Three-layer model

Defend the whole path, not one device.

A resilient environment has a visible boundary, hardened systems and people who know what to do. A weakness in any one layer can undo the others.

03 / Boundary

Control the edge

Separate trusted, guest and IoT traffic. Remove default administration, review exposed services and use an encrypted tunnel for remote access.

05 / System

Harden and recover

Patch quickly, encrypt storage, reduce privileges, retain useful logs and prove that an offline backup restores correctly.

07 / Human

Make behaviour dependable

Use unique credentials and MFA, recognise manipulation, keep devices current and rehearse the first hour of an incident.

Operating principles

Evidence beats confidence.

“It should be secure” is not a control. Record what is configured, when it was checked and whether recovery was actually tested.

Never trust by location alone

A device on the home or office network still needs a known identity and the minimum access it requires.

Design for recovery first

A backup is useful only after a successful restore with a known recovery time.

Prefer boring, repeatable controls

Automatic updates, password managers and clear checklists outperform heroic response under pressure.

Include the household or team

A simple shared vocabulary and escalation path reduce hesitation during an incident.

Keep an offline option

Critical contacts, instructions and references should remain available without an account or WAN link.

Make it concrete

Turn the model into fifteen checks.

The checklist saves progress only in your browser. No account, analytics or server-side storage.