12 tips for effective data security in the digital age

Text on a dark blue background reading Dati ir vertiba. Vai Tu tos sarga? (Data is valuable. Are you protecting it?), with the Jumis and possible.lv logos.

In the digital age, where data is as valuable as gold, data security has become one of the most critical issues for both businesses and individuals. As an IT company, we recognize our role in protecting client data, but data security is a shared responsibility. In this article, we will review the essential principles and share practical tips to help you become an active contributor to your own digital security shield.

1. Do not share passwords

Your password is the key to your private space. It should not be shared with colleagues, family members, or customer support staff. Even if you trust someone, sharing a password in any form increases risk. If multiple users access the system, each must register their own username and password, as the system logs actions by username—who created a document, made an edit, deleted a file, etc. If a dishonest employee is involved, data could be deleted or intentionally damaged, and without unique identification, it would be impossible to determine who performed those actions.

Tip: use password managers (such as 1Password) to avoid using weak or repeated passwords.

Each user must register their own account and keep their administrator privileges to themselves so that you can maintain full control over account activity.

2. Two-Factor Authentication (2FA)

2FA is one of the most effective ways to protect your account, even if your password has been compromised. This means that access is only granted when a unique code from a device or app is entered in addition to your password.

We strongly recommend enabling 2FA wherever possible. It is also available in our solution. You can find more information on how to enable 2FA here.

3. Closing the session

Logging out of systems after finishing work is important — especially when using a shared or public computer. Even if you are using your own device, leaving a session open creates an opportunity for attackers.

Tip: enable automatic session termination after X minutes of inactivity, if available.

4. Cookie management and deletion

Cookies store your browsing information to improve user experience. However, they can also accumulate sensitive data and pose security risks.

Information on how to clear cookies can be found here.

A woman in a green top holding and looking at a tablet showing a table and text, indoors.

Manager, would you survive a real cyberattack? Fill out the questionnaire and find out the level of your company's data security!

5. Archive storage and access control

Archives containing sensitive information, such as customer history or financial data, are often saved.

These files must be:

  • encrypted;
  • stored only in trusted locations;
  • with restricted access.

Tip: never save passwords or sensitive data in an unencrypted Excel file on your desktop.

Recommendation: use secure and professional platforms, such as:

  • Microsoft OneDrive for Business or Google Drive with a corporate account, where an auditable access mode is available;
  • SharePoint – especially for teams with multiple users and a need for access control;
  • Proton Drive or Tresorit — if end-to-end encryption is required;
  • Encrypt files locally using BitLocker (Windows) or FileVault (Mac) if stored outside the cloud.

If archives are stored locally (e.g., on a server or external drive), they must be encrypted, and regular backups should be created and stored in a separate, secure location.

6. Using the same username and password across multiple portals

If one site is breached and a password is leaked, scammers can access all accounts where the same combination is used.

Tip: Use a unique password for every system. Password managers make this easy to implement.

7. Why is it important to use an antivirus?

Even the most conscientious user can make a mistake—for example, by receiving an email from a scammer posing as a colleague or partner. An antivirus acts as an automatic layer of protection that shields you at the exact moment an attack occurs.

What does an antivirus do?

  • Monitors all activities to immediately detect suspicious behavior;
  • Scans files before opening them: removes risks before you have even clicked on anything;
  • Protects against unknown threats using artificial intelligence and machine learning;
  • Warns about suspicious links and downloads, especially when browsing the internet.

Tip: Ensure your antivirus is active and updated—this is the only way it can protect you against the latest threats. If you do not use additional software, at least Windows Defender (built into Windows computers) must be enabled.

8. Opening unknown links in emails (phishing)

Users very often fall for seemingly credible emails from "banka.lv" or "your system support team" that contain malicious links.

Tip: Always verify the sender's address, be cautious if you are being rushed ("act immediately!"), and do not enter passwords after clicking a link.

A man in a wheelchair working on a laptop at a desk in an office.

Employees, find out how securely you handle data

9. Downloading files without scanning

Clients often upload files (such as documents, statements, etc.) that contain viruses or macro scripts.

Tip: Before uploading files, ensure they have been scanned with an antivirus. Do not download files from unknown sources.

How can you be sure that the antivirus is actually scanning the file?

  1. Real-time protection is enabled
    Ensure your antivirus is running in real-time (real-time protection)
  2. Check the file manually
    IIf you are unsure, you can perform a manual check: right-click on the file → select "Scan with [antivirus name]."
  3. Use online verification
    If you do not have antivirus software on your computer, use the free online tool VirusTotal: upload the file, and within seconds, you will see if any of the various security systems detect a problem or suspicious content.

Important: Documents (Word, Excel) can also contain macro viruses. If a file prompts you to "Enable macros," be extremely cautious unless it is from a trusted source.

If your antivirus is disabled, for example, while installing another program, be sure to re-enable it as soon as possible.

10. Using public Wi-Fi networks without a VPN

Connecting to Wi-Fi at locations like airports or cafes and logging into systems without an encrypted connection opens the door to "man-in-the-middle" attacks. This is a situation where a third party (the attacker) secretly inserts themselves between two communicating parties—for example, between you and a website—to intercept or even alter the transmitted information.

In short: You think you are connecting to a secure, verified site, but in reality, an attacker is "monitoring" the connection and can access your data—such as usernames, passwords, or credit card information.

Tip: Always use a VPN when working on a public network.

11. Granting unrestricted access to third parties

Access is often shared with third-party service providers or colleagues without appropriate roles, oversight, or time limits.

Tip: Grant access only to necessary users by following the principle of least privilege. This means that a user, program, or system is granted only the access rights required to perform a specific task—nothing more.

In short: everyone receives only as much access as they actually need to perform their job. No one receives the "entire keychain" if they only need one key.

Always delete access rights when they are no longer needed.

12. Failure to disable old accounts or users

For example, employees change jobs, but their accounts are not closed, allowing them to access systems for months afterward.

Tip: establish a process where employee accounts are automatically deactivated if they have not been used for a specific number of days, weeks, or months.

Data security is not a one-time action; it is a daily commitment. It begins with awareness, continues with training, and becomes part of the company culture when the entire team adheres to it. We are here to support you, provide solutions, and help implement best practices, but your active participation is indispensable.

No matter how technologically advanced a system may be, human behavior remains the weakest link in the data security chain. Even one thoughtless step—writing down a password, sharing it with a colleague, or clicking on a seemingly innocent link—can open the door to unauthorized access and the leakage of sensitive data.

This is precisely why data security is not just an IT task—it is the responsibility of every user.

Be vigilant in your daily routine: consider who you grant access to and how. Do not ignore security recommendations. Implement two-factor authentication, use unique passwords, and regularly review your digital habits. Your conscious actions can be the deciding factor in preventing an incident and ensuring a secure work environment for both you and your entire team.

If you have questions about how to improve your security practices, contact our customer support.

Your Jumis!

Possible Security is a cybersecurity firm with deep roots in research, responsible vulnerability disclosure, and practical security problem-solving. Based in Riga, we work with critical infrastructure operators, government agencies, and large enterprises with specialized security requirements worldwide.

Possible Security