Table of Contents

This course treats the individual as the asset. This is the opposite of most security training, which teaches you to defend an organization and then assumes your personal life works the same way.

The difference matters. You do not have a security team, a managed detection service, or a compliance officer. You have a limited amount of time and a threat model shaped by who you are. The course is built around the constraint.

Every module ends with something you produce: a decision, a configuration, or a record. Reading without acting teaches nothing.

What You Will Learn

The course runs in a fixed order, from account credentials up to the physical layer. Each module builds on the previous one, and the ordering is deliberate rather than alphabetical.

ModuleFocusReader outcome
1. AuthenticationCredentials and second factorsChoose a vault architecture and a phishing-resistant factor
2. Web BrowsingTracking and browser exposureHarden one browser and understand what remains
3. EmailThe recovery gatewaySeparate addresses and control remote content
4. MessagingConversation privacyEvaluate a messenger against real criteria
5. Social MediaPublic exposureReduce what your profile reveals
6. NetworksTraffic and routingConfigure a router and judge a VPN claim
7. Mobile DevicesSensors and trackingCut permissions and background collection
8. Personal ComputersThe operating systemEnable encryption, updates, and least privilege
9. Smart HomeMicrophones and camerasDecide what earns a place on your network
10. Personal FinanceMoney and identityFreeze credit and limit card exposure
11. Human AspectSocial engineeringBuild verification habits which survive pressure
12. Physical SecurityThe world outside the screenReduce public exposure and device seizure risk

How This Course Differs From a Compliance Checklist

A compliance checklist asks whether a control exists. This course asks whether a control changes your outcome, which is a different question with a different answer.

Three commitments shape every module:

  • Priority is explicit. Items carry an impact ranking, so you know what to do first when time is short.
  • Trade-offs are named. Every recommendation carries its cost, because advice without cost is marketing.
  • Tools are optional. Where a client-side tool helps, the module links one. None require an account or an upload.

The most commonly skipped item across all twelve modules is the backup. The most commonly over-prioritized is browser fingerprint randomization. Both are corrected in the modules where they appear.

The Modules

Part One: Accounts and Identity

Part Two: Communication and Exposure

Part Three: Devices and Networks

Part Four: Money, People, and the Physical World

What You Need Before Starting

No technical background is required. The course assumes you use a phone, a computer, and a handful of online accounts. Modules 6 and 8 go deeper for readers who manage their own hardware, and each flags where a step becomes optional.

RequirementWhy
A password managerModule 1 depends on one, and later modules assume it exists
About two hours for Part OneThe first three modules carry most of the immediate risk reduction
Willingness to change defaultsNearly every item is a default you have not yet reviewed
No purchased softwareEvery recommendation has a free or already-included option

Work in order the first time. Modules 11 and 12 assume the habits established in Part One.

ResourceWhat It Adds
Prioritized Personal Security ChecklistThe same material compressed into four tiers for readers who want the summary first
How to Form Your Own Personal Threat ModelDetermines which modules deserve the most of your attention
All Client-Side ToolsLocal tools for passwords, certificates, hashing, and metadata, with no upload
Every ChecklistThe organizational counterparts for readers who also manage systems
Personal Security Checklist by Alicia SykesA widely used community checklist covering personal security in depth

Next Steps

  1. Start with Module 1 and finish Part One in one sitting if you have the time: Authentication and Credentials
  2. Build the threat model first if you are unsure how far to go: Personal Threat Model
  3. Check whether your accounts have already leaked before changing anything, so you know your starting point: Have I Been Pwned
  4. Generate your first strong credentials with a tool which runs entirely in your browser: Password Generator
  5. Read the four-tier summary if you want the whole course compressed onto one page: Prioritized Security Checklist