How to protect my data online
Kahu team·Updated 2 Oct 2026·6 min read
Protect your email first with a long, unique password and two-step verification, use a password manager for everything else, keep your devices updated, and back up what you cannot lose. Then share less: fewer apps, fewer permissions and less personal detail in places that do not need it.
Start with the basics that stop most problems
Government cyber security agencies in New Zealand, the UK and the US give remarkably similar advice to individuals and small businesses. It is not exotic. It is a short list of habits that, done properly, close the doors most attackers use.
- 1Secure your emailUse a long password you use nowhere else, and turn on two-step verification. Whoever controls your email can reset almost every other account.
- 2Use a password managerIt creates and remembers a different strong password for every site, so one leak does not open everything.
- 3Turn on two-step verificationOn banking, payments, social media and any business tool that offers it.
- 4Update everythingPhones, computers, browsers and apps. Turn on automatic updates so you do not have to remember.
- 5Back up what mattersCustomer records, accounts and photos you cannot replace. Check now and then that a backup actually restores.
Share less in the first place
Data you never hand over cannot leak. Most people have accounts they no longer use and apps with access they no longer need. A short clear-out every few months reduces what is exposed if any one of those services is breached.
- Delete accounts you no longer use, rather than just abandoning them.
- Review which apps can see your contacts, location, photos and microphone.
- Remove old third-party apps connected to your Google, Microsoft or social media accounts.
- Leave optional fields blank on sign-up forms: birthday, phone and address are often not required.
- Think before posting details that answer security questions, such as your pet's name or your first school.
Watch for the tricks that bypass all of this
Strong passwords do not help if you type them into a fake login page. Phishing messages pretend to be your bank, a courier or a supplier and push you to act quickly. When a message asks you to log in, pay or change bank details, do not use its link. Go to the site or call the number you already know.
For a small business team
| What to set up | Why | |
|---|---|---|
| Accounts | One login per person, never shared | You can remove access when someone leaves |
| Two-step verification | Required for everyone by an administrator | A stolen password alone is not enough |
| Customer data | Kept in one system, not copied into spreadsheets and chats | Fewer copies, fewer leaks |
| Payments | Bank detail changes confirmed by phone | Stops invoice and supplier scams |
| Leavers | Access removed on their last day | Old accounts are easy targets |
Frequently asked questions
How do I know if my data has been in a breach?
Own Your Online suggests checking your email address at Have I Been Pwned. If it appears, change that password and any account where you reused it.
Are password managers safe?
Government agencies such as the UK NCSC and CISA recommend them. Protect the manager itself with a strong password and two-step verification.
Do I need antivirus software?
Keep the built-in protection on your device turned on and updated. Updates and careful clicking matter more than any single product.
