Russ Harvey Consulting - Computer and Internet Services

Security Policies

Protecting Your Computers & Network

Creating Policies | Business | Home | Servicing Computers | Data Inheritance

Protecting Your Computers

Be sure to read Security Basics because it introduces preventing unauthorized access and key elements of security upon which this page builds.

Now we live in a world that is strictly bounded by our capacity to understand it, by our ability to keep up with the pace of technological change, and to manage the new risks and security challenges that come with limitless storage capacity, limitless transmission capacity, limitless data mining capacity.


We are bounded by our own limited capacity to understand, to imagine the implications of data flow and data aggregation, and our ability to teach. — Privacy Commissioner of Canada

Creating a Security Policy

Create a security policy for the computers in your home or business. This will provide guidelines in making security decisions and help your family or employees understand the need for security.

Your protection depends on:

  1. protecting your computers and devices with good quality security software that is updated regularly;
  2. knowing how that security software operates so you're not fooled by fakes; and
  3. your knowledge about other security threats (including hoaxes) and how to respond to them correctly.

A Written Policy

A written security policy ensures that you cover all the necessary basics and clarifies responsibilities.

A simplified policy for children may be necessary, but it is better to restrict their access so that bad decisions are less likely.

Security Policy Elements

Your security policy should contain at least these elements:

These areas are covered on this page and in other sections of this site. How you apply them depends upon whether it is a business or home environment and who is involved.

Security is Everyone's Responsibility

The user is the point of greatest vulnerability which is why a security policy is useful and necessary if everyone that uses your Internet and devices is to take security seriously.

If others use your computer or devices, they also need to take security seriously.

Educate About Evaluating Risks

Ensure that everyone using your computers understands how to evaluate risks.

Warnings by phone or email indicating your computer is “infected” are common. ALL are scams. Watch for these signs:

  • Simply opening an infected image or other attached file can be enough to endanger the data on your computer. More….
  • Any warnings that appear on your screen, particularly if they indicate that you have hundreds of infections, are scams. Know how the security software you installed reacts to an infection.
  • Do NOT follow instructions given by an unsolicited email or phone call. These are scams, no matter who they say they are. Just hang up.
  • There are logs on Windows computers that show errors even when they are operating normally. Scammers may try to use these logs to convince you that your computer is infected.
  • If you provide a caller with access to your computer so they can “fix a problem” you'll end up with an infected computer, an expensive credit card bill, or both.

Family members and employees should be instructed NOT to respond to such ploys. If you're concerned, call the person that maintains your computers.

Access to Internet

There needs to be a policy regarding access to your home or business Internet (WiFi) in order to protect your network and the devices connected to it.


BEFORE you connect:

  • A secured home or office network is always preferable to an unsecured network.
  • Ensure that your security software (antivirus, firewall) is turned on.
  • Using a VPN (Virtual Private Network) is recommended.*
  • Confirm the WiFi network name with the business owner.
  • Be sure to use secure sites, those starting with HTTPS, especially where you need to login to an account.
  • Turn on two-factor authentication for your accounts.
  • Disable file sharing.

*NEVER access financial sites like banks, PayPal or shopping sites while on a network you don't control without using a trusted VPN.

Protect Your Network

In both homes and businesses the network provides access to the Internet but also can be used to share files and printers between computers and devices.

Vulnerabilities in either the network itself (e.g. the modem or router) or devices connected to it can lead to a compromise of your security.

Not only are computers, tablets, smartphones and networked printers connected to your network, but so are smart assistants (Google Home, Alexa, etc.) and a “smart” devices which can be used to invade your privacy.

Older smart home devices employ obsolete security (short passwords on 2.4 GHz WiFi).

Always change the default passwords on routers and similar equipment and turn off access to insecure devices.

Guest WiFi

Many current routers provide a separate “guest” WiFi so that visitors to your home or business can have access to the Internet without access to your network. You should still consider whether you want users to have access at all since you're responsible for any illegal activity on your internet access account.

Free WiFi Presents a Risk

We're constantly on the go and want to remain connected but choosing an unsecured WiFi network could undo all that we've done to secure our computers and devices.

  • Cellular is more secure than public WiFi.
  • Turn off automatic WiFi connectivity on your devices to avoid being connected either to unknown networks. If WiFi is enabled it nulls the better security provided by a cellular connection.
  • Turn off Bluetooth when you're in public. An unscrupulous person can gain access to your device via an open Bluetooth connection.
  • A VPN encrypts all your wireless traffic to protect you and the person or service you're connected with.

Others on the same network could intercept information like passwords and confidential information using easily-available hacking software. Watch this YouTube video.

Captive Portals No Safer

ZoneAlarm infographic: “The risks of public hotspots: How Free WiFi can harm you”

You'll want to ensure that when devices are outside the home or business they don't leak confidential information or download malware that could infect your own network.

The log-in screen requiring you to agree to the WiFi network's terms in coffee shops and elsewhere are called captive portals and are no safer than an open WiFi network, but give you the illusion of safety.

Captive portals can interfere with secure (HTTPS) sites, calling them “untrusted connections” which leads people to ignore such warnings in the future.

Return to top

Protecting Business Computers

When your employees fall victim to a phishing attack, your entire corporate network and brand is at risk. The cost can be stunning. — Vade Secure
Since 91% of all cyber attacks begin with a phishing email, taking steps to defend against phishing attack might be the single most important aspect of an overall threat defense plan. — DuoCircle
[W]hile most Windows systems on a network should be receiving regular security patches to ensure they can't fall victim to attack, it's all too easy for the PoS terminal to be forgotten about. — TechRepublic

More about phishing.

Use Current and Appropriate Software

Software, including operating systems, generally have an expiry date. Vendors release new software versions and end support for previous versions. In some cases the vendor may not explicitly state software is not supported, but may list system requirements that are no longer currently supported (e.g. an unsupported version of Windows).

Depending upon the software and its critical nature in your business, you can place your business at risk. The following example is specific to Microsoft Office for Mac, but similar risks exist for other business software:

After Oct. 13, 2020, the lack of support for Office 2010 and Office 2016 for Mac means that using those applications in your business or organization could be construed by courts and regulatory agencies as negligence — possibly criminal negligence. The kind of negligence that leads to fines, penalties, incarceration, and bankruptcy. — TechRepublic

More about choosing software.

Enterprise Protection

Larger businesses face different risks and the solutions may require Managed Security Services which are run remotely.

Reliable Backups Critical

Business data is now primarily electronic. Much of the old paper tracking has been replaced with PDFs, e-Transfers, PayPal, online shopping carts, accounting programs, etc. The few remaining paper documents would likely be unable to recreate your business if all your electronic documents were wiped out.

According to an industry study by The Diffusion Group, who surveyed small business organisations, 60 percent of companies that lose their data close down within six months of the disaster and a staggering 72 percent of businesses that suffer major data loss disappear within 24 months. — Workspace
Around the world, IT professionals reported a 6% increase in data loss leading to downtime compared to 2020. That's an 18% increase over our 2019 findings. Similarly, personal IT users reported a 5% increase in permanent data loss over 2020 and an 8% jump from 2019. Despite all of the new technologies put in place, this problem isn't going away. In fact, it's getting worse. — Acronis

You'd need to be able to get up and running in as short a time as possible. Delays could damage your credibility and reputation. Complete and accurate backups are critical.

Restrict Access

You need to restrict access to business computers:

  • Only employees with significant understanding of the risks should have administrative rights.
  • Your company policies should indicate what software each level of user can or can't add or remove without express permission.
  • Software, security and Windows updates are best done by you (or a single trusted employee reporting directly to you) so that you know your computers are protected.
  • Access to personal social media sites like Facebook or personal software on business computers can lead to security risks for your business.
  • Business social media accounts should be managed by experienced employees that understand the medium as used by a business. It is easy for followers to un-Like you if something goes wrong.
  • The use of unsafe media like USB thumb drives can infect computers, including those on your network.
When your employees fall victim to a phishing attack, your entire corporate network and brand is at risk. The cost can be stunning.
Vade Secure

As more people work from home, poor security practices can place your business at risk. Your IT specialists aren't within easy reach and no one is ensuring they are following prescribed policies.

Employees found to be negligent in protecting their employer's security may find it affecting their future employability.

One creative alternative is Menlo Security's Secure Web Gateway:

For companies that don't want to isolate all web traffic, we are providing greater ability to specify which users or categories of websites to isolate.


For example, we can now automatically isolate any web service that was created with software known to be vulnerable to hacking, such as unpatched versions of WordPress and Drupal. End users don't even realize their web sessions are actually occurring on our platform rather than on their PCs.


With our new "Isolate and Read-Only" capability, administrators can allow employees to access — but not interact on — webmail and social media sites. That way, they can't be tricked into providing credentials to clever phishing scams. — Menlo Security Blog

Increase Your Security Budget

Why cyber security training is crucial for your business

Corporate and business Information technology (IT) departments are seriously underfunded and a significant number of employees aren't concerned about the affect their lax security habits could have on the company.

The Equifax data breach, which exposed the sensitive personal information of nearly 146 million Americans, happened because of a mistake by a single employee… — The New York Times (emphasis mine)

Saving money on IT security may benefit you in the short term, but could cost you a great deal in the long term. You could lose your company's credibility if you're hacked and lose critical business information or suffer a data breach revealing your customer database.

Return to top

Protecting Home Computers

While this section primarily discusses computers, people are increasingly accessing the Internet over tablets and smartphones as well as smart devices like Google Home and Alexa.

Protect the Integrity of Your Devices

Protect the integrity of your computers and devices by restricting access.

  • Use secure and unique passwords as well as your answers to security questions (anything based upon information posted on social media sites like Facebook or common knowledge about you can be easily guessed by others).
  • Don't put your business data at risk. Business computers in your home or business should be used ONLY for business and should be secured with a decent password.
  • Provide your family with a separate computer (they are relatively inexpensive these days).

Reliable Backups Critical

So many of our transactions today are electronic. Our bills come via email or are provided online. Think of the monumental task of recreating your financial history of the last year at tax time if you were to lose everything on your computer.

Then there's your collections of photos, music, videos and personal documents, many of which are irreplaceable.

Complete and accurate backups are critical.

Working from Home?

Because you'll be spending about a third of your day in your new home office, be sure to acquire the necessary equipment to make it work for you.

Working from home creates its own policy requirements, including privacy and security:

  • You need to be able to use Online meeting software like Zoom and your phone without being overheard.
  • Confidential company or client data on your computer or your desk needs to be secured. Use a dedicated computer and get a locking file cabinet.
  • Sound-proof your work environment so that outside noises are minimized. A flushing toilet during a Zoom meeting can kill your professionalism.

While working from home can be challenging, a policy can help your family understand the necessity for being undisturbed during working hours.

We're Not Alone

Keep in mind that others in your home have their own requirements such as homework and . Accommodating those can go a long way to garnering acceptance. If you're unable to schedule Internet use, you may need to increase your bandwidth so that everyone can get adequate access.

Restrict Children's Access

Your children should not have full access to devices they use, including the ability to install or remove software. This includes:

  • administrator privileges, even on their own computers and devices.
  • denying the ability for their friends to make changes of any kind to the family's computers.

You are legally liable for any computers and devices as well as the Internet access you provide no matter who uses them. Visits to illegal or unauthorized copyright material could result in very large fines.

Protect Your Children

Children are curious and often more comfortable with technology than their parents. It is important that you monitor their activities for their own protection.

  • Children are vulnerable because of their ignorance and curiosity. They often want to hide their activities from their parents in their eagerness to be “grown up.”
  • While it is important that children's privacy is protected on corporate and public sites and social media, it is important that parents understand what their children are doing online and who they are interacting with.
  • Ensure that your children don't share personal information online. Information like age (birth dates), home address, full name, etc. can be used for identity theft.
  • Predators want to sexually exploit your children or entice them to meet secretly outside of your home.
  • Place computers in common areas of your house and don't allow Internet-accessing devices in their rooms, particularly when the door is closed or at night.

Educate Yourself

You have the right to choose what is appropriate for your children.

You'll need to learn more about how children are exposed to unwanted material online and how you can protect them.

It's important to know what threats kids are facing so that you can have the right conversations and implement the precautionary measures. It's also hugely important to set some fair and effective ground rules for how your kids use the internet. — 17 rules to protect my child online


Servicing Computers

It is important that anyone servicing your computers is knowledgable and trustworthy.

  • Get professional help from a reliable source. Ask friends or colleagues for recommendations.
  • While an employee or the kid across the street might know more than you, they might not know enough.
  • Your policies should indicate how servicing is to be carried out and by whom.
  • Be aware of potential industrial or political spying.

Geek Squad Spying

The FBI used Best Buy Geek Squad employees to conduct warrantless searches of customers' computers.

What other potential confidential information was searched for and perhaps acted upon?

Return to top

Data Inheritance

Not only do we live so much of our lives online but many documents are now electronic only, including our monthly household bills and our taxes.

If you die or lose your capacity to act for other reasons, your family or executor need to deal with these accounts.

Internet users have an average of 90 online accounts on various platforms and websites.

Planning for what happens to these accounts is called data inheritance.


The number of passwords seems to get larger each year.

How do you record these in a safe manner makes them available to someone you trust if necessary?


One method is to keep a record of them with a SecureSafe (see above).

That requires updating your documentation frequently.


LastPass Premium provides access to someone you trust.

Emergency Access makes your account safely available to another LastPass user of your choice.

If you simply provide the login details for your LastPass account, make sure it is in a secure accessible place.

Social Media Accounts

Preserving profiles may seem trivial, but our lives are increasingly lived online, so these accounts are the modern version of physical photo albums, letters, and other keepsakes. — PCMag

You can sometimes make plans for your social media accounts if something happens to you. The rules differ for each social media account.

The topic of data inheritance is young and many online service providers have yet to present their policies on it.


Some of the heavyweights have, however, already put various options in place for their users to pass on important data or rights to online accounts.

Other Aspects

Your online life isn't the only area where your family may need to interpret your intentions.

If you were hit by a bus today or were otherwise incapacitated, would your loved ones be able to quickly locate your important information or know how to handle your affairs?

The better prepared you are, the easier it will be on those you leave behind to carry out your wishes.

  • Everyone should have a current will, a legal document specifying how you're like your estate handled.
  • A power of attorney and representation agreement are legal documents that empower someone you trust to make decisions on your behalf.
  • Create a master list (plus any other associated files) to describe where your personal papers, legal documents, monthly bills and other important documents are stored and how they are organized. Don't forget keys, computer passwords and combinations to the safe.

Consider the information required to manage your life if you were to start from scratch.

Return to top

Related Resources

Related resources on this site:

Return to top

If these pages helped you,
buy me a coffee!


Return to top
Updated: July 12, 2021