Part IV · Chapter 25

Digital security for citizens

Most attacks on private individuals succeed not because someone is technically outmatched, but because they arrive at a moment when attention is somewhere else. This chapter is about safe everyday habits, the things that give the most protection for the least effort, about the phone that is now the most important device to protect, and about the scams that hit the largest number of people in Sweden.

  • Citizens and small businesses

Last reviewed

Advice for private individuals tends to be either too plentiful or too vague. Either a list of thirty points nobody gets through, or an exhortation to be careful online. This chapter tries to do something else, to point out the small number of things that actually change the outcome, and leave the rest aside.

It begins with cyber hygiene, the basic habits. What makes a password strong and why the most important thing is still not its strength but that it is not reused anywhere else. What multi factor authentication protects against, and just as importantly what it does not, since that too can be circumvented. Why updates matter more than most people assume. Then follows mobile security, which has become a chapter of its own in people's lives now that the phone carries identification, banking and every login. Whoever loses control of their phone loses more than a phone. The last major section is about scams, the crime problem affecting the greatest number of private individuals in Sweden. It covers how they are constructed, which emotions they exploit, why time pressure and authority recur in almost every setup, and what can practically be done both before and after. What manipulation looks like when aimed at what we believe rather than what we own is covered in chapter 26 on disinformation and source criticism.

Why now comes down to the tools having improved on the other side. Attempted fraud is no longer clumsily worded and easy to filter out on language alone. It is personal, well written, arrives through channels that feel trustworthy and often refers to something that is genuinely true about the recipient. That means the old rule of thumb about spotting scams by their language no longer carries, and the protection has to sit in the habits instead.

This page shows what the chapter covers and why the habits are worth changing. The concrete advice, the checklists and what to do if it has already happened are in chapter 25 of the book.

You are not alone in being a target. But you are alone in being your own first line of defence.

Key insights

  • A handful of habits account for most of the protection. Password management and multi factor authentication make the biggest difference.
  • The phone now carries identification, banking and communication, which makes it the device most worth protecting.
  • Scams rely on time pressure and authority. Pausing is the single most effective countermeasure.
  • Nobody is too uninteresting to be hit. The attacks are rarely aimed at any particular person.

Tools that belong to this chapter

The templates and interactive tools are in the Toolbox, free of charge.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.