6 Basic Digital Security Measures Every American Adult Should Have in Place

A huge chunk of your life runs through the internet now, and while this comes with amazing conveniences, it also presents the opportunity for much harm that many have become professionals at exploiting. And while this isn't a comprehensive security guide, these are the 6 basic digital security measures I think every adult American should have in place to protect themselves.
1. Use a VPN
A VPN (“Virtual Private Network”) encrypts the internet traffic coming to and from your devices and hides your real IP address, which is the identifier that ties your online activity back to you and your general location.
The practical benefit comes into play on any network you don't control such as public Wi-Fi at airports, hotels, and coffee shops. On those networks, other users or the network operator itself can potentially see or capture traffic that isn't encrypted. A VPN encrypts it so it's unreadable in transit, and it hides your IP address so advertisers, websites, and bad actors have a harder time profiling and tracking you.
A few other potential terms/benefits of a VPN:
- Rotating IP: your assigned IP address changes periodically, so no single address stays tied to you for long. It's usually included even on most entry-level plans.
- Dedicated IP: a consistent IP address assigned only to you (normally a small add-on, roughly $3.69 to $3.75 a month). It's useful if you access work systems that only allow approved addresses, or if a shared VPN address keeps triggering those “verify you're human” robot checks.
- Bundled antivirus: many providers now include antivirus, malicious-site blocking, and data-breach monitoring in the same subscription.
Two mainstream, reputable options are Surfshark and NordVPN. Surfshark's entry plan runs about $2.49 a month, and its “One” plan (which adds antivirus, breach alerts, and more) is about $2.79 a month on a two-year term. NordVPN starts around $3.09 a month, with higher tiers adding its Threat Protection suite. One caveat worth knowing: those low rates are the multi-year promotional prices and they renew higher, so check the renewal terms before you renew [or switch carriers at that time].
Using a VPN is really quite simple too. You install the app on your phone and computer, toggle it on, and wallah! I will share though that if you get a new iPhone, having a VPN enabled through Apple settings can sometimes trigger a network connection issue, so it's a best practice to toggle off the VPN during the transfer process for iPhones [that was my recent experience anyways].
2. Freeze Your Credit at All Three Credit Bureaus
If you do only one thing on this list, make it this one. It's the most effective and it's FREE!
A credit freeze restricts access to your credit report, which means no one can open new credit in your name until you lift it (including YOU!). Because nearly every new loan, credit card, or form of “credit” requires a lender to check your credit first, a freeze blocks the most common form of identity theft: someone opening accounts in your name. Even if a criminal has your Social Security number, they can't get past a frozen credit file.
A few things people don't realize:
- It's free by federal law, it has no effect on your credit score, and it doesn't expire [it stays in place until you remove it].
- You have to freeze your credit with all 3 bureaus separately. Freezing one doesn't cover the other two.
- Each one takes under 10 minutes online, and the freeze takes effect within one business day.
Here's where to do it:
The most common objection I hear is: “What about when I actually need to apply for a mortgage or a new card?” And for that, you simply temporarily lift (“thaw”) the freeze at whichever bureau that lender uses, which takes a couple of minutes online once you have an online account with that credit bureau. You can set a thaw for a few days or weeks then it will automatically put the freeze back on.
3. Use a Password Manager
Most people reuse the same handful of passwords across [potentially] HUNDREDS of online logins and accounts, and that's the biggest reason one password breach can quickly turn into a more pervasive issue. A password manager solves it by generating and storing a long, unique password for every account then filling them in automatically if you let it, all secured behind one strong “master password” that you actually remember.
Your database of passwords is protected with zero-knowledge encryption, which means the provider itself can't read what's inside [like your actual passwords for instance]. If their servers were ever breached, an attacker would only get unreadable, encrypted data.
Two strong options I've used personally are Bitwarden and 1Password. Bitwarden has a genuinely capable free tier (unlimited passwords across unlimited devices), with Premium at about $20 a year. 1Password is a bit more polished and well suited to families at about $48 a year, though it has no free tier.
Two objections come up a lot. The first is: “Isn't that putting all my eggs in one basket?” In a sense yes, but the tradeoff is the lesser of two evils. One heavily encrypted database you protect carefully is far safer than dozens of weak, reused passwords spread across the internet. The second is: “What if I forget the master password?” The provider can't recover it for you, which is exactly what makes it secure. So write it down once, store it somewhere safe like a fireproof box or safe-deposit box, and set up the recovery or emergency options the app provides. Whenever a new device logs in to your password manager, it requires the master password AND a one-time code (that not even the password manager knows) that is on the recovery or emergency options you put in your secure box/safe. You can even have it so that a piece of hardware (like a specific USB drive) has to be inserted to the computer you are using to be able to access your password vault. There's always a trade-off between inconvenience and security, but I can truly say after using a password manager for some time, the benefits highly outweigh the cost (both saved frustration from forgetting my passwords on different sites to meet their different password requirements and password managers are very cost-friendly).
There's one more benefit that's seldom mentioned: a password manager is a core part of a good digital estate plan. If something happened to you, then your family (or your designated “digital executor”) might be completely in the dark about where all of your assets, debts, and online accounts are. Both Bitwarden (Emergency Access) and 1Password (its Emergency Kit and newer Digital Legacy tools) let you designate a trusted person who can gain access when needed, which makes an already difficult time much smoother for the people you leave behind.
4. Turn On Two-Factor Authentication (and Favor Authenticator Apps)
Two-factor authentication (“2FA”) adds a second verification step beyond your password, so even if someone gets your password, they still can't log in without that second factor.
Not all 2FA is equal though. The text-message codes most people are used to are better than nothing, but they are more susceptible to being intercepted, which is why I think the stronger option is an authenticator app such as Microsoft Authenticator, Duo Mobile, or Google Authenticator. These generate a rotating 6-digit code directly on your device [Microsoft Authenticator requires Face ID to even open the Authenticator App], so nothing travels over the network and there's no phone number to hijack. To break in, someone would need your actual, unlocked phone and your face.
Start with your email, since it's the account most of your others reset through, then add your banking and financial accounts, and expand slowly from there over time.
5. Set Up Push Notifications Every Time Your Credit Card Is Used
Most major banks (Chase, Amex, Capital One, Bank of America, etc.) let you enable a push notification every time your card is charged above a dollar amount you set. Set that threshold low (mine is $0.99) and you'll get a notification on your phone for essentially every transaction. If a charge you didn't make shows up, you'll know immediately and can lock the card and call the credit card company before it goes any further.
With Chase, for example, sign in and go to Profile & settings, then Alerts, set your dollar threshold, and select push notification. Every bank's process is a little different, but nearly all of them offer some version of this.
You're already protected from liability on fraudulent charges with credit cards, but catching it early is still a benefit. Not to mention it helps bring awareness to your spending, since most people pay for a ton of subscriptions they don't know they have (or don't use), and it helps trigger a response in your brain each time you spend money, even if it's an autopay.
6. Learn to Spot a Phishing Attack
You can have all 5 of the above in place and still get compromised if someone convinces you to hand over your most sensitive information directly. Phishing (a fraudulent email, text, or call designed to get you to click a malicious link or give up a password) is how a large share of breaches begin. So this last one is less a tool and more a learned skill. Here's what to watch for:
- Check the sender's actual domain, not just the display name. Anyone can set “Chase Support” as their display name. Click or tap to reveal the real email address, and watch for lookalike domains, like service@paypa1-secure.xyz, where a “1” replaces the “l” in PayPal.
- Hover over links before clicking. On a computer, holding your cursor over a link shows the true destination at the bottom of the screen. On a phone, press and hold to preview it. If the address doesn't match the company's real website, don't click.
- Be cautious when a message pressures you to act fast. “Your account will be suspended in 24 hours, verify now” is written specifically to get you to act before you stop and think.
- Don't rely on “it looks legitimate.” AI has made these messages polished and typo-free, so it's getting more and more difficult to tell at times what is legit vs what is fake. When in doubt, don't click.
Putting It All Together
None of these 6 things are particularly difficult, it just takes a little bit of upfront work and it's pretty smooth sailing from there quite honestly. To me the reward-to-risk ratio is very high for these basic security measures, so I'd encourage you to consider implementing these if you currently don't have them in place. Do one per month if doing all of them at once feels overwhelming, and even at that pace, you'll be much better digitally protected 6 months from now and it's a very manageable cadence.
Prices, plans, and features mentioned above are current as of this writing and change frequently, so confirm the latest on each provider's site before you buy. This post is general education, not personalized security, legal, or financial advice.
More from True Riches
Continue building your financial foundation
Christian Financial Planning to Invest, Give, and Live Abundantly.
Reach out for a complimentary "good fit" consultation.




