For an ordinary person who wants a realistic security baseline across email, finance, social, cloud, and devices. This is defensive hygiene—not hacking—and it prioritizes account recovery, unique credentials, phishing resistance, updates, backups, and a calm incident plan.
Course 11 · Digital playbook 04
Protect Your Digital Life
Secure the accounts, devices, data, and recovery paths that matter most before a crisis happens.
A hardened email account, password manager, stronger sign-in, tested backups, and an incident recovery card.
A useful primer before lesson one.
This video is published by Cybersecurity and Infrastructure Security Agency. It complements the Life Starter sequence; it does not replace the work inside the lessons.
Watch directly on YouTubeKnow the route before you begin.
This is the working brief for the full course: who it serves, what to prepare, what good work looks like, and the language you will use along the way.
- Choose a reputable password manager and update your primary devices.
- Gather recovery emails, phone access, device lists, and current backup information.
- Reserve uninterrupted time for email, financial, and identity-provider accounts first.
- If you suspect active compromise, use a clean device and the provider's official recovery path.
Finish with proof you can use.
A personal security file with a critical-account map, unique managed passwords, phishing-resistant or strongest available MFA, secured devices and recovery methods, a tested 3-2-1-style backup plan, and a printed incident checklist.
The rules behind the steps.
Email is the recovery root
Control of primary email often enables password resets elsewhere, so it deserves the strongest protection first.
Unique credentials contain damage
One stolen password should not unlock every account; reuse turns a single breach into a chain reaction.
Recovery is part of security
Updates and MFA prevent many incidents, while tested backups and documented recovery reduce the impact of those that still occur.
Key terms worth knowing.
- MFA
- Authentication requiring more than one factor, ideally something resistant to phishing such as a security key or passkey.
- Passkey
- A cryptographic sign-in credential tied to a device or password manager and designed to resist phishing.
- Phishing
- A deceptive message or site intended to steal credentials, money, or sensitive information or trigger unsafe action.
- Recovery code
- A one-time backup code used when a normal authentication method is unavailable.
- 3-2-1 backup
- A resilience pattern using three data copies, two storage types, and one copy separated from the primary environment.
Six lessons.
One finished outcome.
Work in order the first time. Each lesson makes something the next lesson can use.
- 1Up next
Map your critical accounts
Identify the accounts and recovery channels whose loss would cause the most damage.
- 225 min
Move to unique passwords
Stop one breached password from unlocking multiple accounts.
- 323 min
Turn on stronger sign-in
Add a second barrier and secure the fallback paths around it.
- 424 min
Spot and stop phishing
Break the urgency-and-impulse pattern used to steal credentials or money.
- 527 min
Secure devices and backups
Reduce damage from loss, theft, malware, hardware failure, and accidental deletion.
- 621 min
Prepare for an incident
Make the first hour of an account takeover or lost device calmer and faster.
Make the lesson easier to act on.
Trust, then verify.
The practice sequence is original editorial synthesis. Current rules, safety details, and platform requirements should be confirmed with these primary or authoritative sources. References reviewed September 9, 2026.
Start with the first useful move.
You’ll always know what to do, what to make, and where to go next.
Illustrative fit—not a recommendation: Password managers, security software, backup services
See open opportunities