Cyber hygiene 2.0: What everyone should know, from students to senior executives

IT security advisor at Freedom Cloud Holding

Until recently, almost every discussion of cyber hygiene revolved around three key pieces of advice: use a decent password, enable two-factor authentication and never open suspicious emails.

In 2026, that is no longer enough. The problem has changed. Today, the key target is not just the user, but the trust between users, services, applications and artificial intelligence (AI).

For a large company, addressing this may be another area of responsibility handled by a dedicated team. For small and medium-sized enterprises, however, things are more complicated. Not every company operates a Security Operations Center (SOC) or has a specialized team monitoring cyber threats around the clock and ready to step in at any moment.

That does not mean cybersecurity has to be complex. But it does have to be systematic.

It’s not just about passwords

Some people might think that multi-factor authentication (MFA) is the ultimate solution. But that is an illusion — and a dangerous one.

For example, a user can sign in through a legitimate Google or Microsoft website and then grant a third-party application access to their email, files or other information.

In this scenario, an attacker does not need the user’s password at all.

Even changing the password afterward may not help if previously issued app permissions or tokens remain valid. That is why I recommend that companies review the applications granted access to corporate data, rather than looking only at user accounts and authentication methods. Sometimes, what you find on the list of authorized applications can be more revealing than what you find on the list of active users.

The second-channel rule

It is not uncommon for an attack that could cost a company dearly to begin with a simple message:

«I need you to pay my bill ASAP.»

«Change the bank account details.»

«Send me the client database.»

«I lost my phone. Help me restore access.»

In the past, IT security specialists told employees to watch email addresses and wording to spot suspicious messages. Today, that is no longer enough. Generative AI can make fraudulent messages far more convincing and personalized.

That is why I suggest one simple rule for any action involving money, bank account details or the transfer of sensitive information: never use the same channel through which you received the request to confirm a critical action.

If a request arrives via a messaging app, confirm it by phone. If it comes via email, confirm it through a corporate communication channel or a known phone number. Do not confirm a critical action simply by replying to the same message. A second, independent channel does not make a company invulnerable, but it makes life much harder for an attacker.

Look through a wider lens

The traditional security question, «Who logged into the system?», is not enough these days. The next question should be: «What did this account start doing after logging in?»

Users typically follow consistent work patterns. If someone who usually opens a few documents a day suddenly starts downloading thousands of files, that warrants investigation.

The same applies to new email forwarding rules, unknown OAuth applications, new device registration, changes to authentication methods or a sudden spike in API requests. For me, the key principle is this: a company must see not only that access occurred, but also what happened as a result.

AI creates a new attack surface

Perhaps the most underestimated aspect of modern cyber hygiene relates to AI. A company might secure its corporate email effectively while simultaneously creating a new vulnerability by connecting an AI agent to email, documents, CRM systems and internal infrastructure.

Consider a simple scenario. An AI agent is tasked with analyzing incoming emails and helping an employee process requests. An attacker includes an instruction in one of those emails — intended not for the human recipient, but for the agent itself — telling it to ignore its original task, locate specific documents and exfiltrate them.

To a human, it is just text in an email. But to an agent that treats email content as input and has access to corporate tools, it represents a potential attack vector.

Such scenarios are known as «indirect prompt injection» or «agent hijacking.» The U.S. National Institute of Standards and Technology (NIST) specifically addresses the risk of malicious instructions finding their way into external data — such as emails, websites, documents or code — and subsequently influencing an AI agent’s behavior. In this context, traditional security principles matter even more.

The greater the authority, the costlier the errors

If an AI system needs to read documents, it has no reason to be allowed to delete them. If it drafts an email, it does not necessarily need the authority to send it independently. If it analyzes a CRM system, why should it be able to modify customer data? This is the standard principle of least privilege — only now, it must apply not just to humans and conventional software, but to AI agents as well.

The Open Worldwide Application Security Project (OWASP) recommends restricting an agent’s access to only those tools and resources strictly necessary for its task, while keeping critical operations outside the model’s direct scope of authority. In other words, if the AI makes a mistake, that error should occur within predefined, safe boundaries.

The decision-maker is human

I don’t think a human needs to approve every single AI action manually; doing so would quickly turn automation into another form of manual labor. However, some operations carry unjustifiable risk without additional oversight: transferring funds, deleting data in bulk, modifying access rights, publishing documents or transmitting large volumes of data externally.

Let AI prepare the action and gather the necessary data. But ensure a human makes the final decision before the execution of any irreversible operation. According to OWASP, this is the «human-in-the-loop» principle, and it is king. This isn’t about trusting or distrusting AI; it’s about sound security architecture.

Don’t hide secrets in prompts

Here is another simple check for companies implementing AI: API keys, passwords, tokens and other secrets should never be embedded in a model’s system prompt.

A prompt is an instruction; it should not serve as an access-control system. If an agent requires access to a service, it should obtain that access through standard authorization mechanisms, with restricted permissions, dedicated tokens and activity logging. OWASP specifically emphasizes that system prompts must not be used to safeguard secrets or as a substitute for proper access controls.

What should a leader do?

A leader does not need to become an information security expert. However, every few months, they should ask their team some tough questions:

  • What data is truly critical to us?
  • Who — and which applications — have access to it?
  • What would happen if an executive’s account were compromised?
  • Which AI tools are employees already using?
  • What would happen if one of our AI agents made a mistake or were tricked?

If you don’t have quick, concrete answers to these questions, it is time to investigate.

Cyber hygiene is about managing trust

You can’t ask an employee to «never make a mistake.» People always make mistakes. Someone will open the wrong email, approve the wrong request or upload a work document to an unsuitable AI service. That is inevitable.

The company’s job is to ensure a single mistake doesn’t turn into a catastrophe. This still requires MFA, password managers, software updates, backups and employee training. But today, those measures aren’t enough without understanding which applications access company data, which tokens are active, which devices are connected, what accounts do after logging in and what permissions have been granted to AI systems.

To me, Cyber Hygiene 2.0 is no longer just a guide to «how to create a strong password.» It is about managing trust. The goal is not to build a perfect defense, but to create a business system in which even a successful attack has a limited blast radius.

Related Materials