The Cybersecurity Assumptions I Still Have to Talk People Out Of
The Cybersecurity Assumptions I Still Have to Talk People Out Of
Most of the cybersecurity myths I hear these days aren't the obvious ones anymore. People have generally caught up on "don't click suspicious links" and "use a password manager." What I still run into constantly are quieter assumptions, ideas that sound reasonable enough that nobody thinks to question them, right up until they cause a real problem. These five are the ones I find myself talking people out of most often, and each one is more load-bearing than it looks.
I'm Too Small a Target for Anyone to Bother With
This is the assumption I hear most from individuals and small business owners alike, and it comes from picturing a hacker as someone deliberately choosing to target you personally. That's not how most attacks work. The vast majority are automated, scanning huge ranges of addresses and accounts for known weaknesses, with no idea or interest in who's on the other end until something responds. Your data has value regardless of how interesting you think your life is, an email account can be used to reset other accounts, a small business's customer list can be sold, a home network's processing power can be quietly borrowed for something else entirely. I've seen this assumption do real damage precisely because it stops people from taking basic precautions they'd otherwise consider obvious. Scale doesn't protect you here, it just means you're one target among millions rather than one target among thousands, and the automation doesn't care about the difference.
A Strong Password Alone Is All the Protection I Need
A genuinely strong, unique password is a good foundation, but I still meet people who treat it as the entire security strategy rather than one layer of it. The problem is that a password can be compromised in ways that have nothing to do with how strong it is, through a data breach at a company you trusted, through a phishing page convincing enough that you typed it in yourself, through malware quietly logging your keystrokes. None of those scenarios care how many symbols or how much length your password had. Two-factor authentication is what actually catches you when the password itself fails, because it means a stolen password alone isn't enough to get in. I treat a strong password as step one of two, never as the whole job, and I'd rather have a slightly weaker password with 2FA turned on than a brilliant password without it.

I'd Notice Straight Away If I'd Been Hacked
This one comes from imagining a hack the way it's shown in films, a locked screen, a ransom note, something dramatic and immediate. Most real compromises are quiet on purpose. Someone who gains access to an account often wants to stay unnoticed for as long as possible, reading emails, watching for anything financially useful, waiting rather than announcing themselves. A compromised account can sit there being monitored for weeks before anything visibly changes. This is exactly why I check my accounts' recent login activity periodically rather than waiting for something to feel obviously wrong, and why breach notification services that tell you when your email turns up in a leaked database are worth actually signing up for rather than ignoring. Silence isn't the same as safety, it's often just the attacker being patient.
Incognito Mode Keeps My Browsing Actually Private
I understand exactly where this one comes from, because incognito or private browsing genuinely does something useful, it stops your browser from saving history, cookies, and form data locally on your device once you close the window. What it doesn't do is hide your activity from your internet provider, your employer if you're on a work network, or the websites you actually visit, all of whom can still see exactly what you're doing in real time. I think of incognito mode as a local privacy tool, useful for not leaving a trail on a shared device, rather than an actual privacy tool in the wider sense. If what you actually want is to stop your browsing being visible to your network or provider, that's what a VPN like NordVPN is for, and the two aren't interchangeable even though people often assume they do the same job.
Deleting an App Removes Its Access to My Data
I used to assume this myself, that removing an app from my phone was the same as cutting off whatever access I'd granted it. It isn't, necessarily. Deleting an app removes it from your device, but any permissions or connections it set up elsewhere, a linked account, an API connection, a granted data-sharing agreement, can still exist entirely independently of whether the app itself is still installed. I now make a habit of checking the connected apps and third-party access lists inside accounts like my email and social media every so often, rather than assuming a deleted app took its access with it when it left my phone. It's a five minute check that's turned up more forgotten connections than I expected the first time I actually looked.
None of these five assumptions are unreasonable on their face, which is exactly why they're worth naming directly rather than assuming everyone's already past them. Believing you're too small to matter, treating a password as the whole defence, expecting a hack to announce itself, mistaking incognito mode for real privacy, or thinking deletion equals disconnection, each one quietly removes a step that would otherwise catch a problem earlier. I run NordVPN across my own devices specifically because it closes the gap that incognito mode leaves open, and I've written separately about the antivirus-specific myths I hear just as often, along with the small handful of habits I'd actually tell a beginner to start with first. If you want a second, independent source on any of this, the NCSC publishes its own guidance for individuals and small businesses, and my free Safety Toolkit covers the rest of what I'd recommend if you want to work through your own setup properly.
