Categories
Pages
-

IT Center Blog

The Pitfalls of Everyday Life – Information Security in Everyday Life

June 8th, 2026 | by
ein Laptop umgeben von Symbolen für IT-Sicherheit

Source: Own illustration

We all handle sensitive information on a daily basis, whether at the office, at university, or at home. However, we often underestimate how complex the issue of information security has become. Both companies and private individuals have data that needs to be protected, and this data can be stored digitally or, more traditionally, on paper or in our heads. Protecting information assets therefore requires more than just technology: it also means being mindful and responsible in our everyday lives. As attackers continue to develop their methods, we too must regularly train our awareness and knowledge.

 

 

The Protection Goals of Information Security and Their Implementation

In order to protect information assets in a targeted manner, information security is based on three fundamental protection goals: confidentiality, integrity, and availability. These goals help to systematically identify risks and define appropriate protective measures.

However, before concrete measures can be taken, data classification is necessary. To assess the criticality or confidentiality of information, the “Traffic Light Protocol” can be used, for example. This internationally recognized system divides information into four levels:

  • Red: strictly confidential – intended only for a very limited group of recipients
  • Yellow: confidential – may be shared on a restricted basis within the organization and with clients
  • Green: within a community – for a larger but defined group within an organization
  • White: public – no restrictions on sharing

Depending on the classification, measures are then taken to implement the individual protection objectives:

  1. Ensure confidentiality: This includes encrypting messages and emails, keeping meetings (both digital and on-site) confidential, and securing workplaces. This can be done, for example, by locking rooms or locking screens. And finally, do not conduct sensitive conversations in public spaces.
  2. Ensure integrity: Here, documents are sealed, archived in a tamper-proof manner, or signed.
  3. Maintain availability: This involves regular backups – ideally offline and in separate locations – or test runs for recovery to ensure functionality in an emergency.

 

Behavior in Everyday Situations

Many small behaviors contribute to the effective protection of sensitive information – often, all it takes is an alert eye for your surroundings and a little common sense.

Confidential conversations on the phone should be avoided in public spaces. If you work on the go, you should protect your screen from prying eyes (known as shoulder surfing) with a privacy filter. Laptops should never be left unattended, and if they are, they should at least be secured with a screen lock and ideally with a cable lock. A “clean desk” is not only useful in the office, but also on the train, at university, or at home. Confidential documents should not be thrown in the trash after use, but in a document shredder.

Caution should be exercised when using Wi-Fi connections: You should not automatically connect to public networks – such as WiFi on ICE or open café hotspots – as these are vulnerable to so-called rogue access points. A secure alternative is offered, for example, by Eduroam, which is secured by a certificate-based procedure and also EAP-PWD (if configured in this way, more information at IT Center Help). In addition, VPN connections and SSL encryption provide greater security when surfing and working on the Internet.

Today, smartphones are both constant companions and potential vulnerabilities. A simple swipe gesture or a visible PIN when unlocking is often not enough. Better: a fingerprint sensor that is discreet, secure, and works even if the display is damaged. In the event of loss or theft, a “remote wipe” function should be activated so that stored data can be deleted remotely.

Last but not least, your home Wi-Fi should not be neglected: a strong password, regular firmware updates for your router (preferably automatic) and the deactivation of unnecessary functions contribute to basic security here.

 

Examples From Everyday Life

Not all information security threats are theoretical; many occur on a daily basis, often where you least expect them. The following examples show typical attack scenarios from everyday life and provide tips on how to behave correctly in such situations:

  1. “Service technicians” take over the company’s IT

In a test case, so-called white hat hackers – ethical hackers working on behalf of the company – gained access to a company network by posing as external technicians. With a laptop and a few cables, they were able to manipulate network equipment unhindered without serious questioning. Solution: Always ask for ID, register visitors with the relevant department, and ensure that visitor badges are issued.

  1. Social engineering on the phone: “Microsoft is calling.”

A common scam: A supposed Microsoft hotline calls and claims that the PC has been hacked. The user is asked to install TeamViewer – after which bank accounts and PayPal are accessed.

Solution: Be suspicious of unexpected IT calls. Do not allow remote maintenance! Microsoft does not call private individuals.

  1. Phishing via email or SMS

This involves alleged DHL shipment tracking, fake bank notifications, or a supposed Amazon account. The emails often look deceptively genuine. Solution: Check the sender’s address carefully, don’t just look at the display name. Be wary of urgency, threats, or links. If in doubt, do not click on the link, but go directly to the provider’s official website. You can find more information on this at IT Center Help.

  1. WhatsApp account taken over by changing the number

Fraudsters exploit people’s economic fears to trick them with offers that are too good or too bad to be true! They also use AI to create attacks. A contact suddenly writes: “I’ve changed my number, can you forward me the code you just received?” Behind this is an attacker trying to hijack the account. Solution: Never forward security or confirmation codes. If in doubt, call back to double-check.

 

Working Together for Greater Security

Information security is a constant challenge. It requires attention, common sense, and a willingness to ask critical questions in unusual situations. It often helps to compare new or digital threats with familiar analog situations: Would you give your account details to a stranger on the street? Probably not, so don’t do it via email or messenger either.

Remain alert to anything unusual, but also be brave enough to ask questions openly or report possible errors. Nobody is perfect – the important thing is that we learn from incidents. Error reports are treated discreetly, because only through openness and trust can we create a secure environment together.

Further information can be found on the SOC information page. In most cases, the IT-ServiceDesk is the first point of contact.

 


Responsible for the content of this article is Malak Mostafa.

Leave a Reply

Your email address will not be published. Required fields are marked *