Why you, specifically?
You don’t need to be a technology expert to be a target. As a decision-maker, you are sought for your access (budget, sign-off, sensitive data), your calendar (which reveals when you’re away) and your authority (which makes it possible to pass off a message as genuinely coming from you).
Digital hygiene is not an IT discipline: it is a risk-management discipline, like locking an office door after leaving the room. Here are twelve concrete actions. Each is self-contained, immediate and costs nothing.
The twelve steps
Each is self-contained. You can follow them in order or start with the ones that matter most to you.
Do the "mirror test" (your public footprint)
The riskYour name + your company = a business card anyone can look up to guess your email or your habits.
What to do- Open a private browsing tab ("private" or "incognito" mode).
- Type your name, then your name + your company’s name.
- Note the first five results: an old association directory, a conference bio, an attendee list, an old website.
- If a link exposes your direct work email, your phone number or personal data, look at the bottom of the page for "Remove" / "Report / Contact". Send a short message: "I would like this public information removed." Update your LinkedIn profile so your contact details aren’t visible to everyone.
You know exactly what an adversary sees of you before approaching you.
Lock the keystone: your main mailbox
The riskYour work email is the way into almost everything else (bank, social networks, messaging apps).
What to do- Go to your mailbox settings (Gmail, Outlook, etc.).
- Change the password if it is more than a year old, or if it is the same as one you use elsewhere.
- Turn on "two-step verification": your mailbox will send a code to your phone in addition to the password. Just use the SMS code offered; that’s enough to start, with nothing to buy.
- Check the "Connected apps" or "Security > Third-party apps" section. Remove anything you don’t recognise (old newsletter apps, travel services, etc.).
- Check the "recovery" phone number / email: if it points to an old account, update it.
Even if a password leaks elsewhere, your mailbox stays locked.
Cut off the invisible guests (apps and access)
The riskApps you’ve forgotten about still have access to your contacts, your calendar and your photos.
What to do- On your phone: Settings > Privacy > Calendar, then Contacts, then Photos. Revoke permission for every app except the absolutely essential ones (your official calendar, your messaging app).
- In your mail account (Google / Microsoft / Apple): Settings > Security > Third-party apps / Data access. Remove any not used in the last three months.
- In particular: revoke contacts access from social, gaming and lifestyle apps.
Fewer apps = fewer open doors into your digital life.
Clean up your open links in the cloud
The riskYou may have shared a folder with "anyone with the link" for a team project; that link is still live.
What to do- Open your online storage (Google Drive, OneDrive, iCloud, Dropbox).
- In the search bar, look for "shared publicly", "public", or check the link icons next to files.
- For each sensitive document (strategic presentations, contracts, personal data), change the link to "Restricted to people I invite" or "Private".
- Delete old folders from finished projects that contain personal data.
A simple copy-paste of a URL can no longer expose your documents.
Hide your public face on professional networks
The riskAttackers map your relationships, your job moves and your travel through your profile.
What to do- On LinkedIn: Settings > Privacy > How others see your profile and activity.
- Turn off "Share profile updates": this avoids automatically announcing your changes of role, title or company to strangers.
- Hide your email address and phone number: show them only to your first-degree connections.
- Limit who can see your connections list (Settings > Privacy > Who can see your connections).
- Turn off "Let people find me by my email / phone number".
You stop broadcasting your movements and your network to people you don’t know.
Secure your messaging apps (WhatsApp, etc.)
The riskFaked messages and impersonation attempts often come through these channels because they are lightly protected.
What to do- WhatsApp / equivalent: Settings > Privacy.
- Profile photo / Last seen / Status: set to "My contacts" or "Nobody".
- "Who can add me to groups": set to "My contacts".
- Turn on "two-step verification" in WhatsApp (Settings > Account > Two-step verification): this blocks anyone who has stolen your SIM card or your phone.
- Check your profile photo on other messaging apps too: it is often used to create fake accounts.
An attacker can’t impersonate you visually or add you to malicious groups.
Clean up your phone: delete, don’t just move
The riskEvery app is a potential sensor (microphone, location, contacts).
What to do- Settings > General / Apps: delete anything you haven’t opened in three months (games, old travel apps, former banking apps, coupon apps).
- For each remaining app: Settings > Privacy > Microphone / Location / Photos / Contacts. Revoke access unless it is essential (e.g. a navigation app needs location; your social apps don’t).
- In particular: revoke microphone access from social apps if they don’t need it.
Fewer apps = fewer leaks.
Hide your notifications on the lock screen
The riskA sensitive message from your bank, your team or a client reads itself out in a plane, a lobby or a café.
What to do- Settings > Notifications > [Your work mail / Bank / Messaging]: turn on "Hide content" or "Don’t show content" on the lock screen (iPhone: "Previews" set to "Never" or "When Unlocked"; Android: "Sensitive notifications" or "Hide content" depending on the brand).
- Do the same for your messaging apps.
- If you have a smartwatch or a smart speaker: turn off reading private messages on it.
No one around you reads your sensitive information.
Keep the public web apart from the sensitive network
The riskOpen networks ("Free_WiFi_Airport") make it possible to intercept or reroute your data.
What to do- Settings > Wi-Fi: turn off "Auto-Join" (iPhone) or "Auto-connect" (Android).
- Remove from your known networks anything that looks like an old public network.
- Golden rule: for anything sensitive (an important video call, banking access, reading a strategic document), use your mobile data (4G/5G) rather than the café or hotel Wi-Fi.
- If you absolutely must use an unknown Wi-Fi, turn on your phone’s hotspot to stay on a network you control, rather than connecting to the venue’s.
You aren’t risking your data every time you travel.
Strengthen your critical passwords (with nothing to buy)
The riskYou may have been reusing your password for years.
What to do- Open your browser (Chrome, Safari, Edge) > Settings > Passwords / Password Manager.
- The browser often flags in red any password that is reused or too weak. It’s your dashboard, not a new app.
- Change straight away the ones for: your main email, your bank, your Apple / Google / Microsoft account, and LinkedIn.
- Use a phrase you know but that’s hard to guess (e.g. "MyDogAlbertEatsApplesIn2025!"). If the browser offers to generate a password, accept: it remembers it for you.
A leak on a minor site no longer compromises your critical accounts.
Protect your contact data and your calendar
The riskYour calendar reveals when you’re away; your contacts are a pass for crafting fake messages.
What to do- Phone: Settings > Privacy > Calendar: revoke access from every app except your official calendar.
- Settings > Privacy > Contacts: do the same.
- Check your voicemail: set a PIN if you haven’t. Delete the over-informative greeting ("I’m away until the 15th, call my assistant…"). Replace it with: "You’ve reached my voicemail. Leave a message and I’ll call you back."
- In your email, check your auto-reply: don’t mention your holiday dates or that you’re out of the office.
Attackers who get in through a minor app don’t come away with your schedule or your relationships.
The Friday ritual: 10 minutes to keep it up
The riskHygiene isn’t bought; it’s maintained.
What to doCreate a recurring event every Friday afternoon (10 minutes) titled "Digital security upkeep". During those 10 minutes, do the following, in this order:
- Check for any unfamiliar-sign-in alert email (from your bank, Apple/Google, LinkedIn, Microsoft).
- Delete one app you haven’t used this week.
- Check whether a new link has been created in your cloud (some services show a "shared with a link" warning).
- Take stock: is any service pushing too much information? If so, turn off its notifications or reduce its access.
You keep your exposure low without a huge effort, and you keep it that way.
Your immediate roadmap
If you do nothing else today: do step 2 (main mailbox + double lock) and step 9 (turn off Wi-Fi auto-join + use mobile data). These are two steps of under 20 minutes that immediately reduce your most common risks.
If you want to know what you actually expose
This guide lets you act on your own. A digital hygiene audit establishes what is actually visible about your organisation or yourself — thirty checks, five areas, and a prioritised action plan.
The scoping call lasts thirty minutes, commits you to nothing, and you leave it with a written note that is yours to keep.
Discuss a situation