Protect yourself online
Good cyber hygiene starts with a few everyday habits. The Texas Department of Information Resources (DIR) recommends the following practices to help protect your personal information and devices.
Cybersecurity best practices
- Do not open suspicious or unexpected links or attachments in emails.
- Hover over links in emails to verify they go to the website you expect before clicking.
- Be aware of scammers impersonating legitimate people or organizations — check the sender’s email address carefully.
- Use unique, strong passwords or passphrases for every account.
- Do not share personal or organizational information unless you are certain of the requestor’s identity and authority.
- Take advantage of cybersecurity awareness training when it is available.
- Enable multi-factor authentication (MFA) on your accounts whenever possible. MFA adds a second verification step — such as a code sent to your phone — that helps confirm your identity and keeps your data safe even if your password is compromised.
Shop safely online
Online shopping is convenient but can expose you to fraud if you’re not careful. Follow these tips to reduce your risk:
- Shop only on websites you trust. Look for “https” in the web address and a lock icon in your browser’s address bar.
- Avoid clicking on links in unsolicited emails or text messages offering deals — go directly to the retailer’s website instead.
- Use a credit card rather than a debit card for online purchases, as credit cards generally offer stronger fraud protections.
- Monitor your bank and credit card statements regularly for unauthorized charges.
- Be cautious of deals that seem too good to be true — they often are.
Heightened threat awareness
During periods of heightened cyber threats, it is especially important for individuals and organizations to stay vigilant. The Cybersecurity and Infrastructure Security Agency (CISA) provides guidance to help Americans strengthen their cyber defenses and reduce their exposure to attacks such as ransomware, phishing, and malware.
Maintain your privacy
Websites and apps collect information about your online activity using cookies, pixels, device fingerprinting, and advertising identifiers. Companies track your activity to save your preferences, show you personalized content, and serve targeted ads. Understanding how tracking works can help you take control of your personal information.
How online tracking works
When you visit a website, it may use a cookie — a small file stored on your device — to remember your preferences or identify you on future visits. Apps on your phone may use a unique advertising identifier to track your activity across different apps. Companies can also track you across multiple devices, such as your laptop and smartphone.
First-party tracking is when the website you visit collects your data directly. Third-party tracking is when a website lets another company — such as an advertising network — track you. Third-party trackers can follow your activity across most of the websites you visit.
Take control of your privacy settings
You can limit how much information websites and apps collect about you:
- Delete your browsing history, cookies, and search history regularly.
- Adjust your browser’s privacy settings to block or limit tracking. Most browsers offer a private browsing mode that deletes your history after each session.
- Review the privacy settings on your phone and turn off unnecessary app permissions, such as location access and access to your contacts or photos.
- Check your social media account settings to see how your information is being used and shared.
- Opt out of personalized ads through your browser, phone, and streaming device settings.
- When you visit a website that shows a cookie notice, choose the option that best fits your privacy preferences.
- Consider using an ad blocker or browser extension from a reputable source to limit tracking and unwanted ads.
Stay safe while working remotely
Working from home or a public location introduces additional cybersecurity risks. The Texas Department of Information Resources provides the following guidance to help remote workers protect their devices, data, and networks.
Secure your workspace
- Keep your workspace clean and do not leave documents unattended or visible to unauthorized people, including family members and roommates.
- Lock your computer and phone when you step away, even briefly. Set devices to lock automatically after a few minutes of inactivity.
- Make sure confidential phone calls and video meetings cannot be overheard.
- Keep your work and personal activities separate. Review your organization’s acceptable use policy before using a work device for personal tasks.
- Do not download sensitive work documents to your personal computer.
- Log off all work devices and remote platforms at the end of the workday.
Protect your internet connection
- Connect to the internet only through a trusted, password-protected network such as your home Wi-Fi.
- Avoid connecting to public Wi-Fi in coffee shops, libraries, or other shared locations whenever possible.
- Turn off automatic Wi-Fi connections on your devices so you don’t accidentally join an unsecured network.
- Always use your organization’s Virtual Private Network (VPN) when connecting over public or unsecured Wi-Fi.
- Only visit websites you know and trust. Do not click on suspicious emails, links, or attachments.
- Do not share your device or password with anyone.
- If you experience a security incident, disconnect from Wi-Fi immediately and contact your IT help desk.
Use multi-factor authentication
Multi-factor authentication (MFA) requires you to verify your identity with a second credential — such as a code sent by text message, a push notification from a smartphone app, or another method — in addition to your username and password. Contact your IT help desk to see if MFA is available for your accounts.
Keep children safe online
Children and teens face unique risks online, including cyberbullying, exposure to inappropriate content, and scams that target young users. Parents, teachers, and caregivers can help by talking to children about online safety and setting clear rules for internet use.
Cyberbullying
Cyberbullying is bullying that takes place over digital devices like cell phones, computers, and tablets. It includes sending, posting, or sharing negative, harmful, false, or mean content about someone else. It can also include sharing personal or private information to cause embarrassment or humiliation. Some cyberbullying crosses the line into unlawful or criminal behavior.
The most common places where cyberbullying occurs include social media platforms, text messaging and messaging apps, online forums and chat rooms, email, and online gaming communities. Cyberbullying can be persistent (happening 24 hours a day through digital devices), permanent (most information shared electronically is public and lasting), and hard to notice (parents and teachers may not see it happening). All states have laws requiring schools to respond to bullying, and many include cyberbullying under those laws.
[Important]
Learn about cyberbullying and how to prevent it
Tips for keeping children safe
- Talk to your children about the risks they may encounter online, including scams, inappropriate content, and strangers who may try to contact them.
- Set clear rules about which websites, apps, and games your children can use.
- Review the privacy settings on your child’s devices and accounts to limit what information is shared publicly.
- Encourage your children to come to you if they experience anything online that makes them uncomfortable.
- Monitor your child’s online activity in an age-appropriate way.