July 29, 2026
How I Secure “Me”: A Chief Security Officer’s Personal Playbook
As a Chief Security Officer, I regularly get asked some version of the same question:

By Mike L
11 min read
As a Chief Security Officer, I regularly get asked some version of the same question:
"I'm not a big company. I don't have a security team or unlimited resources. What are the basic things I should do to protect myself and my family?"
This article is my answer.
It is not an exhaustive security standard, and it is not meant to turn your home into a bunker. It is a practical collection of steps that reduce risk without requiring an enterprise budget or a degree in cybersecurity.
A disclosure before we begin: I receive nothing from any of the companies mentioned in this article. There are no affiliate links, referral payments, sponsorships, or other compensation. These are simply the products and services I personally use — or would recommend to my own family.
Some recommendations are free. Some require a subscription. A few require more technical ability than others.
You do not need to implement everything at once. Start with the basics, work your way down the list, and stop at the level of paranoia that makes sense for you.
The goal is not to become impossible to attack. That is unrealistic.
The goal is to remove the easy opportunities.
Start With Your Digital Identity
Use a password manager
If you only take one recommendation from this article, make it this one.
Use a password manager.
My preference is 1Password. It is easy to use, works across multiple devices and operating systems, and is built by people who clearly understand security. The technology under the hood is solid, but just as importantly, the product is usable enough that a normal family will actually adopt it.
Once you have a password manager, stop inventing passwords.
Let it generate a long, random password for every account you own. You should not know most of your passwords, because you should never need to type or remember them.
Computers are better at remembering passwords than people. Let them do the job.
Every account gets a unique password
Never reuse passwords.
When a website is breached, attackers take the stolen usernames and passwords and automatically test them against email providers, banks, retailers, social networks, streaming services, and anything else they can find.
This is called credential stuffing, and it works because people reuse passwords.
The password protecting your bank account should not depend on the security practices of some random shopping website you used three years ago.
Every account should be its own island.
Turn on multi-factor authentication
Enable multi-factor authentication everywhere it is available.
Whenever possible, use a passkey, hardware security key, or authenticator application instead of text messages. SMS-based authentication is still better than having no second factor, but it depends on the security of your mobile carrier — and mobile carriers do not always inspire confidence.
Start with the accounts that can unlock everything else:
- Your primary email
- Your mobile carrier
- Your bank and investment accounts
- Your Apple, Google, or Microsoft account
MFA is not perfect, but it prevents an enormous number of real-world account compromises.
Treat Your Email Like the Master Key
People often assume their bank account is their most important account.
In practice, it is usually their email.
If someone controls your email, they can often reset the passwords for nearly every other account you own. Your email is the recovery mechanism for your digital life.
Personally, I pay for Fastmail.
I like that it is independent, reliable, privacy-conscious, and makes it easy to create email aliases. Instead of giving every company the same email address, I can use a different address for different services.
That provides several benefits:
- A breach at one company does not expose the address I use everywhere else.
- If an address starts receiving spam, I can disable it.
- It becomes much easier to identify which company leaked or sold my information.
- My public email identity can remain separate from my important accounts.
Whatever provider you choose, protect your primary email with a unique password, strong MFA, and carefully reviewed recovery settings. Remove old recovery addresses and phone numbers you no longer control.
For people at elevated risk who use Google, I also recommend enabling the Google Advanced Protection Program. It raises the security requirements around your account and is especially appropriate for executives, journalists, political figures, investors, or anyone likely to face targeted attacks.
Protect Your Financial Identity
Freeze your credit
Unless you are actively applying for new credit, freeze your credit with the major credit bureaus.
A credit freeze is free and makes it significantly harder for an identity thief to open a new account in your name.
This is one of my favorite types of security control: configure it once, then let it quietly protect you in the background.
Use virtual credit cards
Whenever possible, I avoid giving online merchants my actual credit card number.
I use Privacy.com to generate virtual card numbers. Depending on how a card is configured, it can be limited to one merchant, assigned a spending limit, used for a single transaction, paused, or deleted.
If a merchant is breached, I do not need to replace my primary credit card and update it across dozens of legitimate services. I delete the affected virtual card and move on.
Virtual cards are also useful for subscriptions. Instead of trusting every company to make cancellation easy, you maintain direct control over whether the card can continue to be charged.
Share Less About Yourself
You cannot abuse information that was never published.
Make social media private
Make your personal social media profiles private.
Then review your friends and connections. Remove people you do not actually know or trust. Someone you met once ten years ago does not necessarily need continuing access to photographs of your family, your vacations, your home, your children's schools, and your daily routines.
Avoid announcing travel plans in real time. Do not publish more information about your children than necessary. Be conscious of photographs that reveal addresses, vehicle license plates, school logos, access badges, or the layout of your home.
Attackers perform reconnaissance before they act.
Do not do the reconnaissance for them.
Reduce your LinkedIn footprint
LinkedIn is a valuable professional platform. It is also one of the best intelligence-gathering platforms ever created.
An attacker can use it to identify executives, employees, reporting structures, vendors, technologies, projects, and recent organizational changes. That information makes phishing and social engineering far more convincing.
I recommend limiting what you share.
Consider removing your photograph. Avoid publishing detailed lists of the technologies your organization uses. Do not describe internal projects in unnecessary detail. Think carefully before publicly announcing every organizational change or responsibility you inherit.
You can maintain a professional presence without publishing a complete targeting package.
Pay for data-broker removal
Data brokers collect and sell addresses, phone numbers, relatives, prior residences, property records, and other personal information.
I pay for DeleteMe to continuously request removal of that information from data-broker sites.
Could you perform these removals yourself? In many cases, yes. But the information often reappears, the opt-out procedures vary, and the work becomes an ongoing maintenance task.
This is one of the subscriptions I happily pay for because it reduces my public exposure without requiring constant attention.
Protect Your Phone Number
SIM hijacking is real.
In a SIM-swap or unauthorized port-out attack, someone convinces a carrier to transfer your phone number to a device they control. They may then receive your calls, text messages, password-reset codes, and SMS-based authentication prompts.
At a minimum:
- Add a strong PIN or passcode to your carrier account.
- Enable number lock or port-out protection.
- Ask the carrier to require additional verification before making account changes.
- Avoid SMS-based MFA whenever a stronger option is available.
For people who want a much stronger level of protection, I think Cape is fantastic. It was built with threats such as SIM swaps, unauthorized number transfers, location privacy, and carrier-account abuse in mind.
Phone companies generally have a poor history of protecting customers from determined social engineering. Your mobile number has become part of your identity, so treat it accordingly.
Harden Your Computers and Phones
Turn on the firewall
Both macOS and Windows include built-in firewalls.
Make sure they are enabled.
On a Mac, confirm that the Apple firewall is turned on. On Windows, make sure Microsoft Defender Firewall is enabled across the appropriate network profiles.
This costs nothing and requires very little effort.
Enable automatic updates
Turn on automatic updates for:
- Operating systems
- Web browsers
- Password managers
- Productivity applications
- Mobile devices
- Networking equipment
Attackers routinely exploit vulnerabilities for which patches already exist. Staying current is one of the simplest ways to avoid becoming an easy target.
Encrypt your devices
Enable FileVault on macOS and BitLocker or Device Encryption on Windows.
Modern phones are generally encrypted when protected with a passcode, but make sure you are using a strong device passcode rather than a simple four-digit code.
Encryption is what prevents a lost or stolen device from becoming a lost or stolen copy of your entire digital life.
Avoid browser extensions
I install almost no browser extensions, and I recommend that most people do the same.
Your browser is where you bank, shop, work, communicate, and authenticate. A browser extension may be able to read the contents of websites, see information entered into forms, track browsing activity, or modify pages before you see them.
Even an extension that begins as a legitimate product can later be sold, abandoned, compromised, or updated with behavior you never intended to authorize.
My rule is simple:
Do not install a browser extension unless you have a specific and compelling reason to trust it.
Every extension should have to earn its place. Review the extensions you already have installed and remove anything you no longer need.
Take Your Home Network Seriously
Most people will spend more than $1,000 on a phone and then connect it to an old router that has not received an update in years.
Your router sits between every device in your house and the internet. It is one of the most trusted devices you own.
Buy equipment that gets patched
For beginners, Google's Wi-Fi products are a reasonable choice. They are simple to operate, receive automatic updates, and do not require someone in the family to become a part-time network administrator.
For more advanced users, I personally use Ubiquiti UniFi equipment. It provides substantially more visibility, control, and configuration flexibility, but it also requires more technical aptitude.
Regardless of the brand, buy networking equipment from a vendor with a demonstrated history of publishing security updates and supporting products over time.
I will also state one of my purchasing rules plainly:
I avoid networking equipment from Chinese manufacturers.
The U.S. government has repeatedly raised national-security and supply-chain concerns involving certain Chinese telecommunications and networking vendors. For a device that can observe or influence every connection in my home, I prefer vendors operating within legal and security environments I trust more.
This is not an area where I optimize for the cheapest possible product.
I optimize for trust, transparency, and the likelihood that the device will continue receiving patches.
Add DNS filtering
One of the best home-network security investments is a DNS-filtering subscription.
I used OpenDNS for years. Today, I use NextDNS.
Once configured, DNS filtering can prevent devices on your network from connecting to known malicious, fraudulent, or unwanted domains. It is relatively inexpensive, works quietly in the background, and can protect devices that do not support traditional security software.
Install the appropriate profiles or configure it at the router, enable the relevant malware and threat-intelligence blocklists, and let it work.
This is more technically sophisticated than installing a password manager, but for someone comfortable managing a home network, it offers an excellent security return for the money.
Good security should often be invisible after it is configured.
DNS filtering is a good example.
Protect the House Itself
Digital security is only one part of protecting a family.
Start with smoke and carbon monoxide detectors
Before worrying about cameras, smart locks, or advanced networking equipment, make sure your smoke and carbon monoxide detectors are installed correctly and actually work.
Test them regularly. Replace batteries as required. Replace the detectors themselves when they reach the end of their rated service life.
Fatal residential-fire investigations repeatedly find homes with missing, disabled, expired, or nonfunctioning smoke alarms. A smoke detector with a dead battery is not a security system. It is a plastic decoration on the ceiling.
This may be the least technical recommendation in the article, but it is among the most important.
Change the locks when you buy a house
When you purchase a home, hire a locksmith to rekey or replace the exterior locks.
You do not know how many copies of the previous owner's keys exist or who may still have one.
This is inexpensive, straightforward, and should be part of every new homeowner's move-in checklist.
Keep landscaping trimmed
Keep hedges, shrubs, and bushes around doors and first-floor windows trimmed.
Overgrown landscaping creates concealment and makes it harder for neighbors, cameras, or people inside the house to see suspicious activity.
Good visibility is good security.
Install motion-activated exterior lighting
Install motion-activated lighting around entrances, driveways, side yards, and other dark approaches.
Lighting is inexpensive, low-maintenance, and removes one of the advantages an intruder wants: the ability to move without being easily seen.
Install basic exterior cameras
You do not need to build a commercial surveillance operation.
For most homes, a few cameras covering the front entrance, driveway, rear entrance, and side access points are sufficient.
I use Ubiquiti Protect cameras, but that is the premium, technically advanced option. For most homeowners, Ring or Google's camera products are probably sufficient.
The best camera system is one that is installed correctly, sends useful alerts, retains enough footage, and remains operational when you need it.
Buy a safe for important documents
Every household should have a secure place for passports, birth certificates, Social Security cards, estate documents, property records, backup recovery codes, spare security keys, and other important materials.
A fire-rated safe is a reasonable option, but be mindful of moisture.
Many safes trap humidity, which can damage documents or create mold over time. Use desiccant packs or another appropriate moisture-control product, and periodically inspect the contents.
The Higher-Paranoia Tier
Most people can stop after implementing the recommendations above.
People with a higher public profile, significant assets, sensitive responsibilities, or a realistic reason to expect targeted attention should consider going further.
Reduce public records associated with your home
When legally and financially appropriate, consider purchasing a home through a trust or another properly structured entity.
Speak with a qualified attorney and tax professional before doing this. Ownership structures have legal, tax, lending, insurance, and estate-planning implications.
And do not name the trust after yourself.
"The Smith Family Trust" does little to prevent someone from connecting the property back to the Smith family. Choose a generic name that does not advertise the beneficial owner.
Blur your home on Google Street View
Google allows people to request that a residence be blurred on Street View.
This will not make your home impossible to locate, and public records may still identify the property. It does, however, remove an easy source of visual reconnaissance.
Understand that the blur is intended to be permanent before submitting the request.
Remove interior photographs from real-estate sites
After purchasing a home, check Zillow and other real-estate sites for old listing photographs and floor plans.
Those listings may reveal entrances, room layouts, staircases, children's rooms, valuables, windows, security equipment, and access to the backyard.
The house may no longer be for sale, but the reconnaissance package can remain online indefinitely.
Request removal wherever the platform allows it.
Final Thoughts
Personal security is not about living in fear.
It is not about purchasing every security product available or turning your family into full-time incident responders.
It is about reducing avoidable risk.
Use a password manager. Give every account a unique password. Turn on MFA. Protect your email and phone number. Share less information publicly. Keep your devices and router patched. Install working smoke detectors. Change the locks. Light the exterior of your home.
Most of these steps are neither expensive nor technically difficult.
More importantly, most of them continue protecting you after the initial setup is complete.
You do not need to implement this entire playbook in one weekend. Start with the highest-impact basics, complete them properly, and add more protection over time.
Good security compounds.
You will never make yourself impossible to attack.
But you can make yourself substantially harder, less attractive, and more expensive to target.
For most people, that is the right objective.