Security advice is most useful when it responds to your actual risks. A personal security plan—sometimes called a threat model—helps you choose proportionate protections instead of trying to defend against everything.
Step 1: List what matters
Write down the things that would cause real harm if they were exposed, altered or lost. Consider:
- access to your primary email account;
- private conversations, photographs and documents;
- your location and daily routines;
- financial accounts and identity documents;
- access to your phone and computer;
- the separation between personal, professional and public identities.
Include people who depend on you. Protecting a shared family account may matter more than hardening an account you rarely use.
Step 2: Identify likely problems
Ask who might want each item and why. Common examples include opportunistic criminals, abusive partners or relatives, data brokers, employers, online harassers and government authorities.
Be specific. “Hackers” is too broad to guide a useful decision. “A criminal using a leaked password to access my primary email” points towards concrete safeguards.
Step 3: Consider consequences
For each realistic problem, note what could happen. Could you lose money, be locked out of other accounts, expose someone else, lose your job or face physical danger?
If a consequence could involve stalking, domestic abuse or immediate physical danger, seek specialist support before changing devices or accounts. Sudden changes can sometimes alert the person responsible.
Step 4: Rank risks
Prioritise risks that are both plausible and harmful. You can use three simple labels:
- Act now — likely or potentially severe.
- Plan next — meaningful, but not urgent.
- Accept for now — low likelihood or limited impact.
Step 5: Choose proportionate safeguards
Match one or two actions to each priority risk. For example:
- unique passwords and two-step verification for account takeover;
- full-device encryption and backups for a lost laptop;
- a separate email address for separating identities;
- removing location metadata before publishing photographs.
Every safeguard has costs in time, convenience and recovery complexity. Record those trade-offs so the plan remains realistic.
Step 6: Verify and revisit
Check that each safeguard actually works. Save recovery codes, test a backup and confirm that account alerts reach you. Review the plan after a major life change, a security incident, or at least every six months.