— The full list
The cybersecurity beliefs that get repeated the most — and what's actually true behind each one.
Myth
Incognito mode makes you anonymous online.
Fact
It only hides your history from others using your device — your internet provider and the sites you visit can still see you.
Myth
I'm too unimportant to be hacked.
Fact
Most attacks are automated and cast a wide net — they target anyone reachable, not specific "important" people.
Myth
A strong password is enough on its own.
Fact
Without two-factor authentication, even a strong password can be handed straight over by a good phishing email.
Myth
Antivirus software catches everything.
Fact
It catches known threats well. New or targeted attacks often slip through — habits matter more than any single tool.
Myth
Public Wi-Fi is fine as long as I'm not doing banking.
Fact
Anything unencrypted on open Wi-Fi can be read by others on the same network — emails and logins included, not just banking.
Myth
Deleting a file removes it permanently.
Fact
Deleting usually just hides the file from view — the data often stays recoverable on the drive until it's overwritten.
Myth
Two-factor authentication is too much hassle to bother with.
Fact
It adds seconds to logging in and blocks the vast majority of account takeovers — one of the highest-value habits there is.
Myth
Phones can't get viruses the way computers can.
Fact
Phones are more locked-down by design, but malicious apps and scam links still affect them — they're not immune, just harder to target.
Myth
A padlock icon in the address bar means a site is completely safe.
Fact
It only means the connection is encrypted — scam sites can have a padlock too. It says nothing about who runs the site.
Myth
Changing your password often makes you safer.
Fact
Frequent forced changes often lead to weaker, more predictable passwords. One strong, unique password per account beats that.
Myth
Hackers only go after big companies.
Fact
Small businesses and individuals are frequent targets precisely because they tend to have weaker defenses in place.
Myth
Reusing one strong password everywhere is fine.
Fact
If just one of those sites is ever breached, every other account sharing that password becomes vulnerable too.
Want the full picture in one sitting? The free guide covers the habits that matter most.
Get the free guide →