← All terms

Cyber Hygiene

Cyber hygiene is the set of routine practices — updates, strong authentication, least privilege, awareness — that keeps users and systems resistant to attack.

Cyber hygiene is the set of routine, low-cost practices that keep systems and users resistant to common attacks — the security equivalent of hand-washing. For systems, that means timely software updates, secure configuration, backups, and least-privilege access. For people, it means strong unique passwords in a password manager, multi-factor authentication, caution with links and attachments, and reporting anything suspicious quickly. The term has moved from advice to law: the EU's NIS2 Directive lists "basic cyber hygiene practices and cybersecurity training" among the minimum measures every in-scope entity must implement, and its Recital 89 frames hygiene — zero-trust principles, software updates, device configuration, user awareness — as a practice spanning the whole workforce, not an IT-only duty.

How it works

Hygiene works through accumulation rather than any single control. Most intrusions chain small failures: a reused password, a missed update, an unsanctioned tool operating as shadow IT, an employee who hesitates to report a suspicious email. Each hygiene practice removes one link from that chain, and because attackers overwhelmingly take the cheapest path — commodity phishing and credential abuse rather than novel exploits — consistent basics eliminate a large share of realistic attack paths before any advanced defense is needed. The hard part is not knowing the practices but sustaining them across thousands of people and devices, which is why hygiene decays silently between audits.

How to defend with it

Treat hygiene as a measured program, not a poster campaign. Define a small set of practices per role, automate what machines can enforce (patching, MFA, configuration baselines), and train what only people can do — recognizing manipulation, handling data carefully, reporting fast — reinforcing it between trainings with well-timed security nudges. Then verify behavior rather than assuming it: phishing simulations test the human practices under realistic pressure, and tracking outcomes in a human risk score shows where hygiene is genuinely holding versus merely documented. Under NIS2's human-risk requirements, that evidence doubles as compliance documentation — regulators increasingly ask organizations to prove their hygiene, not just describe it.

Related terms

NIS2 DirectiveThe NIS2 Directive (EU 2022/2555) is the EU cybersecurity law for 18 critical sectors, mandating risk management, training and 24-hour incident reporting.Password ManagerA password manager generates, stores, and autofills unique credentials — a core defense against credential stuffing, password reuse, and lookalike phishing sites.Shadow ITShadow IT is technology used without IT approval — unsanctioned apps, accounts, and AI tools that expand attack surface outside security's visibility.PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo