
In 2024, the number of personal data breaches reported to the CNIL has significantly increased compared to the previous year. The number of breaches affecting more than one million people has doubled during the same period. The platform Cybermalveillance.gouv.fr received over 400,000 assistance requests, 94% of which came from individuals. These figures illustrate a context where individual digital protection is no longer a topic reserved for businesses or administrations.
Phishing and fake technical support: the anatomy of attacks targeting individuals
Phishing accounts for more than a third of reports on Cybermalveillance.gouv.fr. The mechanism has remained stable for several years: an email or SMS mimics a trusted entity (bank, delivery service, tax administration) to encourage the target to provide their credentials or banking information. What evolves is the quality of the bait. Messages contain fewer and fewer spelling mistakes, and the landing pages faithfully reproduce official interfaces.
Fake technical support is among the top three threats targeting individuals in France. The typical scenario: a window pops up on the screen, simulating a system alert, and a phone number invites the user to contact a supposed technician. This technician requests remote access to the computer, then charges for a fictitious intervention or installs malware.
These two types of attacks exploit the same lever: visual trust. An official logo, a neat layout, or an alarming tone is enough to short-circuit vigilance. Recognizing this mechanism constitutes the first line of defense, well before any software tool. Resources like those offered on cyberspass.fr help familiarize users with these attack patterns and better identify them in daily life.

Password managers and two-factor authentication: concrete friction points
Most guides recommend using long, complex, and different passwords for each service. This advice is correct. The problem is that it is unmanageable without a dedicated tool. An average user manages several dozen online accounts. Memorizing so many unique combinations is a mnemonic feat.
A password manager (KeePass, Bitwarden, or the one integrated into the browser) stores and generates these combinations. One master password protects the entire vault. The security gain is significant, provided that this master password is itself robust and never reused elsewhere.
Two-factor authentication (2FA) adds an extra layer. Even if a password is compromised, access to the account requires a second factor: a temporary code via an app, a physical USB key, or a notification on the phone. Adoption by individuals remains hindered by activation interfaces that are sometimes buried in settings. Some services only offer 2FA via SMS, a channel vulnerable to interception (SIM swapping).
- Prefer an authentication app (like FreeOTP, Google Authenticator) rather than SMS for receiving temporary codes.
- Enable 2FA as a priority on the main messaging service, as it serves as a recovery point for almost all other accounts.
- Ensure that the password manager itself is protected by two-factor authentication, to prevent a single vulnerability from compromising everything.
Software updates and backups: two recurring blind spots
Updates are not only meant to add features. They fix identified security vulnerabilities, sometimes already exploited by attackers. Postponing an update is like leaving a publicly documented door open. Operating systems, browsers, and mobile applications release patches at regular intervals, and each day of delay widens the exposure window.
Enabling automatic updates on all devices (computer, phone, tablet, connected objects) reduces this risk effortlessly. For software that does not offer this option, a monthly check is sufficient in most cases.
Data backup remains the other blind spot. In the event of ransomware, theft, or hardware failure, unsaved files are lost. A regular backup on an external device that is not permanently connected significantly limits the impact of an incident. The “3-2-1” principle (three copies, two different media, one off-site copy) provides a simple framework to remember.

Personal data on social networks: the link that tools do not cover
No antivirus protects against information voluntarily published. Date of birth, pet’s name, real-time vacation location: these elements, shared on social networks, frequently serve as answers to security questions or facilitate targeted social engineering attacks.
Reducing exposure involves a few concrete adjustments:
- Restrict profile visibility to confirmed contacts rather than the public.
- Remove personal information that can be used as password hints (date of birth, maiden name, hometown).
- Disable automatic geolocation of posts, which provides real-time information about movements.
- Audit third-party applications connected to the account and revoke those that are no longer used.
These adjustments take only a few minutes per platform. The main risk is not technical but behavioral: posting less, or posting with a delay, radically changes the attack surface offered to a malicious actor.
Everyday cybersecurity relies less on the accumulation of tools than on a handful of practices applied consistently. A password manager, two-factor authentication on critical accounts, automatic updates, and regular backups cover the vast majority of risks faced by individuals. The rest is a matter of attention to what one clicks, what one publishes, and what one postpones to tomorrow.