A complete guide to protecting yourself and your company against digital threats.
By Yosef Alberti · 443sec · X2 Nova Labs
A complete guide to protecting yourself and your company against digital threats — phishing, passwords, social engineering, and best practices.
Employee Onboarding · 443sec · X2 Nova Labs
Most attacks start with human error. A click on a malicious link, a weak password, or information shared with the wrong person. Technology protects systems, but training protects people.
Information Security is the set of practices to protect information against unauthorized access, misuse, disclosure, destruction, or modification. It is based on three pillars:
Phishing is an attempt to obtain confidential information (passwords, banking data) by pretending to be a trustworthy entity through emails, messages, or fake websites.
Golden rule: When in doubt, DON'T CLICK. Contact the company directly through an official channel to confirm if the message is legitimate.
Never use: 123456, password, qwerty, abc123, admin, your name, date of birth
An extra layer of security. Even if someone discovers your password, they'll still need an additional code.
Tip: Use a password manager like Bitwarden, 1Password, or LastPass. You only need to remember ONE master password.
Manipulation techniques used to deceive people into revealing information or taking harmful actions. The attacker exploits trust, fear, or urgency.
"I'm from IT, I need your password for a system update"
"Lost" USB drive in the parking lot with a virus
Phishing by phone — "Call from the bank"
Following an authorized employee to enter a restricted area
No legitimate institution will ask for your password over the phone. When in doubt, hang up and call the official number yourself.
Networks in cafes, airports, and hotels can be monitored by attackers. They can see everything you do online if the connection is not encrypted.
NEVER do this on public Wi-Fi: Access banking, shop online, enter important passwords, access company systems without VPN
Privacy regulations (like GDPR, CCPA, LGPD) protect personal data. Violations can result in fines of up to 4% of annual revenue or millions of dollars.
Best practices: Don't send sensitive data via email without encryption. Don't leave documents at the printer. Shred papers with data. Lock your screen when away.
IMMEDIATE STEPS:
1. DON'T panic
2. Disconnect from the network (if possible)
3. DON'T turn off the computer (may erase evidence)
4. Notify IT/Security IMMEDIATELY
5. Document what happened (screenshots, times)
6. Change passwords on another device
Remember: Reporting an incident is NOT grounds for punishment. It's better to report a false alarm than to ignore a real threat.