Brief No. 001 · September 30, 2026

Cybersecurity awareness for people who don't work in IT

Plain-English briefings on phishing, scams, passwords and account safety for households, nonprofits and small businesses. Each one tells you how to recognize a threat, prevent it, respond to it and recover from it.

What's moving this week

Headlines from Krebs on Security, the EFF's Deeplinks and The Hacker News. We link to their reporting and never copy it.

BRF-01 / Internet Safety

Internet Safety

Most online trouble starts on a normal day: an update you put off, a download from the wrong site, a shared tablet nobody locked. This section covers the everyday habits that close those gaps for households, classrooms and small offices.

Read the internet safety briefings

Privacy and digital rights, this week

BRF-02 / Phishing

Phishing

Phishing is a message pretending to be someone you trust so you'll click, sign in or pay. It arrives by email, text, phone and QR code. The delivery changes. The trick doesn't.

Read the phishing briefings

What attackers are sending right now

BRF-03 / Online Scams

Online Scams

Every scam is a story with a deadline. Fake invoices, fake lawyers, fake tech support, fake refunds. We take the script apart so you can see the seams before the money moves.

Read the online scams briefings

Scam and fraud reporting this week

BRF-04 / Password Security

Password Security

The biggest password problem isn't weak passwords. It's reused ones. A password manager and a single good passphrase fix most of it in an evening.

Read the password security briefings

5-minute security check

  • Change your email password to a unique passphrase.
  • Install a reputable password manager.
  • Check your email address at haveibeenpwned.com.
  • Turn on passkeys where your main accounts offer them.

BRF-05 / Multi-Factor Authentication

Multi-Factor Authentication

Multi-factor authentication means a stolen password isn't enough on its own. It's the single setting we most want every reader to turn on, starting with email.

Read the multi-factor authentication briefings

5-minute security check

  • Turn on MFA for your main email account.
  • Move from text codes to an authenticator app where you can.
  • Save backup codes somewhere offline.
  • Tell your team that real support never asks for a code.

BRF-06 / Account Protection

Account Protection

Your email account is the master key, because password resets for everything else land there. Protect it first and a takeover gets much harder.

Read the account protection briefings

5-minute security check

  • Review the recovery email and phone on your main accounts.
  • Check your email settings for unknown forwarding rules.
  • Sign out of devices you no longer use.
  • Turn on login alerts wherever they're offered.

Questions readers ask first

What should I know before getting into cybersecurity awareness?

You don't need technical training to start. Most attacks on individuals and small organizations work by tricking people rather than breaking code, so the habits that matter most are spotting warning signs, using a password manager and turning on multi-factor authentication. Begin with the one account you'd hate to lose, usually your email, and secure that first.

How much does cybersecurity awareness cost in United States, Canada, United Kingdom, Australia, South Carolina, Grand Strand, Myrtle Beach, Conway, nonprofit communities, small-business communities, global English-speaking internet users?

The basics are free wherever you live. Built-in security settings on your accounts, official fraud-reporting services and plain-English guides like ours cost nothing. A paid password manager or formal staff training for a small business or nonprofit adds some cost, but most of the protection comes from free habits you set up once.

Follow on Google News