A couple of weeks ago I got a text from my dad that said, “Should you use a password manager?“
It was the last call from my parents (and my family in general) for help in cybersecurity. The most recent call before this came from my mom, asking why “tech support” had appeared on her PC and seemed to have taken control of your screen.
I’m always happy to help solve the mysteries of the digital world when I can, and I must emphasize that my parents are not Luddites. They just don’t live completely in the digital world like many of us do.
To help you be proactive, I thought I should probably set up a cybersecurity best practices document they might refer to when considering what is important and what is not.
this is that listClean and easy to read for anyone else who is quietly managing their family’s IT support over group chat.
Fix these security flaws TODAY
Here is a list of security loopholes that need to be fixed as soon as possible. All of these require fairly little effort and should be followed on virtually any PC you or your family are using.
Enable Windows Hello
Windows Hello It is one of Microsoft’s best security features. It can be used as a PIN, fingerprint, or face scan and effectively protects a Windows 11 PC from external physical threats.
Windows Hello can be configured by navigating to the Settings > Accounts > Sign-in options section in Windows 11.
Make sure Windows Update is actually running
Windows Update provides security patches periodically. Without it enabled, a PC becomes less secure over time.
You can navigate to Settings > Windows Update to know if updates are active or paused. It’s never a bad idea to check for updates while you’re there.
Make sure Windows Defender is turned on
Windows Defender is Windows 11’s built-in antivirus and is surprisingly effective at blocking malware and other threats. Defender is usually enabled by default, although third-party antivirus software can sometimes interfere and result in a confusing, half-disabled state.
Navigate to Settings > Privacy and security > Windows Security > Virus and threat protection to confirm that everything (especially real-time protection) is active and no action is required.
Activate the “Find my device” function
When a laptop is lost, forgotten, or worse, stolen, having Windows 11 Find my device Feature enabled often means the difference between “it’s gone forever” and “I can figure this out.”
With Find My Device enabled, you can see where your PC is and lock it remotely to prevent intrusions.
Navigate to Settings > Privacy & security > Find my device to enable and disable the settings, as well as view all PCs linked to your account.
Perform these security measures once and for all
These security measures only need to be applied once and can make a big difference in how security and privacy are handled.
Switch from a local account to a Microsoft account with 2FA
This is a solution that can make a big difference when something goes wrong on a PC as it provides a convenient recovery path. A Microsoft account makes it easy to back up and sync devices; allows you to change your PC password online and protects digital licenses in your email.
When you sign in with a Microsoft account, two-factor authentication (2FA) can be enabled, adding additional security in case a password is leaked.
Navigate to Settings > Accounts > Your information to change the way you sign in to your Windows 11 PC.
Enable device encryption
Device encryption It’s essentially the only thing standing between a stolen laptop and stolen data.
If a drive is not encrypted, it can simply be removed from an otherwise locked PC, plugged into a different PC, and openly read.
Windows 11 has a built-in encryption feature that handles these things pretty neatly. In Home versions, it is simply known as Device encryption; in Pro versions, it is known as BitLocker.
Either way, you can navigate to Settings > Privacy and security > Device encryption and enable it.
Switch from a Windows 11 administrator account to a standard account
Windows 11 PCs generally default to the first account created to be a Administratormeaning that any software that runs gets full permissions on the system.
Since this can include malware, it is much better that everyday computing is handled in a Standard account.
Navigate to Settings > Accounts > Family to add or change accounts. You can use the Standard account as a daily driver and only switch to the administrator account when something needs to be installed (legitimate).
Use a password manager
The tip that started this security cheat sheet involved a password managersomething I consider absolutely mandatory for any Internet user in 2026. I don’t know exactly how many people are still recycling passwords they’ve used for decades, but I’m sure I’d be surprised to know.
Instead of asking my parents to create new passwords, I set them up with a password manager that takes all the effort and memorization out of the equation.
This specialized tool should absolutely contain the most important passwords for banking, shopping, email, etc., and should be allowed to create the strongest passwords possible.
NordPass NordVPN is what my dad finally decided on (I already had him using a VPN), but there are great VPN options. 1password, bitwardenand Proton. Heck, even the Edge browser can manage passwords in a pinch.
The best cybersecurity habits to get used to
Even with the above methods completed, the fight against bad actors online is far from over. There are a few habit-level best practices that I’ve tried to instill that should go a long way toward keeping our PCs secure.
Learn how to spot phishing scams
Phishing scams can come from virtually anywhere. It could be an email. It could be a compromised web page. It could be a phone call.
If you suspect something is wrong, stop what you are doing and investigate further. Is the email address the message was sent from really legitimate? Does the URL of the web page you are viewing look familiar? Do you know the person on the phone?
Learning to recognize phishing attempts and other scams is not always easy, but it is something we should all practice.
Never think that someone is calling you on your PC
I have never received a legitimate phone call in my life asking me about my computer.
Whether it’s “Microsoft support,” a bank’s fraud department, or some other strange institution calling you about your PC, there’s a good chance it’s a scam.
The same goes for pop-ups. If you see a phone number on your screen asking you to call it immediately for assistance, it is a scam.
Premium: Under no circumstances should you share your passwords online, over the phone or anywhere else.
Never install unsolicited software on your PC
A classic scam involves a user installing remote access software on a PC, giving criminals control over the computer.
If someone on the phone tells you to install something like AnyDesk or TeamViewer (or really any software) to fix the problem, just hang up.
I want to know your cybersecurity tips!
The cybersecurity cheat sheet I’ve created here is definitely missing some valuable tips and tricks, and I’d love for you to share them in the comments section below.
And while I originally created this guide for those who often deal with IT support in their family and friend groups, it should serve as a solid reference for anyone looking to make their PC more secure.
Join us on Reddit at r/WindowsCentral to share your ideas and discuss our latest news, reviews and more.




