“Cover Your Assets” in a Constantly Connected World

Living in 2026 means that we live in an increasingly digital society, one that operates continuously and rarely takes a moment to breathe. Smartphones with Apps melded with a 24‑hour news cycle ensure that information is always available, notifications are always popping-up, and attention is always demanded. While this environment offers convenience and access, it also introduces risks. These are technical, psychological, and behavioral risks while remaining secure and grounded in this context require deliberate choices rather than passive participation.

The following are practical steps that can help reduce exposure, limit unnecessary intrusion, and preserve personal agency in an always‑on world.

1) Use a Pattern or PIN to Unlock Devices While Avoiding Biometrics

One of the simplest decisions involves how we secure our devices. Using a pattern or PIN to unlock a phone, laptop, or tablet. This is rather than relying on biometrics, which provides a level of control that other convenience features cannot. Biometrics are efficient, but they are not secrets; they cannot be changed if compromised. A pattern or long PIN can be updated at any time and places control back in the user’s hands. This choice prioritizes adaptability over speed.

Problem: If your device is secured with biometrics, anyone can unlock it simply by holding it up to your face or placing your thumb on the sensor. If you are incapacitated or unalived, the device and every account accessible through it can be unlocked without your consent. The same is true if you are detained or questioned by authorities; your face or fingerprint can be used to unlock the device without you saying or doing anything.

2) Do Not Write Down or Reuse Passwords

Password practices remain another foundational issue. Passwords should never be written down or reused across accounts or services. Reuse creates cascading failure: one breach becomes many. Writing passwords down eliminates the assumption of secrecy altogether, as each important account should have a unique password, generated and remembered—or managed with purpose. I explored this topic in more depth in a post I wrote last year, which outlines structural approaches to password creation rather than reliance on memorization alone.

Blog Reference: https://www.lifecycle365.com/password-algorithms/

3) Turn-off Automatic Location Tracking on Your Mobile

Location data represents a quieter but equally important concern. Many mobile applications collect location information even when it is not essential to their function. Over time, this creates a detailed record of movement and behavior that most users neither need nor explicitly agreed to share. Disabling automatic location tracking, and enabling it only when absolutely necessary, reduces passive surveillance and limits the accumulation of unnecessary data about daily life.

On both major mobile platforms, location tracking is enabled by default and must be deliberately restricted by the user/owner. In either case, the responsibility falls on the user to review and restrict these settings. Leaving default location tracking enabled passively generates a detailed log of movement that is rarely necessary and often never intentionally consented to.

  • iPhones ship with system‑level location services turned on, allowing the operating system and many applications to collect location data unless this access is explicitly disallowed.
  • Android devices provide similar capabilities, but they also allow users to manually turn off automatic location tracking and limit access on an application‑by‑application basis.

Problem: Automatic location tracking also introduces significant legal and practical consequences that many people do not consider until it is too late. Location data can provide a precise record of where a device was, how long it remained there, and the paths taken before and after an “event.” If someone is arrested or questioned, this data can be used to place them at a specific location for a specific duration, regardless of intent. In cases involving reckless behavior or major disturbances, there is often little meaningful way to contest this data once it exists in the hands of authorities. This risk becomes especially relevant during protests or large public gatherings, where individuals who are present but not involved in harmful activity may still be associated with events simply because their device shows they were there at the time incidents occurred. Passive location logging can therefore blur the line between presence and participation.

4) Use Many Personal Email Addresses

Managing one’s digital identity benefits from separation and maintaining multiple personal email addresses, for different roles, helps contain risk and reduce cognitive overload.

  • A primary email should be reserved for personal communication with family, friends, and direct contacts.
  • A second and separate address should be used for transactional matters such as job applications, banking, shopping, and government services.
  • A third address can absorb newsletters, subscriptions, and mailing lists that may be deemed as junk by many, but also necessary.

This structure makes it easier to detect suspicious activity, isolate compromised accounts, and disengage from nonessential information streams.

5) Aggressively Limit Mobile Notifications

Mobile application notifications are another area where deliberate limitation pays dividends for device owners. Most apps have no legitimate need to interrupt users in real time with their generic updates. Allowing notifications only from a very small set of essential applications, and disabling lock‑screen previews entirely, prevents information from demanding attention before it is consciously requested. This reduces distraction and restores a basic boundary between the individual and the device.

Problem Solved: Aggressively limiting mobile notifications also solves several secondary problems that are often overlooked.

  • When lock‑screen previews are disabled, no one can read incoming notifications unless the device is unlocked or the application is intentionally opened.
  • Restricting notifications to only essential applications ensures that the information you do see is deliberate rather than cluttered with promotional or irrelevant messages.
    • This greatly reduces the accumulation of unread alerts, eliminating the need to clear dozens, or hundreds, of notifications that never required attention in the first place.
    • Minimizing notifications reduces exposure to junk messages, including scam and phishing attempts that often rely on urgency and surprise to be effective. In this way, notification control improves privacy, focus, and security simultaneously.

6) Set Boundaries Around News and Social Media Consumption

Finally, the issue of information consumption, particularly news, deserves explicit boundaries. The modern news cycle is continuous and optimized for urgency rather than proportion and accuracy. Constant exposure encourages a state of ongoing alertness that is neither sustainable nor informative, but repetitive at its core. Staying informed does not require perpetual monitoring of the same information on repeat. Designating specific times for news consumption and avoiding continuous checking throughout the day helps prevent anxiety, fatigue, and the illusion that everything requires immediate reaction.

7) Turn On Multi‑Factor Authentication (MFA)

Passwords are a necessary baseline, but they are no longer sufficient protection for high‑value accounts such as email, banking, cloud storage, and primary social accounts. Multi‑factor authentication adds an additional requirement beyond a password, making credential theft far less catastrophic. MFA is one of the simplest upgrades that meaningfully reduces account‑takeover risk.

Problem: A strong password still fails if it is phished, leaked in a breach, written down for the reading, or reused by an attacker through automated “credential stuffing” attacks. With MFA enabled, the password alone is not enough to enter the account, which blocks many real‑world takeovers at the moment they would otherwise succeed.

8) Build a Recovery Plan: Backups Plus Password Algorithms

Security isn’t only about preventing intrusion; it’s also about preventing irreversible loss. Devices fail, accounts get locked, phones get stolen, and people get unexpectedly removed from their own digital lives. A deliberate recovery plan means maintaining current backups of critical data, storing recovery codes for important accounts in a secure place, and designing a minimal “break glass” path that allows trusted people to handle essentials without granting them blanket access to everything. This turns emergencies into manageable events instead of permanent damage.

Problem: Without backups and recovery materials, a single incident like a phone loss, account lockout, hardware failure, or a compromised email can cascade into total digital loss and massive amounts of stress. Worse, rushed recovery often leads people to weaken security at the exact moment they are most vulnerable (reusing passwords, turning off protections, or granting excessive access). A pre‑made recovery plan prevents panic‑driven decisions.

Conclusion

None of these steps require abandoning technology or disengaging from this modern digital world. They are small, intentional decisions that shift control away from systems designed to capture attention and back to the individual and other individuals around them. In an ultra‑digital society, security and well‑being are no longer passive conditions; they are practices. Choosing how and when we engage is one of the most effective ways to protect both.

Leave a Reply