests
Fake job/payment offers
Tech support pop-ups
👉 Rule
No legitimate service pressures immediate action
🧭 The “Good Enough” System
Focus on this:
✔ Password manager
✔ 2FA
✔ Don’t click suspicious links
✔ Keep devices updated
✔ Limit what you share
📘 Terms to Know (Simple + With Examples)
Two-Factor Authentication (2FA)
Extra security step after your password
Example:
You log in → receive a code → enter it to complete login
HTTPS
Encrypted connection to a website
Example:
`https://bank.com` protects your data—but you still verify the site
VPN (Virtual Private Network)
Protects your internet connection
Example:
Using public Wi-Fi with a VPN reduces exposure
Password Manager
Secure tool to store and generate passwords
Example:
One master password unlocks all others
Phishing
Scam to trick you into giving information
Example:
Fake email asking you to log into your bank
Malware
Harmful software that steals or damages data
Example:
Downloading a file that installs tracking software
Backup
A separate copy of your data
Example:
Photos saved automatically to the cloud
👉 Important:
Backups reduce loss risk but must be checked
Cookies
Data stored by websites on your device
Example:
A site keeps you logged in
👉 Important:
Some cookies are necessary—others track behavior
👉 Lower-risk approach:
Choose only what you need
NIST (National Institute of Standards and Technology)
U.S. government body that sets cybersecurity standards
Example:
Recommends:
Long passwords
Password managers
No forced frequent password changes unless needed
✅ Final Thought
You don’t need to be perfect.
👉 Most problems come from:
moving too fast
accepting defaults
choosing convenience without awareness
👉 Better approach:
slow down briefly
make intentional choices
reduce exposure where you can