Skip to main content
The Digital Safety Pack

Digital safety when you are the whole IT department: the complete guide

How to secure your accounts, recognise phishing, look after customer data under GDPR, and keep running when things break, in dependency order.

Updated September 2026

Most security writing is aimed at one of two people: someone with a security team, or someone who already enjoys this subject. This guide is for the third person. You run a small business, or just a household's worth of accounts, you know your password habits are bad, and you have been meaning to deal with it for about four years.

If you administer systems professionally, none of this will be new to you. If what you want is anonymity from a government, or advice on operating outside the law, this is the wrong page entirely. Everything here is defensive and fairly ordinary: recognising a fake message before you click it, making a stolen password useless to whoever stole it, keeping the customer data you hold from becoming somebody else's property, and staying functional when a service you depend on goes down. The bar is not "unbreakable". The bar is "not the easiest house on the street".

The map: five layers, in dependency order

Digital safety splits into five things: your credentials, your ability to recognise an attack, the extra surface a business adds, the obligations attached to other people's data, and what happens when something breaks for reasons nobody attacked you over. Most people start in the middle, learning to spot suspicious emails, and skip the layer underneath.

Credentials come first, and the reason is unglamorous arithmetic. Detection is a skill with a failure rate. Every book in this pack concedes that a good enough fake gets through eventually. A password manager and second-factor authentication change what a single failure costs. Two-factor turns a successful phish from a loss into a bad afternoon. Reversing the order, sharpening your detection while one reused password still opens fourteen accounts, leaves the expensive failure mode fully intact.

Recognition comes second, because it is the layer that fails gracefully once the first one is in place. It is also the layer that never finishes; the shapes change.

The business layer comes third. It is not a different discipline, it is the same discipline with more accounts, more people holding keys, and money moving through some of them. It genuinely depends on the first two: your admin account is a personal account, and the person most likely to be targeted at a five-person company is the founder.

Compliance comes fourth, after security rather than instead of it. A privacy policy describing controls you have not implemented is a written record of what you failed to do. The dependency runs one way. You can be secure and non-compliant, but you cannot be compliant and insecure for long.

Continuity comes last, and it is the layer people either ignore completely or over-invest in. Backups, redundancy, a plan for the week the power or the platform is out. Ransomware and a flooded basement destroy your data by different routes and are solved by the same backup.

Your own accounts, before anything else

Protect Your Digital Life opens with the image that explains most attacker behaviour: a robber does not target Fort Knox when there is a house down the street with the door left open. Criminals sort by effort, not by how interesting you are. Almost all consumer-level compromise is opportunistic.

The book's core structure is what it calls the cyber shield (front door, devices, backups), and the front door is credentials. Its practical claim is that you do not need to become technical, you need a small number of habits that hold. The kit's 5-Minute Password Manager Setup and Two-Factor Authentication Quick-Start guides exist because those two moves, done once, retire most of the risk you carry.

The backup half is the 3-2-1 rule, reproduced in the kit's Digital Data Backup and Recovery checklist and worth stating exactly: three total copies of anything you care about, stored on two different media types, with one copy offsite or in the cloud. Three copies covers corruption. Two media types covers a technology-specific failure: the external drive family that dies at four years, the cloud account that gets locked. One offsite copy covers fire, flood and theft, the events that take every local copy at once.

The mistake that costs most here is doing the setup and never verifying it. A backup nobody has restored from is a hypothesis. Restore one file, deliberately, and you learn whether the system works before the day you need it to.

Start with the credential and backup layer in Protect Your Digital Life, which covers the password manager migration, second factors, and the monthly review that keeps them from drifting.

The message that gets through

Phishing Exposed is built on a premise worth sitting with: phishing is not a technical attack, it is a psychological one, which is why security-conscious professionals still fall for it. The book names four cognitive biases that do the work: urgency, which forces a fast emotional decision; authority, which borrows a trusted brand or a boss; scarcity, which manufactures a closing window; and curiosity, which baits an information gap you feel compelled to close.

That framing is more useful than a list of red flags, because it tells you where your own risk lives. The message that will get you is not the badly written one. It is the well-written one that arrives at the exact moment you are expecting something like it: the delivery notice during the week you ordered something, the invoice on the day you were chasing an invoice.

Which is why the countermeasure is a rule rather than a judgement call. The bundle's 7-Second Phishing Detection Protocol and its 12 Quick Checks to Expose a Phishing Scam both work the same way: a fixed sequence you run when a message asks you to log in, pay, or hurry, applied regardless of how legitimate the message feels. Feeling legitimate is the product the attacker is selling.

The second half of the bundle is the part most people skip until it is needed. Its Post-Phishing Incident Response checklist sequences containment before cleanup (change the credential, revoke the sessions, then work out what was taken), and its Full Device Protection checklist walks the boring settings that reduce the blast radius: disk encryption on, automatic updates on, remote wipe configured, third-party cookies blocked, unused extensions removed. It ends with a recurring calendar appointment it calls a Security Sunday, monthly, for the maintenance that otherwise never happens.

The full walkthrough of the psychology, the five channels phishing now arrives through, and the recovery sequence is in Phishing Exposed.

What changes when a business is on the other end

Online Business Security Best Practices leads with an Accenture finding: small businesses absorb more than 43% of cyberattacks while only 14% are prepared for one. Treat the exact figures as directional (vendor-adjacent research usually is), but the shape is right, and the reason is not that small businesses are interesting. It is that they hold real customer and payment data behind consumer-grade defences.

Three things genuinely change when a business is involved. Access becomes plural: other people hold keys, and the day someone leaves is the day you find out whether you can remove them. Money moves, which adds payment gateways and fraud to the surface. And your email account stops being correspondence and becomes the reset mechanism for everything else you own.

The book's most actionable correction is small and specific: use a password manager built for teams rather than an individual plan shared around. The feature that matters is not the vault, it is the ability to revoke one person's access to everything in a single action. Individual plans cannot do that, so offboarding turns into a memory exercise conducted under time pressure.

The kit is organised as a thirty-day implementation plan rather than a reading list, and includes a 21 Free Security Upgrades listicle for the zero-budget version, a Business Password & Access Protection Plan, a Data Backup Strategy for Online Businesses, and a listicle on seven blind spots that tend to survive an otherwise careful setup.

The business-scale version (team access, payment security, backups sized for a company) is covered in Online Business Security Best Practices.

The data you hold about other people

Compliance is the layer people either panic about or resent, usually because it arrives as a cookie banner and a policy copied from a template. GDPR Compliance for Business Websites is more useful than that, mostly because it treats the regulation as a data-handling discipline rather than a document exercise.

Its starting move is a data inventory: every place your site collects personal data, what you collect, why, where it goes, and what protects it. The book calls that inventory the roadmap, and it is right, because you cannot write an honest privacy policy about collection you have not mapped.

Two principles do most of the work. Purpose limitation says each use of personal data needs its own legal basis: collecting addresses for shipping does not license you to market to them. Data minimisation asks one question before you add any field to a form: do you really need this information to provide the service. If you collect phone numbers and never call anyone, that field is pure liability. Data you never collected cannot leak, cannot be subject to a deletion request, and cannot appear in a breach notification.

The operational half is consent withdrawal, and the book's specification is concrete: offer multiple withdrawal routes (email, account settings, contact form), process the request within 72 hours, confirm the withdrawal and what it means, update every downstream system, and keep the record. Most small sites fail on the fourth item: the unsubscribe works while the CRM, the ad platform and the spreadsheet quietly retain the person.

The kit covers the same ground as working material rather than theory, including a cookie consent implementation guide and a privacy policy component checklist. The full treatment is in GDPR Compliance for Business Websites.

When the disruption is not digital at all

The Ultimate Survival Prepper is the odd one out in this pack, and it is worth saying so plainly rather than pretending it fits neatly. It is not about cybersecurity. It is about the week the power is out, the supply chain stalls, or a weather event closes the roads.

What makes it belong is the reasoning, which is the same reasoning as the 3-2-1 backup rule applied to physical life. Its layered preparedness timeline sets three benchmarks (72 hours, two weeks, three months) and insists you start with a home inventory, because most households already own scattered pieces of the first layer and buy duplicates instead of filling actual gaps. The 72-hour layer is specified rather than vague: at least one gallon of water per person per day, food needing no preparation at around 1,500 calories per person daily, and both ambient and task lighting.

The genuinely transferable framework is PACE (primary, alternate, contingency, emergency), a communication plan with four ranked fallbacks. Text messages as primary because they survive network congestion better than calls, landline or VoIP as alternate, two-way radios as contingency, and a pre-arranged physical meeting point as the last resort. Paired with what it calls the 10/20 rule, checking in at 10 AM and 10 PM with twenty minutes of listening time if contact fails, it is a plan a family can actually execute.

Its one instruction we would generalise to everything in this guide: test the backup systems. Run the generator monthly under load. Restore the file. Try the second factor on a device you have not used it on.

The home and family resilience layer is covered in The Ultimate Survival Prepper.

How to start this week

Two hours, no budget, in this order:

  1. Install a password manager and move your five most important accounts into it. Email first, because email is how every other password gets reset. Then banking, then the platform your business runs on. Generate new passwords for those five rather than importing the old ones. Leave the other ninety accounts for later. They are not what gets you hurt.
  2. Turn on two-factor authentication for those same five accounts. An authenticator app beats SMS, since SMS codes can be intercepted through your phone carrier. This is the single change with the best ratio of effort to risk removed, and it takes about fifteen minutes.
  3. Verify one backup. Pick a file that would ruin your month if it vanished, and restore it from wherever you think it is backed up. If you cannot, you have just found the actual problem, which is worth more than a perfect password.

Then adopt one rule for messages: when anything asks you to log in, pay, or hurry, you do not use the link. You go to the site the way you normally do and check there. It costs twenty seconds and defeats most of what will be aimed at you.

If the business layer is where your gaps are, most of the surrounding decisions (entity setup, contracts, the systems that hold customer data in the first place) sit in The Business Foundations Pack guide. And if the preparedness section was the part that landed, the household side of it continues in The Home & Relationships Pack guide.

Take the whole pack

5 bundles, 44 items, one flat $29. Instant download, yours to keep.