💻Coming to SF Tech Week?We went through all 300 events so you don't have to. Here is where we will be.Read the guide
💻Coming to SF Tech Week?300 events, one guide.
Read the guide
← Blog
For individuals

Don't Make It Easy for Them: The Small Habits That Keep You Safe Online

Explore an AI summary

Every October, Cybersecurity Awareness Month gives us a reason to stop and think about how we protect ourselves online.

This year's theme from the National Cybersecurity Alliance is simple: Don't Make It Easy for Them.

We like it because it doesn't ask you to become a cybersecurity expert. It doesn't ask you to understand every new threat or memorize a hundred security rules.

It asks you to do something much more practical: make yourself a little harder to scam.

That can mean using a unique password instead of reusing the same one everywhere. Turning on MFA for your most important accounts. Pausing before clicking an unexpected link. Installing the software update you've been putting off.

Small things. Repeated consistently.

And together, they can make a meaningful difference.

Haven is proud to be a 2026 Cybersecurity Awareness Month Champion, so this October, we're breaking down what "Don't Make It Easy for Them" actually looks like in everyday life.


What does "Don't Make It Easy for Them" actually mean?

Scammers don't need to fool everyone.

They send a message to thousands of people. They build a fake website that looks like a real one. They impersonate a company you know. They create a sense of urgency and wait for someone to click.

The goal isn't necessarily to outsmart you. It's to catch you in an ordinary moment when you're distracted, busy, tired, or simply moving too quickly.

That's why staying safe online isn't about being perfect.

It's about adding a few layers between a scammer and the thing they're trying to get from you.

A strong password makes an account harder to take over.

MFA adds another layer when a password is compromised.

Recognizing a suspicious message gives you a chance to stop before clicking.

Keeping software updated closes known security holes.

And having protection in the browser gives you another layer when a suspicious page is already in front of you.

The goal isn't to make yourself impossible to attack. It's to stop being the easy option.


The four habits that do most of the work

The National Cybersecurity Alliance recommends four simple steps for getting started: use strong passwords and a password manager, turn on multifactor authentication, recognize and report scams, and keep your software updated.

Here's what each one looks like in practice.

1. Use strong, unique passwords

The problem with reusing a password is simple: one compromised account can put other accounts at risk.

If the same password protects your email, shopping account, social media, and bank account, a breach at one service can create a much bigger problem.

You don't need to invent and remember dozens of complicated passwords yourself. That's exactly what password managers are for.

A password manager can generate long, unique passwords for your accounts and remember them for you.

A good rule: if two important accounts share the same password, change one of them.

Start with your email, financial accounts, cloud storage, and any account that could be used to reset another password.

2. Turn on multifactor authentication

A password is only one piece of the puzzle.

Multifactor authentication, or MFA, asks for another way to verify that you're really you. Depending on the service, that might be an authenticator app, a security key, a biometric check, or a one-time code. CISA recommends enabling MFA on accounts that offer it, particularly important accounts such as email and financial services.

Why does this matter?

Because if someone gets your password, MFA can still stand between them and your account.

Start with the accounts that would cause the most damage if someone got into them:

  • Your primary email

  • Banking and financial accounts

  • Cloud storage

  • Social media

  • Work accounts

  • Accounts containing personal or sensitive information

And when a service offers a stronger, phishing-resistant MFA option, consider using it.

3. Learn to recognize scams before you click

This one is getting harder.

Scams used to be easier to spot because they were full of obvious spelling mistakes, strange formatting, or suspicious-looking addresses.

Today, a scam can look polished.

The logo can be right.
The branding can be right.
The message can sound like someone you know.
The website can look almost identical to the real thing.

So instead of asking only, "Does this look real?", ask:

"Was I expecting this?"

A few warning signs deserve a pause:

  • Someone is creating urgency: "Your account will be closed today."

  • You're being asked to log in through an unexpected link.

  • Someone is asking for money, gift cards, cryptocurrency, or payment information.

  • A message claims to be from a company you use but sends you somewhere unexpected.

  • The web address doesn't match the company you're trying to reach.

  • Someone asks you to bypass a normal process or keep something secret.

And remember: you don't have to decide immediately.

If a message says your bank needs you to act right now, open your bank's app yourself instead of following the link.

If a package delivery message looks suspicious, go directly to the carrier's website.

If a coworker sends an unusual payment request, verify it through another channel.

A few seconds of friction can be valuable.

And when you encounter a scam, report it. Reporting suspicious activity to the relevant platform, service provider, financial institution, or government agency can help others avoid the same scheme.

4. Stop ignoring software updates

That notification you've been dismissing for three weeks?

It might be fixing a security vulnerability.

Software vulnerabilities can give attackers opportunities to compromise devices, accounts, or data. CISA recommends keeping software and operating systems updated and turning on automatic updates where possible.

The easiest approach is also the least exciting:

Turn on automatic updates.

Your operating system.
Your browser.
Your phone.
Your important apps.

You don't need to become an expert on every security patch. You just need to let the people maintaining the software fix known problems.


Phishing isn't just an email problem anymore

For years, "watch out for phishing" basically meant "be careful with your inbox."

That's no longer enough.

A scam can start almost anywhere you spend time online:

Text messages:
"Your package couldn't be delivered. Confirm your address."

QR codes:
"Scan here to pay your parking ticket."

Social media:
"Your account violated our policy. Appeal now."

Direct messages:
A friend, creator, recruiter, or brand suddenly sends you a link.

Calendar invitations:
An unexpected meeting appears with a link inside.

Shared documents:
A notification says someone shared a file with you.

Search engines:
You search for a company and click a sponsored result that looks legitimate.

Phone calls:
Someone claiming to be your bank or a support representative tells you to visit a website while you're on the phone.

These attacks have different names. Smishing. Quishing. Vishing. Search poisoning.

But from the user's perspective, they often follow the same pattern:

Something gets your attention → you click or scan → a browser page opens → the page asks you to trust it.

That's the part worth paying attention to.


The browser is where the scam often becomes real

The message isn't always the final destination.

It's the delivery mechanism.

A text sends you to a website.

A QR code sends you to a website.

A social media message sends you to a website.

A search result sends you to a website.

An email sends you to a website.

And once you're there, the scam has a new opportunity to convince you that everything is normal.

The page might look like your bank.

It might look like Microsoft.

It might look like Google.

It might look like a delivery company.

It might even use the exact colors, logos, language, and layout you've seen hundreds of times before.

That's why "I would never click a phishing email" isn't quite enough anymore.

The important question is what happens after the click.

Before entering a password, payment information, or other sensitive information into a page you reached unexpectedly, stop and check where you are.

Look at the domain.

Think about how you got there.

Ask whether the page is actually where you intended to go.

And if you're still unsure, navigate to the service directly instead of continuing through the link.


One more layer for the moment you actually click

Good cybersecurity isn't one tool.

Your password manager doesn't replace MFA.

MFA doesn't replace software updates.

Software updates don't replace good judgment.

And knowing how to spot scams doesn't mean you'll never click one.

Sometimes you will.

You'll be distracted.

You'll be in a hurry.

You'll see a message that looks completely legitimate.

You'll click before you think.

That's human.

That's also the moment where another layer of protection can matter.

That's what we built Haven for.

Haven works in your browser to help verify the pages you're visiting and flag suspicious activity before you hand over sensitive information. It can also flag risky extensions and help you understand when something in your browser deserves a closer look.

It doesn't replace the four habits above. It adds another layer around one of the most important moments in the chain: when a link becomes a page and you're deciding whether to trust it.


Why Haven is free for individuals

There's one more part of "Don't Make It Easy for Them" that matters to us.

Making security easier means making it accessible.

The more people who have protection, the fewer easy targets there are.

That's why Haven is free for individuals.

Not a limited-time trial. Not freemium bait. Just free protection for individual users.

Because the people who need protection shouldn't have to decide whether it's worth paying for.

Your parents shouldn't need a cybersecurity budget.

Your friends shouldn't need to understand every threat before they can protect themselves.

And you shouldn't need to be an expert to have another layer of protection in the browser.

More people protected. Fewer easy targets.

That's the direction we're trying to move in.


Don't make it easy for them

You don't need to overhaul your entire digital life this October.

Start with one thing. Use a password manager. Turn on MFA. Update your devices. Pause before clicking an unexpected link. And if something sends you to a page you're not sure about, take a second to verify where you are before entering anything sensitive. Then help someone else do the same.

Set up MFA with your parents.

Help a friend get a password manager.

Send this guide to the person who always says, "I can tell when something's a scam."

Cybersecurity doesn't have to be complicated.

It just has to become a habit.

Don't Make It Easy for Them.


Haven is a proud 2026 Cybersecurity Awareness Month Champion. Haven is operated by MirrorTab, Inc.

Frequently asked questions

What is Cybersecurity Awareness Month?
Cybersecurity Awareness Month is a global initiative held every October to raise awareness about online safety and encourage individuals and organizations to take practical steps to protect themselves from cybercrime. The National Cybersecurity Alliance's 2026 campaign theme is "Don't Make It Easy for Them."
What is the 2026 Cybersecurity Awareness Month theme?
The 2026 theme is "Don't Make It Easy for Them." The National Cybersecurity Alliance describes the theme as a reminder that online safety comes from building and consistently repeating small habits.
How can I tell if a website is legitimate?
Start by checking the web address and considering how you got there. Be especially cautious if the page arrived through an unexpected message, creates urgency, asks for sensitive information, or uses a domain you don't recognize. When in doubt, don't use the link you were sent. Navigate directly to the company's official website or app instead.
Is Haven free?
Yes. Haven is free for individual users. Haven provides an additional layer of browser protection by helping verify pages and flag suspicious activity, while also helping users identify risky browser extensions. For teams and organizations, Haven offers additional business plans and capabilities.