I have made my living protecting people for many years, and in that time the centre of gravity of risk has shifted noticeably. An attacker can now obtain much of the information that once required physical surveillance from an email, a phone or what someone has posted about themselves. Here is what I do about it in practice, and what I recommend to the people I protect.
Today an attack usually starts with a message, not with surveillance
The pattern I see most often with clients looks harmless. A message arrives that appears to come from a manager or a colleague, with a similar signature, a similar way of writing and the same clipped style. It asks for something that seems trivial: forward the travel itinerary, confirm an address, send over a contact.
That small thing is exactly the problem. A travel itinerary means precise times, addresses and routes. That is no longer just a data leak; it is a blueprint for anyone who wants to catch a person in the wrong place. This is precisely where the physical and digital sides of protection meet.
Over my years in this line of work, I have learned to read an environment: who is watching, who turns round, which window is not empty by chance. But the world has moved on. Information that once had to be gathered through physical surveillance can now often simply be requested, looked up or read from publicly available sources.
I take a data leak as seriously as a forced door
The attacks I encounter with clients rarely begin with sophisticated hacking. They begin with phishing: a message that appears to come from someone trustworthy and asks you for a single response. A click, a login, a payment confirmation. The attacker takes care of the rest.
Alongside it there is malware, which reaches a device through an attachment or a downloaded installer and quietly records what you type and where you go. Then there is ransomware, which encrypts your data and offers it back to you for a ransom. Identity theft tends to be the quiet one: someone acts in your name, and you only find out when you have to go to great lengths to explain it.
The consequences tend to be of three kinds, and none of them is pleasant. Financial loss, which can usually be dealt with somehow. Damage to your reputation, which is much harder to repair. And the psychological toll, because the feeling that a stranger is reading your correspondence does not leave your head easily.
What interests me most, though, is a fourth consequence that IT rarely considers. Leaked data can be pieced together into a routine: where you live, when you leave home, where you take the children, where you have lunch. That is exactly what someone who wanted to threaten a person physically would need to know. That is why I treat data hygiene as part of close protection, not as a separate subject.
The password you cannot remember is usually the better one
The most common mistake I see among clients is not a weak password. It is one password used in ten different places. It only has to leak from a single unimportant service, and an attacker will try it everywhere else. And that service is usually one you forgot about long ago.
A good password is long and used nowhere else. A whole sentence you can recall beats a short word with a digit tacked on the end. Above all, use a different one for every account. Nobody can remember all that, which is exactly why you should not try: that is what a password manager is for.
A password manager is something clients tend to shrug off at first and later refuse to give up. It generates a unique password, stores it and fills it in for you. You remember just one: the master password, which you must never use anywhere else. Critical accounts, email above all, should each have their own password, without exception. Email is the key ring to everything else: whoever controls it can use it to regain access to almost anything.
A second lock that is harder to open remotely
In my experience, two-factor authentication is one of the measures with the best return on the time invested. It takes a moment to switch on, and after that a guessed password is no longer enough to log in: a second confirmation step is needed too. Someone with only a stolen password usually has no way to complete that second step.
Turn it on wherever you can, starting with email, banking, cloud storage and social media. If you have to choose a method, I prefer an authenticator app or a physical security key to SMS codes. SMS is better than nothing, but in certain circumstances a phone number can be redirected, and the second lock is gone.
One practical detail. When a service offers you backup codes as you switch it on, print them and keep them somewhere physical, ideally with your important documents. I have met people who were locked out of their own accounts by the very security they had switched on themselves.
The boring part that decides everything
The rest is hygiene. There is nothing exciting about it, which is exactly why it gets neglected. Updates are postponed because now is not a good time. Backups are only sorted out after data has been lost. And public Wi-Fi in a hotel looks harmless right up to the moment someone is listening in.
When I go through a client's devices with them, I always work through this list:
None of this is technically demanding, and you can handle most of it yourself. Yet the difference between someone who has done it and someone who keeps putting it off only shows at the moment when it is too late to catch up.
- Operating system, apps and security software kept up to date, ideally automatically
- Backups of important data on an external drive or in encrypted cloud storage, and checked to make sure they can actually be restored
- A VPN on public networks: in hotels, at airports, in cafés
- Software downloaded only from official stores and the manufacturer's own website, never from a link in a message
- Regular review of app permissions on your phone: location, microphone, camera, contacts
- An encrypted messaging app for sensitive calls and messages, not ordinary SMS
What you give away about yourself without meaning to
I have nothing against social media. I simply ask clients for two things: do not share your location in real time, and do not post anything from which a routine can be inferred. A holiday photo can wait until you are home. A picture from the car does not need to show a legible number plate or the area around your house. And a regular post from the same place on the same day of the week is information I would keep to myself, in your position.
The same rule applies to family and those closest to you. Security measures are usually circumvented not through the client but through a partner, the children, an assistant or a driver. Privacy protection that stops at one person is only half done.
Companies work in much the same way. An organisation is only as secure as the least careful person on the team, and that is not necessarily the most junior. That is why I include digital risks in security audits, and why I push so hard for staff training: recognising phishing, verifying unusual requests through a second channel and basic rules for handling technology. When I deploy CCTV and monitoring systems, they are encrypted and configured to comply with GDPR, because a measure that creates a legal problem of its own fails in its purpose.
Key takeaways
If I had to sum up this whole article in one thought, it would be this: information about you is now as sensitive as the keys to your house, and it deserves the same care. No fear, no paranoia. Just good order.
In practical terms, that means four steps nobody else will take for you. Unique passwords stored in a password manager. Two-factor authentication wherever possible, starting with email. Updates and backups that genuinely run. And conscious decisions about what you, and the people around you, let out into the world.
None of these measures guarantees anything, and nobody can honestly promise that an attack will never touch you. The point lies elsewhere: to reduce the amount of information that can be gathered about you, and to increase the chance that someone spots an irregularity in time.
The cheapest measure of all is a habit, not a piece of technology: verifying an unusual request through a different channel from the one it arrived on. Picking up the phone and asking. It can be learned, and it works even where technology fails.
If you are not sure where your family or company stands, we can go through it together calmly. I offer a no-obligation consultation in which we look at both the digital and the physical side and agree what is worth tackling straight away and what can wait. Discretion goes without saying.
“I do not treat a personal data leak as an IT issue. I treat it as information about where and when a person moves.”— Robert Václavík



