Skip to main content
Resource library
Personal cybersecurityExecutives, business owners, high-risk individuals, households, and the trusted people who help manage their affairs

Personal Cyber Foundations Guide

A checklist-directed guide for protecting critical accounts, money movement, shared access, devices, backups, privacy, and personal cyber recovery.

Working guide

Use the relevant sections, keep the defined outputs, and use the completion checks before moving on.

Start the guide

Author

Trawvid Sec

Published

Last reviewed

Review status

Current

Before you begin

Set up the work

Expected effort: Allow 30 to 45 minutes for the first pass. Then work only the weak or high-consequence areas identified by the Personal Cyber Risk Checklist.

Bring these inputs

  • The Personal Cyber Risk Checklist result, including weak sections and open critical flags.
  • The names of important email, financial, cloud, phone, and business-adjacent accounts. Do not record passwords or recovery secrets.
  • A short list of people who help manage accounts, files, payments, devices, or household affairs.

Keep these outputs

  • A prioritized map of root accounts, recovery paths, financial workflows, delegated access, devices, backups, and public exposure.
  • A short first-hour recovery plan for account compromise, fraud, lost devices, identity misuse, or impersonation.
  • A realistic 30-day hardening plan focused on the changes that reduce the most risk.

Start with the checklist

Personal cybersecurity is not a shopping list. It is the way email, phones, financial portals, cloud files, devices, family members, assistants, and professional advisors connect to one another.

That system usually grows one convenience at a time. A spouse knows one password. An assistant receives statements. A bookkeeper can prepare a payment. An old email address still resets a brokerage account. A phone number is the recovery method for almost everything. Each choice may have been reasonable by itself. The trouble starts when nobody can see the full chain.

Begin with the Personal Cyber Risk Checklist. It scores ten areas privately in your browser. Do not complete every section of this guide just because it exists. Use the result to choose the modules that match a weak score, an open critical flag, or a consequence you cannot accept.

If something suspicious is happening now, skip to Module 6: Write the first-hour plan and contact the relevant bank, carrier, provider, or emergency service through a known channel.

The five moves that matter most

  1. Protect the primary email, recovery email, password manager, and phone carrier account.
  2. Put a separate verification step around wires, payees, payment changes, and urgent financial requests.
  3. Replace informal password sharing with named, removable access for family members, assistants, and advisors.
  4. Secure and back up the devices that can approve payments, reset accounts, or open sensitive records.
  5. Write down what happens first if a phone is lost, email is hacked, money moves fraudulently, or an identity is misused.

Use a controlled copy of this guide. Record account names and decisions, not passwords, recovery codes, seed phrases, private keys, full account numbers, Social Security numbers, or other secrets.

If the map gets complicated, use the help links on this page as an escape hatch. Email Trawvid Sec or book a 30-minute introductory call before making a change that could lock someone out or disrupt a financial workflow.

Module 1: Protect root accounts and recovery

Start with accounts that can reset or unlock other accounts. Primary email is often the real master key. Recovery email, the password manager, the phone carrier, and a trusted device may each provide another route around the protection on that mailbox.

Map the chain before changing it. Otherwise, it is easy to improve one login while leaving an old recovery address or phone number in control.

What to do

  • List the primary email, recovery email, password manager, phone carrier, important financial portals, cloud storage, and business-adjacent accounts.
  • Mark any account that can reset another account, approve identity changes, move money, or expose sensitive records.
  • Remove stale recovery addresses, former phone numbers, unknown trusted devices, and old authorized users.
  • Use unique credentials or passkeys for critical accounts.
  • Turn on the strongest practical multifactor authentication offered by the provider. For root accounts, prefer passkeys, security keys, or authenticator applications over text messages when the recovery process is understood.
  • Store backup codes outside the account they recover. Do not leave the only copy in ordinary email, photos, or the same password vault.
  • Test one recovery path on paper. Know what remains available if the main phone is lost.

The CISA password manager guidance is a useful product-selection and recovery reference. The operating rule is simpler: one reputable vault, unique credentials, strong protection on the vault itself, and no circular recovery chain that depends on the unavailable account.

Root account map

AccountWhy it mattersCurrent recovery pathProtection in placeChange neededOwner
Primary emailResets other accounts
Recovery emailCan bypass primary email protection
Password managerStores critical credentials
Phone carrierControls number and text-message recovery
Financial portalMoves money or exposes records
Cloud or business-adjacent accountStores records or controls business access

Move on when:

  • Primary and recovery email accounts use unique credentials and strong sign-in protection.
  • Old recovery methods and unknown trusted devices have been reviewed.
  • The password manager has a recovery plan that does not depend only on itself.
  • Backup codes are protected outside this guide.
  • At least one root-account recovery path has been walked through without guessing.

Module 2: Protect money and the phone number

A phone number is not just a communication tool. It may receive account-recovery codes, confirm identity, approve transactions, or serve as the trusted contact for financial institutions. Protect the carrier account as part of the financial system.

Ask the carrier which protections are available. Names vary, but useful controls may include an account PIN, number lock, port-out lock, transfer lock, and notifications for subscriber identity module or number-transfer changes. The FTC SIM swap guidance explains why text messages should not be the only protection on sensitive accounts.

Money movement also needs a rule that exists outside email. A believable message from an executive, family member, attorney, advisor, or vendor is still just a message until it is verified through a known second channel.

What to do

  • Set a unique carrier account PIN and enable available transfer protections.
  • Review carrier account owners, authorized users, recovery email, and notifications.
  • Move high-consequence accounts away from text-message-only sign-in or recovery when stronger options are available.
  • List portals that can move money, create payees, change contact details, access credit, or expose tax and financial records.
  • Turn on useful alerts for sign-ins, profile changes, password resets, new payees, transfers, withdrawals, and large purchases.
  • Require out-of-band verification for new wires, changed payment instructions, new payees, urgent requests, and account changes. Use a known number or contact path, not the contact information in the request.
  • Place and maintain credit freezes when appropriate. The credit-freeze guide links directly to Equifax, Experian, and TransUnion.

Money and carrier control record

AreaCurrent safeguardRequired verification or alertOwnerNext action
Phone carrier
Bank and credit accounts
Brokerage or investment portal
Payroll, payment, or business-adjacent portal
Credit freezes and identity monitoring

Move on when:

  • Carrier ownership, authorized users, PIN, and transfer protections are known.
  • High-risk accounts do not rely only on the phone number for access or recovery.
  • Financial alerts reach a person who will act on them.
  • New or changed payment instructions require verification through a known second channel.
  • Someone knows what to do if the phone suddenly loses service.

Module 3: Control files, family access, and professional helpers

Family members, assistants, bookkeepers, attorneys, accountants, wealth managers, household staff, and technology providers may need legitimate access. The problem is not that they help. The problem is access that is shared informally, never reviewed, and difficult to remove.

Separate the verbs. Viewing a statement is not the same as changing contact information. Preparing a payment is not the same as releasing it. Emergency access is not the same as permanent access.

What to do

  • Choose an approved storage location for sensitive tax, estate, identity, insurance, health, property, legal, and business records.
  • Review public links, old collaborators, automatic email forwarding, shared folders, and exported copies.
  • Give each helper a named account or controlled share where practical. Avoid sending live passwords by email or text.
  • Record whether a person may view, prepare, change, approve, or release.
  • Define who removes access when a role, firm, employment relationship, household relationship, or advisor changes.
  • Review family sharing for location, photos, calendars, subscriptions, cloud storage, purchases, and devices.
  • Keep emergency access narrow. A person who may need an estate document someday does not necessarily need continuous access to every financial portal.

Delegated-access register

Person or firmWhat they can accessAllowed actionsAccess methodRemoval triggerOwner
View / prepare / change / approve / release
View / prepare / change / approve / release
View / prepare / change / approve / release

Move on when:

  • Sensitive files have an approved home and a named owner.
  • Shared links, old collaborators, and forwarding rules have been reviewed.
  • Helpers have named, removable access where practical.
  • Payment preparation and approval are not treated as the same authority.
  • Family and emergency sharing is intentional rather than assumed.

If several people touch the same accounts and nobody can explain who can approve what, pause before changing access one account at a time. Trawvid Sec can help map the workflow without taking possession of passwords.

Module 4: Harden high-risk devices, backups, and the home network

Do not boil the ocean. Start with the phone and computers that can approve payments, reset root accounts, open sensitive files, or act as trusted sign-in devices. A streaming stick and the laptop used for email, banking, and the password manager do not deserve equal attention.

Encryption protects data on a lost device. Backups protect against loss, failure, malware, and mistakes. Neither control helps if recovery keys are unavailable or nobody has tested a restore. The CISA device-data guidance provides a useful baseline.

What to do

  • Enable supported operating system and application updates on high-risk devices.
  • Use device encryption, a strong screen lock, automatic locking, and supported biometric protection.
  • Turn on trusted locate, lock, and erase features. Confirm those controls are reachable from another trusted path.
  • Replace unsupported devices or routers when their role makes the exposure meaningful.
  • Back up important photos, contacts, records, and working files.
  • Restore one small file. A green backup icon is not proof that recovery works.
  • Change default router administrator credentials, apply updates, use WPA2 or WPA3, disable unneeded remote administration, and remove unknown devices.
  • Put guest and connected-home devices on a separate guest or Internet-of-Things network when the router supports it.

Device and backup record

Device or dataSecurity and backup methodLast checkedRestore or recovery resultOwner
Primary phone
Primary computer
Sensitive files and records
Photos and family records
Home router and wireless network

Move on when:

  • High-risk devices are supported, updated, encrypted, and strongly locked.
  • Locate, lock, or erase features can be reached without the missing device.
  • Important data has a backup owner and a tested restore.
  • Router administration uses a unique credential and current software.
  • Guest or connected-device separation has been considered.

Module 5: Reduce public exposure

The objective is not to disappear from the internet. Public records, professional biographies, business roles, and old information may never vanish completely. Reduce the details that make impersonation, account-recovery abuse, doxxing, harassment, or a believable payment request easier.

The FTC people-search guidance explains how these services assemble public records, social data, and brokered information. Opt-outs can help, but information may return. Treat this as maintenance, not a one-time cleanup.

What to do

  • Search the person's name, common name variations, email addresses, phone numbers, and home address while signed out.
  • Note what a stranger could learn in 30 minutes about roles, relationships, locations, travel, authority, and likely verification questions.
  • Remove unnecessary birth dates, family details, location patterns, personal contact details, and old profiles where practical.
  • Submit opt-outs to the highest-exposure people-search sites and set a recheck date.
  • Review executive biographies, company pages, speaking profiles, family posts, shared albums, calendars, and travel details.
  • Tell family members, staff, and advisors how to verify an unusual request through a known channel.
  • Treat stalking, domestic violence, credible threats, or immediate physical safety concerns as a safety matter requiring qualified support, not an ordinary privacy project.

Exposure register

SourceUseful detail exposedDecisionOwner and recheck date
Search resultsRemove / reduce / accept
Business or professional profileRemove / reduce / accept
Social or family accountRemove / reduce / accept
People-search siteRemove / reduce / accept

Move on when:

  • Public searches have been reviewed from an outsider's perspective.
  • The most useful details for impersonation or recovery abuse have been reduced where practical.
  • Public contact information is not automatically trusted for sensitive verification.
  • Likely recipients know how to verify an unusual request.
  • A recheck date exists.

Module 6: Write the first-hour plan

The first hour is not the time to search for the carrier's fraud number or decide who can call the bank. Keep this plan short enough to use and store it somewhere available when the main email, phone, or cloud account is unavailable.

Name one response coordinator and a backup. Save trusted contact methods for the carrier, financial institutions, technology providers, and relevant advisors. Record facts, times, case numbers, and actions, but never passwords or recovery secrets.

First-hour action card

EventFirst actionsWho must be contactedEvidence to preserve
Email compromiseUse a known-clean device; regain control; change the credential; review recovery methods, forwarding rules, active sessions, trusted devices, and recent messages; warn affected contacts through another channel.Email provider, affected contacts, business support if company access overlapsAlerts, notices, suspicious messages, forwarding rules, session details, case numbers
Fraudulent payment or wire requestCall the financial institution through a known number; ask about recall or reversal; pause related payments; preserve the request and transaction details.Bank or brokerage fraud department, payment owner, relevant advisorOriginal request, transaction confirmation, call notes, case numbers
Lost phone or computerUse trusted locate or lock controls; contact the carrier if a phone is involved; protect root accounts; revoke sessions when warranted; warn contacts if impersonation is possible.Carrier, device provider, business support when company data is presentDevice details, last known location, alerts, support case
Identity misuse or new-account fraudFreeze credit if needed; contact affected businesses; preserve notices; use IdentityTheft.gov for a recovery plan.Affected institution, credit bureaus, insurer or qualified advisor as appropriateCredit reports, notices, fraudulent account details, reports and correspondence
Impersonation, doxxing, or harassmentPreserve messages, profiles, links, dates, and screenshots; warn likely recipients; report through relevant platforms or authorities; address physical safety first.Likely recipients, platform, qualified safety or legal support when neededMessages, links, account names, screenshots, reports and case numbers

Move on when:

  • A primary and backup response coordinator are named.
  • Trusted contacts are accessible without the primary phone or email.
  • Someone has authority to pause payments, contact institutions, and protect devices and accounts.
  • First actions exist for the events that would cause the most harm.
  • The plan contains no secrets.

If an event is active, do not wait for Trawvid Sec before contacting emergency services, the financial institution, carrier, provider, insurer, law enforcement, or another qualified professional when appropriate. Trawvid Sec does not provide 24/7 monitoring or guaranteed emergency response.

Finish the highest-value work in 30 days

Do not turn this into a 70-item someday list. Close the root-account and money-movement gaps first, then reduce the ways those controls can be bypassed.

PriorityActionOwner and target dateProof it is complete
1Protect primary email, recovery email, password manager, and carrier account
2Publish the separate verification rule for wires, payees, and account changes
3Review delegated access, shared files, family sharing, and recovery authority
4Harden high-risk devices and test one backup restore
5Store the first-hour plan outside the primary phone and email

Repeat the Personal Cyber Risk Checklist after material changes, when a family or advisor relationship changes, after a serious scare, and at least annually. A strong score is useful, but an unresolved critical flag still deserves attention.

This guide should leave you with fewer unknowns, not a false promise that compromise is impossible. If recovery paths, advisor relationships, household sharing, or business overlap are difficult to untangle, email Trawvid Sec, book a 30-minute introductory call, or review the Personal Cyber Risk Review service. Bring the decisions you cannot confidently close. Do not send passwords, recovery codes, financial secrets, or sensitive family documents.

Keep working

Practical next step

If account recovery, household sharing, delegated access, money movement, or incident planning is difficult to untangle, Trawvid Sec can help turn the unknowns into a practical hardening sequence.

Get help with your personal cyber plan

Reference baseline

Sources