Secure Like a Pro
Secure Like a Pro
Author: Taylor Kerber, CISSP, CRISC
Published: July 17th, 2026
Understanding Personal Risk
As both an educator who teaches Cyber Security at Hennepin Technical College and a Cyber Security / Information Security Professional with roughly ten years in the industry, I have personally been involved in mitigating, preventing, and analyzing many high severity incidents and breaches and would like to share some of my knowledge to help others better understand some basic security practices. Pop culture and media portrayals of Information Security have long romanticized the industry and what our day-to-day job entails. While I’ve primarily worked in what is considered a blue team role, also known as a defensive role, I often work closely with Ethical Hackers / Penetration Testers to validate and test existing security controls. My experiences and knowledge have made me personally hold a more holistic and practical view of Information Security.
At their core, many Information Security decisions that organizations make can be distilled down to a formula that usually includes the following:
Asset = Anything of value that needs protection — can be information, people, physical assets, etc.
Vulnerability = Flaw, weakness, gap, or misconfiguration in a process, system, or environment.
Threat = Potential event or action that can act upon and utilize a vulnerability and cause damage or harm.
Risk = The result of the exploitation or action from a threat happening.
Think of this in simpler terms like owning a car. If you live in North America like me, you likely own a vehicle to get around. My vehicle is an asset I own that allows me to get to work, get groceries, and perform many other essential tasks that modern life requires and has a high monetary value. Now let’s say this vehicle gets stolen and damaged (threat) — it will need to be replaced in its entirety and that event and its likelihood of happening is a risk. I cannot personally afford to accept and own this risk, and I am legally required to carry insurance, so I do not have to worry. In this example most of us use risk transference and risk sharing which means we pay an insurance company to take the burden of that risk for us in the form of a monthly premium. The insurance company manages our risk, and millions of other vehicles owners' risk for a price. The insurance company is essentially betting (with a lot of math) that we will not need to use their services monetarily more than we pay in. Additionally, the insurance company is calculating the price of our individual premium based on the likeliness of our risk being realized. This is often calculated with information like our driving history, the type of car we drive, our age, and where we live. So, what does car insurance have to do with Information Security and why am I talking about risk management (yawn)? Because many of these concepts can be used by everyday technology users to better understand their own vulnerabilities, threats, and risks.
I mentioned earlier that I’ve personally been involved in a lot of high severity breaches and incidents. Well, anecdotally many of those did not involve some elite hacker or advanced Nation-state threat actor. Alas, many security incidents are often the byproduct of mundane misconfigurations, default passwords, and lack of even basic security controls but these seemingly low hanging vulnerabilities can cost a lot of monetary and reputational damage. Can you think of some of your own personal risks and what they may look like? Losing a lifetime of precious family photos because they were all on a single physical hard drive that failed is a risk that could be mitigated with a $120 yearly subscription to a service like Dropbox. Similarly, a yearly anti-virus subscription could mitigate and reduce the risk of harmful malware infecting your PC and gaining access to sensitive personal information. To help get creative and identify your own personal risks, threats, and vulnerabilities — I've created and attached a guide as seen below. This guide is a quick user-friendly reference with tools and practices that can help everyday users of technology identify and mitigate personal risks of their own. Not all the tools in this guide are free, but many are lower cost options and could greatly reduce and mitigate personal risks while creating a safer and more secure digital world.
Password Hygiene
What security blog post would be complete without a lecutre on passwords? To some of you The Digital Citizenship Guide, Secure Like a Pro, may be information and knowledge you’ve already possessed or have seen before. Most of the items on this guide are straightforward with the exception of one, passwords. Passwords are a form of authentication and can be categorized as something you know. The other forms of authentication are; something you are (Think Sci-Fi biometrics, fingerprints), and something you have (A key, an authenticator app, or smart card). In my experience I’ve found that passwords can be one of the most misunderstood concepts and one of the most misunderstood risks for personal users.
What defines a good password goes beyond the complexity, character types, and length. In the modern digital age, a good password should essentially be seen as disposable one-time use object that has zero recognizable patterns or information that could be tied to you personally. The reason for this is because almost everything we do now requires an account and password and humans tend to try and make passwords we can personally remember. Take a moment to think of all the different accounts you have and what usernames and passwords you use. Streaming services, gaming, online banking, e-commerce, medical accounts, government accounts, fitness memberships, smart devices in your home. The list could be seemingly endless; we have accounts and passwords for almost everything we do in the digital world and the data behind these accounts could vary from an embarrassing workout playlist you curated to incredibly personal medical and financial information.
As digital citizens we often have little choice but to trust all these different entities with our information and we have limited information on how all these individual entities handle and care for our data. Think for a moment, who might have more financial resources and required regulations to safeguard your data; a large medical provider (hospital and clinics) or a locally owned coffee shop that you have a rewards account with? If you chose the medical provider, you would most likely be correct in your logic. By that similar logic would you trust that small locally owned coffee shop with your medical records? Probably not. This fundamental concept is why it is so important to not just have strong passwords, but to never under any circumstance reuse them or use them for multiple accounts. See this quick animated graphic below for visualization.
A Neverending Battle
Understanding risk is a crucial step to securing your own digital footprint and being a more responsible digital citizen. Thinking like a business by identifying your assets and their risk can help you understand how and where to focus your time, attention, and money. Technology will continuously change and evolve around us but the principles behind identifying and addressing risk remain a stable and reliable tool for all digital citizens to leverage.
Updated: August 1st, 2026
References
Altomonte, L. (2026, April 28). Understanding Risk Transference. https://safetyculture.com/topics/risk-management/risk-transference
Carmichael, M. (2022, October 24). ISACA now blog 2022 risk appetite vs risk tolerance what is the difference. Risk Appetite vs. Risk Tolerance: What is the Difference? https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2022/risk-appetite-vs-risk-tolerance-what-is-the-difference
Cybersecurity and Infrastructure Security Agency. Nation-State Threats. Helping critical infrastructure owners and operators protect against and respond to nation-state threats. https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors
Downey, A., & Finn, T. What is Blue Team? | IBM. What is blue team? https://www.ibm.com/think/topics/blue-team