Category 06 / ARM.NET

Cybersecurity and privacy

Understand digital threats and the concepts that help protect accounts, devices and information.

What is it about?

Cybersecurity protects systems and data against unauthorized access or changes. Privacy focuses on what information is collected, who can use it and for what purpose.

12 topics explained

Explore this category

01 / 12

Passwords

A password protects an account through a secret. Reusing it links risks: if a service exposes credentials, someone can try them elsewhere. Length, uniqueness and secure storage matter more than predictable cosmetic changes.

Use different passwords and avoid sharing them in messages. If an account warns of suspicious access, visit the official address to review activity and credentials. CISA password advice.

Back to the topic index ↑

02 / 12

Password managers

A manager stores credentials in a vault and can generate different values for each service. It reduces the need to remember many passwords, but protecting and recovering the vault become central concerns.

Understand how to unlock and recover it, and where it stores backups. Check the domain before filling in information. Keep recovery mechanisms accessible without leaving them inside the only system they can recover.

Back to the topic index ↑

03 / 12

Two-factor authentication

Multifactor authentication adds identity checks from different categories, such as something you know and something you possess. Two passwords are not two factors. Methods differ in their resistance to deception and session theft.

Enable the most suitable supported method and keep recovery codes. Never approve a login request you did not initiate. CISA explains multifactor authentication.

Back to the topic index ↑

04 / 12

Phishing

Phishing tries to make someone disclose information or take action by impersonating a trusted organization. It can arrive through email, messages, calls or fake pages. Urgency, payment changes and unexpected access requests warrant verification.

If a message reports an account problem, open the service through a known route and check there. A logo or display name does not prove identity. CISA resources for recognizing phishing.

Back to the topic index ↑

05 / 12

Malware

Malware is software designed to cause harm, spy or perform unauthorized actions. It can enter through files, altered applications or vulnerabilities. Symptoms such as slowness are nonspecific and do not alone prove an infection.

Keep the system updated and use trusted installation sources. When alerted, record what happened and follow official recovery tools and procedures. On a work computer, notify the responsible person before improvising changes that could hinder investigation.

Back to the topic index ↑

06 / 12

Online scams

An online scam manipulates trust, fear or urgency to obtain money, access or data. It may imitate technical support, a purchase or an opportunity. The deception combines convincing messages with an action that benefits the attacker.

Verify payment account changes through a previously known channel. Do not rely solely on contact details in a suspicious message. Keeping messages and transaction details helps report the incident to the affected service.

Back to the topic index ↑

07 / 12

Wi-Fi network security

Wireless security depends on encryption, router configuration and connected devices. The router administrator password and Wi-Fi access password serve different purposes. Sharing one should not mean sharing the other.

Review manufacturer updates, administrator credentials and connected devices. A guest network can separate visitors from the main network if configured to do so. Check its actual isolation rather than assuming the name guarantees it.

Back to the topic index ↑

08 / 12

VPN

A VPN creates a tunnel between a device and another network endpoint. It can protect that segment and enable remote access, but does not remove every trace or stop you from giving data to a fake site. It also changes whom you trust to carry traffic.

Define the goal first: accessing work resources or protecting a specific connection. Review who operates the service and what it logs. The additional route may affect latency. Cloudflare explains VPNs and performance.

Back to the topic index ↑

09 / 12

Social media privacy

A post can reveal information through text, images, location and context. Audience settings limit certain access, but cannot prevent screenshots or copies by people who can already see it. Connected application permissions also matter.

Review audiences, tags, location and active sessions. Before posting a photo, check screens, documents and other people's information in the background. Deleting a post reduces availability but does not guarantee retrieval of all existing copies.

Back to the topic index ↑

10 / 12

Account protection

Protecting an account means securing access, sessions and recovery. The primary email account is especially important because it receives reset links for other accounts. An attacker may retain access through sessions or authorized apps even after some changes.

Review activity and recovery methods on the official site. After unrecognized access, follow its process to change credentials and revoke sessions. Save recovery codes and check that the alternate phone or email remains under your control.

Back to the topic index ↑

11 / 12

Business security

A business needs to know its devices, data and permissions to manage risks. Recoverable backups, updates and separate access help limit mistakes and incidents. Continuity depends on the process working even when a key person is absent.

Assign responsibilities, maintain an inventory and define incident reporting procedures. Test restoration with sample data and review accounts when roles change. Security improves when people know what to do as well as having tools.

Back to the topic index ↑

12 / 12

Vulnerability news

A vulnerability describes a weakness; an advisory should identify affected products, conditions and mitigations. Severity depends on context, exposure and exploitability. A CVE identifier helps cross-reference information but does not alone explain your computer's risk.

Check the model, version and configuration against the vendor advisory. Distinguish a released fix from a temporary measure and check whether the issue is actively exploited. Record applied updates to track what remains pending elsewhere.

Back to the topic index ↑

Where to start

This section organizes concepts such as authentication, online deception and permissions. Specific incidents and vulnerabilities require current vendor information before applying particular instructions.