Security & Safe Computer Habits
✓ CompletedAs a VA, you'll be trusted with other people's files, accounts, and sometimes their customers' information. Protecting that trust is part of the job.
This lesson isn't about being afraid of your computer. It's about a handful of habits that prevent most problems before they happen.
Passwords
- Use a different password for every account. If one website is hacked, a reused password opens all your other accounts too.
- Make passwords long. A phrase of several random words is stronger and easier to remember than a short jumble.
- Use a password manager to create and remember them for you. Most browsers include one, and separate apps like Bitwarden or 1Password work across devices.
- Never send passwords in a chat message or email. Many clients share account access through a password manager instead. Follow the method your client uses.
Two-Step Sign-In and Passkeys
Two-factor authentication (2FA) means that signing in needs a second step after your password, such as a code sent to your phone or a tap in an app. Even if someone steals your password, they can't get in without that second step. Turn it on wherever it's offered.
Some websites now offer passkeys, which let you sign in with your fingerprint, face or phone PIN instead of a password. They're safe to use when offered.
Never tell anyone a sign-in code sent to you, even someone claiming to be from the company. Real companies don't ask for it.
Suspicious Messages and Links
Phishing is a fake message designed to get you to click a link, sign in on a fake page, pay money, or download something harmful. Phishing messages are now often well-written and look professional. Watch for these signs instead:
- Urgency or pressure: "Your account will be closed today," "Pay this invoice immediately."
- A sender or link that doesn't match: the name says your client's bank, but the address is something different.
- A request to sign in, pay, or change payment details through a link in the message.
- Something unexpected: an attachment you weren't expecting, even from someone you know.
Before clicking a link, hold your pointer over it (without clicking) and look at the real address that appears, usually at the bottom of the window.
When in doubt, don't click. Open the website yourself by typing its address, or check with the sender through a different channel, such as a separate message or call.
Downloads and Software
- Only install programs from the official website or your computer's app store.
- Be very careful with unexpected files that end in .exe (Windows) or .dmg (Mac), or documents that ask you to "enable content" or "enable macros."
- Don't install anything on a client's computer or account without permission.
Everyday Habits
- Lock your screen whenever you step away: ⊞ Win + L on Windows, Control + ⌘ + Q on a Mac.
- Install updates for your system and browser when they're offered. Many updates fix security problems. Save your work, then restart when asked.
- On a public or shared computer, use a private window, never let the browser save passwords, and sign out of every account before you leave.
- Keep backups. Work saved in cloud storage survives a broken or stolen laptop.
- Handle client information carefully. Keep it in the places the client provides, don't copy it to personal accounts or USB drives, and don't show it in screenshots you share elsewhere.
If You Think You Made a Mistake
If you clicked a suspicious link, entered a password on a page that seemed fake, or opened a strange attachment:
- Stop. Don't enter anything else or click further.
- Change the password of the affected account right away, from the real website, and check that 2FA is on.
- Tell your client immediately if it involved their account or files. Reporting quickly is what limits the damage. Hiding it makes it worse.
What Would You Do?
Realistic situations. Use judgment, not fear.
An email that looks like it's from your client's bank says their account will be locked today unless you sign in using the link.
A client asks for the password to a shared account. How should you send it?
Someone calls saying they're from a software company and asks for the code that was just sent to your phone.
You finish a task on a computer at an internet café.
Your laptop has shown an update notice for a week.
You realize you typed a client's account password into a page that now looks fake.
- A different password for every account, kept in a password manager, plus 2FA.
- Urgency, mismatched senders and unexpected requests to sign in or pay are warning signs. When in doubt, don't click.
- Lock your screen, install updates, and sign out fully on shared computers.
- If something goes wrong, act fast and tell the client. Don't hide it.