Cyber Hygiene
Cyber hygiene is the set of routine practices — updates, strong authentication, least privilege, awareness — that keeps users and systems resistant to attack.
Cyber hygiene is the set of routine, low-cost practices that keep systems and users resistant to common attacks — the security equivalent of hand-washing. For systems, that means timely software updates, secure configuration, backups, and least-privilege access. For people, it means strong unique passwords in a password manager, multi-factor authentication, caution with links and attachments, and reporting anything suspicious quickly. The term has moved from advice to law: the EU's NIS2 Directive lists "basic cyber hygiene practices and cybersecurity training" among the minimum measures every in-scope entity must implement, and its Recital 89 frames hygiene — zero-trust principles, software updates, device configuration, user awareness — as a practice spanning the whole workforce, not an IT-only duty.
How it works
Hygiene works through accumulation rather than any single control. Most intrusions chain small failures: a reused password, a missed update, an unsanctioned tool operating as shadow IT, an employee who hesitates to report a suspicious email. Each hygiene practice removes one link from that chain, and because attackers overwhelmingly take the cheapest path — commodity phishing and credential abuse rather than novel exploits — consistent basics eliminate a large share of realistic attack paths before any advanced defense is needed. The hard part is not knowing the practices but sustaining them across thousands of people and devices, which is why hygiene decays silently between audits.
How to defend with it
Treat hygiene as a measured program, not a poster campaign. Define a small set of practices per role, automate what machines can enforce (patching, MFA, configuration baselines), and train what only people can do — recognizing manipulation, handling data carefully, reporting fast — reinforcing it between trainings with well-timed security nudges. Then verify behavior rather than assuming it: phishing simulations test the human practices under realistic pressure, and tracking outcomes in a human risk score shows where hygiene is genuinely holding versus merely documented. Under NIS2's human-risk requirements, that evidence doubles as compliance documentation — regulators increasingly ask organizations to prove their hygiene, not just describe it.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo