Table of Contents

← Return to the Personal Security Course

On a desktop, three controls carry more weight than everything else combined: updates, disk encryption, and backups. The remaining controls reduce the consequences when one of those three fails.

This module covers those three first, then least privilege, endpoint integrity, attack surface reduction, and the isolation techniques which matter for readers who run untrusted software.

Budget about 45 minutes. Encryption and the backup check are the two items to finish today.

What You Will Learn

  • Sequence desktop controls by consequence rather than by popularity
  • Enable full disk encryption on Windows, macOS, or Linux
  • Apply least privilege to daily work rather than only to servers
  • Reduce the listening attack surface by closing services and ports
  • Isolate risky activity with virtual machines and separate accounts
  • Produce a computer record listing encryption, backup, and privilege configuration
TermMeaning
Full disk encryptionEncrypting the entire volume so a stolen device yields no readable data
Least privilegeOperating with the minimum rights needed for the task at hand
Attack surfaceThe set of services, ports, and interfaces reachable by an attacker
Keystroke injectionA device which presents itself as a keyboard and types commands
Mandatory access controlA policy layer which restricts programs beyond file permissions
Canary tokenA decoy file or credential which alerts you when it is touched

The Three Controls Which Matter Most

1. Automatic Updates

Most successful compromises exploit a vulnerability with an available patch. Update lag is the exploitable window.

  • Enable automatic updates for the operating system and restart when prompted
  • Update applications separately. Browsers, document readers, and media players are common targets
  • Include firmware and drivers where the vendor supports automatic delivery

A pending restart means a pending vulnerability. Treat the notification as unfinished work rather than an interruption.

2. Full Disk Encryption

Encryption converts a stolen device from a data breach into a hardware loss. Without it, anyone holding the machine reads your vault, your sessions, and your files.

PlatformFeatureWhere to Check
WindowsBitLocker or Device EncryptionSettings, Privacy and Security, Device encryption
macOSFileVaultSystem Settings, Privacy and Security, FileVault
LinuxLUKSConfirm root and home volumes at install time

Verify your recovery key is stored somewhere other than the encrypted disk. A recovery key only on the encrypted volume is not a recovery key.

Turning the device fully off rather than leaving it in standby matters once encryption is enabled. A suspended machine often holds keys in memory.

3. Backups

A tested backup is the only control which survives ransomware, theft, and hardware failure alike.

  • Keep one local copy for fast restores
  • Keep one encrypted offsite copy for fire and theft
  • Keep one offline or write-only copy for ransomware which reaches your synced storage

Test a restore. A backup never restored is an assumption.

Least Privilege on a Desktop

Most people work as an administrator all day, which means every process they launch inherits those rights. Least privilege is not a server-only concept.

PracticeWhy It Matters
Use a standard account for daily workMalware inherits the account’s rights, not the machine’s
Elevate only for administrative tasksLimits what runs with full rights
Do not link the machine to a cloud accountA local account avoids syncing settings and browsing data to a vendor
Review installed applicationsFewer applications means fewer update obligations and fewer targets
Lock the screen on idleAn unlocked machine is a complete compromise

Separate accounts are the simplest compartmentalization available. One account for daily use, one for administrative work, and one for anything untrusted. On Linux and macOS the separation is native. On Windows it requires creating additional local accounts rather than using the built-in administrator.

The measurement for this module is not how many controls you enabled. It is how much an attacker gains from compromising one account.

Endpoint Integrity

These controls answer a different question: is the machine currently trustworthy?

ControlWhat It Addresses
Built-in platform protectionsDefender, Gatekeeper, or the Linux equivalents, which are adequate for most users
Avoid commercial free antivirusMany monetize telemetry, and some add attack surface rather than reducing it
Periodic rootkit checksTools such as chkrootkit or rkhunter on Linux, and vendor tooling elsewhere
Watch for hardware keyloggersInspect the connection between keyboard and machine after the device has been unattended
Guard against keystroke injectionA device presenting as a keyboard types commands instantly. USB filtering tools address it
Block camera and microphone physicallyA physical cover defeats software which has already compromised the device
# Linux: check what is listening on external interfaces
ss -tulpn

# Confirm a hardware keystroke filter is active before trusting the machine
lsusb | head

Physical access defeats most software controls. A BIOS or UEFI password raises the effort for casual access, and it does not stop someone with the disk removed. Treat it as friction rather than protection.

Canary tokens are worth knowing about. A decoy file or credential which alerts you when opened gives early warning something has access it should not. Self-hosted canary services and file-integrity monitoring both implement the idea.

Attack Surface Reduction

Every listening service is a path in. The goal is a smaller list, not a longer one.

TargetAction
Listening portsIdentify what listens, then disable what you do not use
SSHDisable password authentication in favor of keys, change the default port, and restrict source addresses
File and print sharingDisable protocols you do not use, especially legacy SMB versions
Remote access featuresDisable remote desktop and remote assistance unless actively used
Voice assistantsDisable or limit always-listening features
Vendor telemetryReduce usage data and diagnostic reporting to the minimum offered
Secure BootKeep it enabled, which complicates bootloader tampering
# Linux: verify SSH will not accept passwords
grep -E '^PasswordAuthentication|^PermitRootLogin' /etc/ssh/sshd_config

# List enabled services to decide what deserves to stay
systemctl list-unit-files --state=enabled

On Windows, the equivalent exercise is reviewing startup items and optional features. Disabling unused services reduces both collection and attack surface, at the cost of some convenience.

Our organizational counterpart covers the server-side version of this exercise: Patch Management Checklist .

Isolation for Risky Activity

When you must run something untrusted, isolation limits what a compromise reaches. These techniques cost convenience, so reserve them for the cases which justify it.

TechniqueIsolation LevelBest For
Separate user accountLow, shares the kernelKeeping work and personal data apart
ContainerModerate, shares the kernelRunning a service in a defined environment
Virtual machineHigh, separate kernelTesting unknown software and browsing risky sites
Dedicated hardwareHighestAny activity you never want correlated with your identity
Mandatory access controlOrthogonal, restricts programsConfining applications even after compromise

A virtual machine is the practical option for most readers who want to inspect suspicious files or software. Remember containers share the host kernel, so a kernel vulnerability crosses the boundary. Our analysis of why containers are no longer a security boundary covers exactly this failure mode for the 2026 vulnerability families.

Mandatory access control is worth knowing on Linux, where AppArmor or SELinux confines what an application does regardless of its user’s rights. Enabling it adds a layer which survives a compromised process.

Compartmentalization is the underlying principle for all five rows. Ask what a compromise of this account or this virtual machine would reach, then reduce it until the answer is acceptable.

Diagram ranking desktop security controls by consequence, with updates, disk encryption, and tested backups at the top and isolation techniques such as virtual machines and compartmentalization at the bottom

The Computer Record

COMPUTER RECORD
Device:                  ______________________
OS and version:          ______________________  auto-update: on / off

The three controls:
  Disk encryption:       enabled / disabled   recovery key stored at: __________
  Backup local:          ______________________  last restore test: __________
  Backup offsite:        ______________________  encrypted: yes / no
  Backup offline:        ______________________

Privilege:
  Daily account type:    standard / administrator
  Separate admin account: yes / no
  Cloud account linked:  yes / no

Attack surface:
  Listening ports reviewed: yes / no
  SSH password auth:     disabled / not applicable / not reviewed
  Sharing services off:  file / print / both / none
  Remote desktop:        disabled / enabled
  Secure Boot:           enabled / disabled / unavailable

Integrity:
  Platform protections:  enabled / disabled
  Rootkit check run:     yes / never
  Camera cover:          yes / no

Next Steps

  1. Continue to Module 9 and decide what earns a place on your network: Smart Home and IoT
  2. Confirm disk encryption is on and the recovery key is stored off the device
  3. Restore one file from your backup to prove the backup works
  4. Review what listens on external interfaces and disable anything you do not recognize
  5. Read the container boundary analysis before treating a container as isolation: Containers Are No Longer a Security Boundary
  6. Read the organizational counterpart: Patch Management Checklist