Build your cybersecurity fitness with daily reps of good habits

by | Oct 13, 2025 | Article

Article by Dan Whitty, Senior Information Security Manager at Good Grants

Cybersecurity and fitness have more in common than you think

We’ve all heard it before: “Consistency is key.” Whether it’s hitting the gym or staying healthy, it’s not one big workout that makes the difference but rather the little, regular things we do each day that build lasting strength.

The same principle applies to cybersecurity. Staying secure isn’t about having the most advanced tools or being a tech genius. It’s about building habits that become second nature, and doing them together as a team. When each person works to improve their “form,” the whole organisation gets stronger, protecting sensitive data and keeping information safe.

In honour of Cybersecurity Awareness Month, here’s how you can start training your cybersecurity “muscles” one habit at a time.

8 Cybersecurity habits to build into your daily work routine

Turn on multi-factor authentication (MFA): the classic push-up

Push-ups are simple but powerful, building core strength and stability. Enabling MFA works the same way. It’s an easy move that adds an extra layer of protection, reducing your risk of unauthorised access.

At Good Grants, we support MFA to help you keep your account secure by requiring a second verification method, like an app or SMS code. A few extra seconds can make all the difference.

Use a password manager: the deadlift

Strong posture, steady form: that’s what deadlifts are all about. And that’s what a password manager provides for your online life. Let it take the heavy lifting off your memory while keeping your credentials strong and unique.

We recommend tools like 1Password to safely store and generate passwords. It’s the smart way to build strength without the strain, and to finally say goodbye to “password1234.”

Lock your device: the trusty plank

A short hold, but full of benefits. Locking your screen when you step away is one of the easiest, most effective habits you can build. It keeps your “core” (your data and apps) protected, even when you’re taking a break.

Update your software: stay hydrated

Just like your body needs water to function, your devices need updates to stay in peak condition. Ignoring them leaves you vulnerable, like skipping hydration during a long workout.

Keep your system refreshed and secure by installing updates regularly. Outdated software is one of the easiest targets for cyber attackers.

Share files with care: spot your teammates

When you’re spotting someone at the gym, you stay focused and controlled and the same applies when sending or sharing files. Make sure permissions are correct, links are secure and sensitive information isn’t shared with the wrong person. A moment of mindfulness prevents costly “drops.”

Clean up old access: stay flexible

Regular stretching keeps you agile; cleaning up unused accounts and permissions does the same for your systems. Review access lists often and remove what’s no longer needed. Staying “limber” helps prevent tight spots that could become vulnerabilities down the line.

Report suspicious emails: correct bad form

If you see someone lifting incorrectly, you’d call it out. Cybersecurity works the same way; if an email or message looks suspicious, report it right away.

At Good Grants, we use Hoxhunt to train and gamify phishing awareness, helping everyone spot red flags and stay sharp. Speaking up protects you, your team and your grant community.

Stay alert and keep learning: build consistency

No one becomes fit overnight. Strength comes from showing up and staying consistent. Cybersecurity is exactly the same: ongoing awareness and curiosity keep you sharp.

Stay alert to new scams, question unusual requests and take time to learn. Every small action adds up to a stronger, more resilient organisation.

Security at Good Grants

At Good Grants, protecting client data is part of our daily routine. We follow strict security policies, regular audits, and comprehensive staff training. You can explore more about our approach to data protection in our Trust Centre.

But remember, real security strength comes from the collective effort. By building small, daily cybersecurity habits, you’re not just protecting yourself, you’re helping your whole team and community stay strong, aware and ready for anything.

Categories

Follow our blog

This field is for validation purposes and should be left unchanged.
Name(Required)