Opens in a new tab

Online Safety and Cybersecurity: 17 Important Tips

Table of contents

Start a new project with onlineKarma

Tell us about your goals, and we'll tell you how we can help.
Raphael Guldimann
Raphael Guldimann
Founder & CEO
Book a free consultation

[Article updated on August 8, 2024.]

Even major players like Facebook, Yahoo, and Digitec Galaxus have been targeted by hackers. However, the focus right now is primarily on small and medium-sized businesses (SMEs). That’s where most cyberattacks in Switzerland are currently taking place. There are a few simple but important steps you can take to protect yourself and your organization:

Screenshot of an SRF report on the cyberattack targeting Digitec-Galaxus customers

1 – Always Up to Date: The Key to Maximum Security

Keeping your devices and software up to date is one of the most fundamental and important steps you can take to improve your online security.

Be sure to regularly update all software —no matter how small—as well as any scripts and plugins you use anywhere on your website .

Be sure to also update the operating system on your device (Microsoft, Apple, etc.) and your web browser (Chrome, Opera, Safari, etc.).

Open-source versions are publicly available, and hackers can use their source code to discover potential vulnerabilities.

2 – Encrypt or Lose It: Why HTTPS/SSL Is Indispensable

Close-up of an illuminated laptop keyboard as a symbol of online security

Websites, emails, and the like should always be encrypted using HTTPS/SSL. If your website isn’t already using HTTPS, it’s high time you did so (this is also a requirement under the GDPR, by the way).

Websites that still use HTTP (Hypertext Transfer Protocol)—the standard protocol for transferring data between your server and the user’s browser—are vulnerable to hacker attacks (latest news on hacker attacks).

HTTPS/SSL encryption is particularly important for e-commerce websites and any sites that use forms containing sensitive user data or personally identifiable information (PII) .

A website encrypted with HTTPS/SSL appears in the browser as, for example, www.onlinekarma.ch:

Browser notification "Connection is secure" with a valid certificate

3 – Risks from Extensions: Beware of Malicious Plugins

Modern browsers, devices, and CMS (content management systems) offer a sheer endless array of extension options, plugins, and add-ons.

When doing this, make sure that the extensions:

  1. come from legitimate sources,
  2. be updated regularly,
  3. have already been downloaded a large number of times
  4. and there are enough positive reviews.

Be wary of free versions of premium plugins: These are usually pirated and infected with malware.

Any software can be compromised, and unfortunately, your website’s software is no exception.

— Sebastian EbneterOnline Marketing Specialist

4 – Only the Original Matters: The Value of Trust in Software

Hosting interface with WordPress, plugin, and security features

Use only genuine software from a well-known and trusted provider.

The same principle applies to emails, text messages, and WhatsApp messages containing links and attachments that seem suspicious. Only open files and links from senders you can trust 100 percent.

Warning: Emails may look very legitimate, but they aren’t necessarily so. The sender’s address can be spoofed—also known as“phishing.” Here are two examples:

Fake Stripe support email with a false sender address
An email from the payment provider Stripe? If you look closely, you'll notice the wrong sender URL.
Fake Squarespace Email About Disabled Automatic Renewal
It looks real, but it's FAKE.

Report phishing emails with a single click here on Switzerland’s official anti-phishing website.

👉 Tips on how to spot phishing emails (in English)

We’ve noticed a sharp increase in fraudulent direct messages sent to company pages on social media.
Stay vigilant and keep the following points in mind:

  1. Social media platforms will not contact you via direct message if there are any issues. Therefore, do not click on any links or attachments in such direct messages from people claiming to be representatives of the respective platform.
  2. Report the messages as spam.
  3. Continue your successful community management and stay alert.

5 – Passwords of the Future: Your First Line of Defense

A man enters the insecure passcode "000000"

via GIPHY

Of course, this point is a must. Strong passwords are the be-all and end-all of online security—both for your company and for you personally.

Password Tip 1

There is a simple formula that summarizes the three essential requirements for a secure password: CLU (Complex, Long, Unique).

  1. A password should be complex—that is, made up of random characters. No birthdates, no pet names, and no real words.
  2. Passwords should also be at least 20 characters long.
  3. And, of course, you shouldn’t use the same password in multiple places.

Password Tip 2

Now you’re probably thinking: How am I supposed to remember countless random 20-character passwords? That’s where tools like LastPass, a password manager that stores all your passwords in encrypted form and also generates random passwords for you.

Password Tip 3

Even the strongest passwords are useless if they aren’t used properly. So: Lock your cell phone, laptop, or computer when you’re not using it. And protect it with a password 😉.

Password Tip 4

Do not send passwords via email, and above all, never send a password together with the username and the purpose of use. By the way, https://pwpush.com/ is a handy tool for sending passwords.

6 – Protect Your Privacy: Avoid Public Networks

If you use confidential information while browsing the web—such as for online banking or shopping—you should do so on a device that belongs to you and on a network you trust.

Your data could be stolen while using a public, free Wi-Fi network, a coworker’s cell phone, or a publicly accessible computer.

You should also be careful about what personal information you share on social media . The “bad guys” could use this data to obtain valuable information about you.

7 – Strong Defense: Why You Can’t Do Without Antivirus Software

Golden Cybersecurity Lock as a Symbol of Virus Protection

Protect yourself against viruses that weaken your computer and make it more vulnerable to attacks. Install an antivirus package.

Avira, for example, is free, but paid software will offer you more comprehensive protection.

8 – Less Is More: Limiting Access Rights

If multiple users can edit your website, you should ideally follow the principle of least privilege: Grant access only to the applications and resources that are essential for a user’s work and for which he or she is authorized.

In other words, if someone “only” writes blog posts on your website, they shouldn’t have permission to customize the design of the entire site.

Be especially careful with guest posts to ensure that new users are not granted more privileges than are strictly necessary.

9 – Secure Hosting Provider, Secure Operations: What Matters Most

Price should not be the deciding factor in choosing a web host; rather, security considerations should be the primary consideration.

Your trusted web host should have an SSL-secure server (required for HTTPS; see above), offer secure email support, have a secure data center, and perform regular backups .

If, like many smaller companies, you host your website on a shared hosting server, ask your provider about the security measures in place.

10 – Safe Browsing: Security Tools for Your Browser

You can also protect yourself while browsing the Internet: with the security tool provided by your browser of choice.

These can, for example, block pop-ups, send “Do Not Track” requests to websites, disable insecure Flash content, restrict access to your webcam, and block potentially dangerous downloads.

You can find these security tools in your browser’s settings.

Chrome menu with the "Settings" entry highlightedChrome settings with the “Privacy and Security” section highlightedChrome Options for Privacy and Security

11 – Better Safe Than Sorry: Use Multi-Factor Authentication

In today’s digital world, a simple password is often no longer enough to protect our data. That’s where multi-factor authentication (MFA) comes in.

MFA provides an additional layer of security by requiring a second factor for verification, such as an SMS code or an authenticator app. This extra barrier can be crucial in preventing unauthorized access to sensitive information.

Companies should implement MFA wherever possible to strengthen their security strategy and effectively protect themselves against cyberattacks.

12 – Don't Leave Anything to Chance: Perform Regular Backups

Data loss can be caused by cyberattacks as well as hardware failures or human error. Regular backups are a simple yet effective safeguard to ensure that important information is not lost permanently.

Companies should develop a backup plan that includes both automatic and manual backups. These should be stored securely on external drives or in the cloud to ensure a quick and complete data recovery process in the event of an emergency.

13 – Knowledge Is Power: Cybersecurity Training for Employees

People are often the weakest link in the security chain. Given this, regular employee training on topics such as phishing, password security, and safe online behavior is essential.

By raising their employees’ awareness of the risks and keeping them informed about current threats, companies can foster a culture of security that significantly reduces the risk of cyberattacks.

14 – Keep Your Private Life Private: Stay Safe Online on Your Own Networks

Using public Wi-Fi networks can pose a significant security risk, as data transmissions can easily be intercepted. Companies should encourage their employees to use only secure, private networks, especially when accessing sensitive company data.

In addition, security measures such as WPA3 encryption should be implemented in wireless networks to prevent unauthorized access and ensure the integrity of the transmitted data.

15 – Stay Informed: Rely on reputable sources

It is important to stay up to date on the latest security threats and measures. Websites such as the Cybersecurity & Infrastructure Security Agency (CISA) offer comprehensive information and guidelines that can help improve a company’s security strategy.

Regularly consulting such reliable sources can help identify best practices and detect emerging threats in a timely manner.

16 – Leave No Gaps: Security Checks Are a Must

Regular security audits are crucial for identifying and addressing vulnerabilities in the system before they can be exploited. A thorough audit should cover all aspects of the IT infrastructure, from network security to software applications.

Companies should consider engaging specialized service providers to conduct independent audits that help address security vulnerabilities and optimize their overall security strategy.

17 – Always Connected, Always Protected: VPN for Greater Security

For employees who work on the go or from home, using a VPN (Virtual Private Network) is essential. A VPN encrypts the Internet connection, thereby protecting against unauthorized access to confidential information. (VPN Review: A Comparison of the Best VPN Providers)

By using a VPN, companies can ensure that their data remains secure even when employees are away from the office and that their privacy is protected.

Bonus Tip – ICT Security

We are happy to recommend Sowacom’s security solution. From cyber protection to data security to cyber insurance , this ICT partner can provide you with expert assistance. Learn more here about their cybersecurity offerings for small and medium-sized businesses.

Cybersecurity Summary

Those were the 10 tips to help you ensure greater security for yourself and your website. Of course, there’s no guarantee that your website will never be attacked or hacked, even if you follow all of these tips.

However, this should protect you against the majority of automated attacks and, at the very least, drastically reduce the overall risk.

Animation on Safe Travel

via GIPHY

Protect your WordPress website

Discover our maintenance packages for Swiss companies – for less risk, fewer outages, and more security.
Our Maintenance Packages
Seliem Attia
About the author

Seliem Attia

Team Lead

Seliem Attia is a Team Lead at onlineKarma.

Profile and more articles

You might also be interested in

An onlineKarma employee explains technical content on a laptop
July 9, 2026

How to protect your website

Cybercriminals are becoming increasingly targeted. The Federal Office for Cybersecurity (BACS) states in its latest semi-annual report that attacks are increasingly individualized, with artificial intelligence being used more and more frequently.
Read more
A person is working on building a website on a laptop
September 30, 2025

9 Tips for Creating a Strong Homepage

New visitors should be able to understand within 2–3 seconds what you offer and why they should stay.
Read more
View all items

Now you know what's possible. Let's make it happen together.

We don’t just write about it – we implement it every day for our customers.

Get in touch with no obligation

Get in touch for a no-obligation conversation. We usually reply within a few hours.

By submitting this form, you agree to our privacy policy.

Talk to us directly

Call us for a free initial consultation: 061 551 02 02.

Phone Hours
  • Mon–Thu: 8:00 a.m.–12:00 p.m. and 1:00 p.m.–5:30 p.m.
  • Fri: 8:00 a.m.–12:00 p.m. and 1:00 p.m.–5:00 p.m.
  • Sat–Sun: Closed
Call now