Resources
Free, trustworthy cybersecurity tools and references — vetted, with a note on why each one is here.
A short, opinionated list. Everything here is free to use and comes from a source we'd trust ourselves. Short beats comprehensive — a list of 200 tools helps nobody.
How to read this page. We don't take payment or affiliate commissions for any listing. If that ever changes, it'll be disclosed on the line item, not buried in a footer.
Check your exposure
- Have I Been Pwned— enter an email address to see which known breaches it appeared in. Run by security researcher Troy Hunt, and the standard reference for this. Start here if you've never checked.
- Firefox Monitor— the same underlying breach data with ongoing alerts, if you'd like to be told rather than have to check.
Password managers
Any of these is dramatically better than reusing passwords. Pick one and commit.
- Bitwarden— free tier covers unlimited passwords across all your devices. Open source and independently audited. The default recommendation for most people.
- 1Password— paid, but the family and small-team sharing features are worth it if several people need shared access.
- KeePassXC— fully offline, your database stays on your own machine. More effort to sync; the right pick if you don't want a cloud service involved at all.
Multi-factor authentication
- Aegis (Android) /Ente Auth (iOS & Android)— free, open-source authenticator apps with encrypted backups. Better than SMS codes, which can be intercepted through SIM swapping.
- YubiKey— a physical security key. The strongest widely-available protection against phishing, because the key simply won't authenticate to a fake site.
Learning and reference
- CISA Secure Our World— US government guidance for individuals and small businesses. Genuinely readable, which is rarer than it should be.
- NCSC Cyber Aware— the UK equivalent, similarly plain-spoken and applicable anywhere.
- OWASP Top 10— the standard reference for web application risks. Aimed at developers.
- Krebs on Security— investigative reporting on cybercrime. Deeper than headline coverage.
For small organizations
- CIS Critical Security Controls— a prioritized checklist of what to do, in order. Implementation Group 1 is designed for organizations with limited resources.
- NIST Small Business Cybersecurity Corner— free templates, planning guides, and worksheets.
- CISA Free Cybersecurity Services— a catalog of no-cost tools, many usable by small organizations.
Reporting cybercrime
- United States — IC3(FBI Internet Crime Complaint Center) andreportfraud.ftc.gov
- United Kingdom —Action Fraud
- Canada —Canadian Anti-Fraud Centre
- Australia —ReportCyber
Know something that belongs here, or spot a link that's gone stale?Let us know.