Cybersecurity Resources
Protect Your Financial Life Online
Digital security is an important part of protecting your financial life. While no checklist can prevent every scam or cyber threat, a few practical habits can help you recognize suspicious activity, reduce risk, and respond more confidently if something happens or doesn’t seem right. Totus Wealth Management created this resource page to help clients and families stay alert to common cybersecurity threats, strengthen everyday digital habits, and know where to turn for trusted information.
Think Before You Click
Avoid clicking links or opening attachments in your email unless you were expecting them and recognize the sender. If anything feels unusual, contact the person or organization through a trusted channel before clicking links or responding.
Use a VPN on Public Wi-Fi
Most websites encrypt data in transit, but a trusted VPN can add privacy on public Wi-Fi. Confirm sites use HTTPS, and avoid financial accounts if the network or connection seems unfamiliar or insecure.
Turn On MFA Options
Multi-factor authentication adds another step when you sign into an account. Even if someone gets your password, that added verification can make it much harder to access your email, financial, and other accounts.
Keep Software & Apps Updated
Outdated software may contain security gaps that criminals can exploit. Turn on automatic updates when possible, and keep your devices, apps, browsers, and security software current and protected.
Use Long, Unique Passwords
Use a different, hard-to-guess password for every important account. A reputable password manager can create and store long, unique passwords so you do not have to remember or reuse them.
Slow Down Urgent Requests
Stay skeptical. Scammers often use fear, excitement, or urgency to push you into acting quickly. Pause before sending money, sharing information, scanning a QR code, buying gift cards, completing unusual requests, or moving funds.
Stay Alert to the Tactics Behind Cybersecurity Threats
Most digital scams rely on the same core tactics: urgency, impersonation, emotional pressure, and requests for sensitive information or quick payment. Recognizing those patterns can help you pause, verify the authenticity of the request, and avoid acting before you know who is really contacting you.
The examples below explain common cybersecurity threats and the warning signs to watch for.
Phishing Attacks
Phishing scams use emails, texts, or websites that appear to come from a trusted source. The goal is often to get you to click a link, download an attachment, enter a password, or share personal information in order to steal information or money.
Romance Scams
Romance or friendship scams may begin on a dating app, social media, or with a “wrong number” text. The scammer builds trust over time, then asks for money, sensitive information, or help with a supposed investment opportunity.
Toll Road and Payment Scams
A text or email may claim you owe a small toll, delivery fee, ticket, or other urgent payment. The link often leads to a fake website designed to collect your card details or other personal information.
AI Impersonation Scams
Scammers can use AI-generated voices, videos, or messages to sound like someone you trust. Stop responding and contact that person directly using a phone number or other trusted communication method.
Trusted Cybersecurity Resources
For more information about current scams, fraud prevention and reporting, identity theft, and consumer cybersecurity, these resources may be helpful:
FTC Consumer Alerts – Scams & Fraud
consumer.ftc.gov — Regular updates on trending scams targeting consumers and guidance for avoiding, reporting, and recovering from fraud.
FBI Internet Crime Complaint Center (IC3)
ic3.gov — Report suspected cybercrime and review information about online fraud, phishing, account takeovers, and other threats.
Identity Theft Resource Center
idtheftcenter.org — No-cost guidance and victim assistance for people affected by identity theft, data breaches, or identity fraud.
CISA Ransomware Guide
cisa.gov/stopransomware — Federal guidance and resources for helping prevent, respond to, and recover from ransomware incidents.
Cybersecurity & Infrastructure Security Agency (CISA) – Secure Our World
cisa.gov/secure-our-world — Tips for securing devices, accounts, and networks at home.
Google Safety Center
safety.google — Tools and guidance for reviewing privacy settings, strengthening security across Google services.
Microsoft Security Tips
microsoft.com/security — Guidance for protecting Microsoft accounts and devices and recognizing phishing, malware, and online scams.
Consumer Reports – Digital Security
consumerreports.org — Consumer-focused guidance, tools, and reporting about online privacy and digital security.
Frequently Asked Questions About Cybersecurity
Cybersecurity can seem like a technical topic, but many of the most important protective steps are simple and practical. Below are some answers to common questions we hear about cybersecurity.
- What is the most important cybersecurity step for protecting financial accounts?
One of the most important cybersecurity steps is enabling multi-factor authentication on financial, email, and other sensitive accounts. Multi-factor authentication adds another layer of protection, making it harder for someone to access your account even if they have your password.
- How can I tell if an email, text, or phone call may be a scam?
A message may be a scam if it creates urgency, asks for personal information, includes an unexpected link, requests payment in an unusual way, or comes from an address or number you do not recognize. When in doubt, do not reply, click links, or give sensitive information over the phone. Instead, contact the person, company, or institution directly through a trusted phone number or website.
- What should I do if I click a suspicious link?
If you click a suspicious link, do not enter personal information, download files, or continue interacting with the page. Close the browser window immediately, run a security scan if available, update relevant passwords from a trusted device, enable multi-factor authentication where possible, and monitor your accounts. If you are concerned about malware or device exposure, contact a trusted IT professional. If account, card, or financial information may have been shared, contact the appropriate bank, credit card company, account provider, or financial institution directly through a trusted phone number or website.
- Why do scammers use urgency or emotional pressure?
Scammers use urgency and emotional pressure because they want people to act before they have time to think clearly. Messages about locked accounts, unpaid bills, family emergencies, prizes, romantic relationships, or limited-time requests should be reviewed carefully before you click, respond, share personal information, or send money.
- When should I contact Totus about a cybersecurity concern?
You should contact Totus if a cybersecurity concern may involve your financial accounts, investment information, tax documents, estate documents, or other pertinent financial details. Our team can help you think through what may need to be reviewed and coordinate with the appropriate professionals when needed.
Have a Concern About Your Financial Information?
If you believe financial information, account credentials, tax documents, or identifying information may have been exposed, act promptly. Contact the affected financial institution through a trusted number, change compromised passwords, turn on multi-factor authentication, monitor your accounts, and report the incident to the appropriate organization or agency.
Totus clients can also contact our team when a cybersecurity concern may affect their financial plan or accounts. We can help identify financial items that may need attention and coordinate with your custodian, financial institutions, or other appropriate professionals as needed.