Toolkit by Bot&Partners / Security

Security

How protection of accounts, devices and documents is built, what exactly each measure protects against, and how to set up the basics in one evening. Anyone who works with other people's data, money or documents, such as a lawyer, an accountant, an HR officer, a journalist or an executive assistant, keeps in their email, phone and laptop things that interest more people than just them.

  1. 1What we protect against
  2. 2Passwords
  3. 3Second factor
  4. 4Phishing and spoofed addresses
  5. 5Scenario: Friday, 4:40 pm
  6. 6Encryption
  7. 7Devices and backups
  8. 8Access and leaks
  9. 9AI and confidential data
  10. 10Set it up in an evening
  11. 11If it happens

What we protect against

Security starts not with a program but with three questions. What I protect: email, accounts, client or company documents, the phone, money. From whom: from mass mailings that send the same message to millions; from a targeted attack on a specific company, firm or case; from an accidental mistake, a colleague's or your own. What happens if the protection fails: an inconvenience, lost money, a disclosed secret.

The answers to these questions are called a threat model. It shows where simple protection is enough and where something stronger is needed. For most people who work with documents the main risks are mundane: a reused password, a phishing email, a document shared with “anyone with the link”, a lost phone without a lock. A few habits and settings protect against them, and this practicum is made of exactly those.

Protection works in layers. No single measure covers everything: a password can be stolen, a second factor can be bypassed by phishing, encryption does not help if the laptop is unlocked. Each layer stops part of the attacks, and together they make an attack expensive and noticeable.

Which risk is it

More: what others find interesting in work data

Email. It is how access to every other service is recovered, and it holds correspondence with clients and colleagues, and payment details. A hacked mailbox gives away both the secrets and the ability to write in your name.

Payment details and money. Companies, accounts departments, law firms and their clients often send invoices and bank details by email. Swapping the account in an email (see the “Phishing” section) earns fraudsters more than most other attacks.

Work documents. Contracts, case materials, HR records, financial statements, personal data. A leak harms the people whose data it is, and in professions with a duty of confidentiality, such as a lawyer or an auditor, it also breaches that duty.

Devices. A phone with messengers and second-factor codes, a laptop with documents. They get lost more often than hacked.

Passwords

A site does not store your password in plain form. It stores a hash: the result of a one-way function from which the password cannot be computed back. At login the site hashes what you entered and compares it with what is in the database.

Site databases leak regularly. A hash is not decrypted, it is guessed: attackers take millions of known passwords, dictionaries and common patterns (“Kyiv2024!”, a name plus a year), hash each one and look for a match. Short and patterned passwords are found quickly. The “email and password” pair found this way is then tried automatically on other services. If the password is the same, everything opens.

Hence two rules. A password should be long and random: each extra random character multiplies the number of candidates. And each service gets its own password, so that a leak from one site stays a leak from one site. Nobody can remember dozens of such passwords, so a password manager keeps them.

Film. From a site's database to a hacked mailbox: how passwords are stored, how they are guessed after a leak, why length matters more than complexity, and how a password manager breaks the chain.

How many candidates a password has

Enter a password similar to yours, but not the real one. The estimate is computed in the browser and sent nowhere.

    The estimate is simplified: it counts length, character set and the most common patterns. Real cracking programs know many more patterns, so the actual strength of a patterned password is even lower.

    More: what the standards say

    The US standard NIST SP 800-63B, which many organizations follow, dropped the old requirements of “a capital letter, a digit, a symbol and a change every quarter”. Instead: a password that is the only login factor must be at least 15 characters long; it is checked against lists of known breached passwords; forced periodic changes are not required, and a password is changed when there are signs of compromise.

    A phrase of several random words (“cliff pepper morning lamp wind”) is long and easy to remember. The word “random” matters: a line from a song or a proverb is in the cracking dictionaries.

    A password manager (Bitwarden, 1Password, KeePassXC and others) generates and stores unique passwords, fills them in only on the right domain and shows where a password is reused or has turned up in leaks. The manager itself is protected with one long master password and a second factor.

    Second factor

    A second factor adds to what you know (the password) something you have: a phone, a code app, a physical key. Then a stolen password is not enough. It is the single most effective setting for an account.

    Factors differ in what they protect against. An SMS code can be intercepted or obtained by reissuing the number on a new SIM card. An app code is generated on the phone, but it can be entered on a fake site, and the fraudster will use it within seconds. A passkey or a physical key checks the site's address itself and signs nothing for a fake. That is why such keys are called phishing-resistant.

    Film. Four kinds of second factor and one attack: a fake site. Watch at which step each factor stops it or lets it through.

    What each factor stops

    Pick an attack and see which factors protect against it.

    More: where to start and how not to lose access

    Start with email: it is how passwords to everything else are reset. Then the password manager, the bank, the cloud with documents, messengers, work systems.

    Turn on the strongest factor the service supports: a passkey or a physical key, then a code app, SMS only when there is nothing else. Push confirmations are convenient, but fraudsters send them in bursts until the person taps “yes” out of fatigue; services that ask you to enter a number from the screen are better protected against this.

    Keep recovery codes offline: print them or store them in the password manager. Add a second key or a second device. Otherwise a lost phone means lost access.

    Phishing and spoofed addresses

    Phishing is an email, message or site that poses as a familiar sender to get you to enter a password, open a file or pay. Mass phishing is easier to recognize. Targeted phishing knows your name, your project or case, your counterparty, and arrives at a convenient moment.

    The main check concerns the address. A link shows one text and leads to another domain. A domain can differ by one letter, contain a Cyrillic “а” instead of a Latin “a”, or hide the real address at the end: in “bank.ua.login-secure.com” the domain owner is “login-secure.com”, not the bank.

    For companies that pay invoices the most costly variety is a swapped account number in correspondence. A fraudster breaks into the supplier's mailbox, reads the correspondence for weeks and at the right moment writes “our bank details have changed”. The protection is procedural, not technical: any change of payment details is confirmed by a call to the number from the contract, not from the email.

    Take an address apart

    Paste a link or click an example. The breakdown shows who actually owns the address.

      Find the warning signs in the email

      An email came from the “supplier”. Click the parts that make you suspicious. Found: 0 of .

        Film. How an account swap happens: the supplier's mailbox is hacked, weeks of silence, an email with new bank details, and the procedure that stops the payment.

        Scenario: Friday, 4:40 pm

        A client forwards a supplier's email with new bank details and asks for a quick answer. Here you are an outside adviser, but the steps are the same for an accountant, a procurement manager or an executive assistant. Go step by step: each choice leads on or into a dead end you can come back from. At the end you see the path you took and the branches you did not turn into.

        An email with changed bank details

        Encryption

        Encryption turns data into a string of characters that only a key can open. The main question about any encryption: who holds the key. The answer decides whom it protects against.

        In transit (https, TLS): data is encrypted between your device and the server. The Wi-Fi owner and the internet provider see only the fact of the connection and its volume. On the server the data is opened. On the server: the service stores data encrypted, but holds the keys itself; this protects against outside intruders, not against the service or a lawful request to it. End-to-end (as in Signal): the keys are only on the participants' devices, and the server forwards sealed envelopes it cannot open. Disk (FileVault, BitLocker): the contents of a lost laptop cannot be read without the login password.

        Encryption moves the weak point to the device. An unlocked phone shows everything that is encrypted in transit and on the server. That is why the screen lock and disk encryption matter as much as a secure channel.

        Film. One message and four kinds of encryption. Each shot shows who can open the envelope.

        Who can read it

        Choose how you send a document and see who along the way can see its contents.

        More: VPN, public Wi-Fi and metadata

        A VPN wraps all traffic in a tunnel to the VPN server. The internet provider sees only the tunnel, and the VPN company sees the sites. A VPN does not make you invisible, it moves trust from the provider to that company, so choose it carefully. On open Wi-Fi in a café, https already protects the contents; a VPN also hides which sites you visit.

        Metadata is data about data: who wrote to whom, when, from where, how much. End-to-end encryption hides the contents, but part of the metadata stays with the service. In documents, metadata means the author, the time of edits, hidden comments; see the practicum “Document: structure and assembly”.

        Devices and backups

        Most attacks on devices use known vulnerabilities for which updates have already been released. So automatic updates of the system, the browser and apps close more holes than any separate security program.

        Three things protect a lost device: a screen lock with a PIN or password, disk encryption, and the ability to locate and erase the device remotely. On modern phones encryption turns on together with the PIN; on laptops it is turned on in the settings (FileVault on a Mac, BitLocker or “Device encryption” in Windows).

        A backup protects against loss: a broken disk, theft, ransomware that encrypts files and demands a ransom, or your own mistake. The 3-2-1 rule: three copies of the data, on two different media, one of them outside the office. A backup that has never been test-restored is only the promise of a backup.

        Check your backup plan

        Tick what you already have. The check shows what the plan protects against and what it does not.

          Access and leaks

          Incident reports show year after year that the human factor is involved in most breaches: a wrong recipient, an open link, a document published without checking, a password in a text file. Big hacks of large services are rare; everyday leaks through access settings happen daily.

          A cloud document shared with “anyone with the link” is open to anyone the link reaches. Links get forwarded. One forward, and the document is with a third party without any hacking. The rule of least privilege: give access to specific people, only for the time needed and only at the level needed (view, comment, edit).

          How to share

          AI and confidential data

          The question “is it safe to give documents to AI” is really four. Can the request be read in transit: no, the channel is protected by TLS, as with a bank. What does the service do with the data once it has it: that depends on the plan and the settings, in particular on whether conversations are used for training and how long they are kept. Can someone oblige the service to keep or hand over the data: a court can, and such cases have already happened. What data did you hand over yourself: that depends on your habits.

          A working approach has three levels. Tasks without sensitive data: any plan with training turned off. Client materials, HR and financial documents: a business plan or the API, where training is off by default, plus anonymizing everything that can be removed without losing meaning. The most sensitive: a local model whose data never leaves the organization's perimeter. More on training and data retention in the practicums “How a language model works” and “Working with an assistant”.

          Set it up in an evening

          The steps in order of importance. Tick what you have done: the ticks are stored only in this browser. App names are given as examples, not as advertising; choose what your system supports and your organization trusts.

          Checklist

          If it happens

          After an incident, speed and the order of actions matter. Changing the password without signing out of all sessions or without checking the forwarding rules in the mailbox leaves the fraudster access. Below are five typical situations and the steps for each.

          Check yourself

          Practice

          1. A threat model of your own workWrite down what you protect (email, accounts, documents, devices, money), from whom, and what happens in a leak. Mark the three most likely risks and, for each, one protective measure from this practicum.
          2. Check your email in leaksCheck your address on haveibeenpwned.com. For each leak, find out whether the same password was used elsewhere, and change it there.
          3. Second factor on your emailTurn on the strongest available factor on your main email and keep the recovery codes offline. Write down which factor you turned on and where the codes are.
          4. A shared-access auditOpen your cloud drive and find files shared “by link”. For each one, decide: close it, limit it to specific people, or leave it and write down why.
          5. A procedure for changed bank detailsWrite a half-page procedure for your team or firm: how a counterparty's change of bank details is confirmed, who the second person is, what to do if confirmation fails.

          What to take away

          1. Protection works in layers. No single measure covers everything.
          2. A long unique password in a password manager and a second factor on your email close off most everyday attacks.
          3. Passkeys and physical keys resist phishing; SMS and app codes do not.
          4. Check the address, not the look. Confirm changed bank details by calling a known number.
          5. About any encryption, ask who holds the key.
          6. Updates, a screen lock, disk encryption and a tested backup protect devices better than any single program.
          7. Give access to specific people and for the time needed, not “by link”.

          Sources