If you’ve spent any time in cyber security, you’ll know that old advice sticks around long after the risks have changed. Some of these tips spread quickly, sound convincing, and get recycled in organisations year after year… even when they are no longer helpful.
According to the Stop Hacklore website, hacklore is a blend of hacking and folklore, which spreads quickly and confidently, passed from person to person as if it were hard-earned wisdom. But like most folklore, it isn’t grounded in reality, no matter how plausible it sounds. Their goal is to help everyday people and organisations focus on the simple, fact-based steps that truly protect their data and devices
In this blog, we’re highlighting common pieces of outdated cyber security advice and replacing each one with simple, practical guidance that actually strengthens security.
Photo by Caio
Avoid public Wifi at all costs
Team members often worry about using Wifi outside the workplace, especially during travel or hybrid working. Older advice painted public Wifi as a serious threat, but modern devices encrypt traffic and browsers flag unsafe sites. For more staff, this isn’t a top organisational risk.
What matters more for businesses:
Company devices kept up to date
MFA on business accounts
Strong, unique passwords
Corporate VPN to log into sensitive systems on shared or unmanaged devices.
These steps protect organisational data far better than avoiding coffee shop Wifi.
Staff should change their passwords every month
Frequent forced password changes can often backfire. People create predictable patterns (adding a 1 or increasing a number at the end of a password by 1), store passwords in insecure places, or share workarounds.
What’s better for organisations are:
Complex, random passwords
Encourage using password managers (or deploy one centrally)
Turn on MFA for all key systems
Only require a password change if there’s evidence of compromise
This reduces the risk and reduces admin load.
Everyone should use a VPN, all the time
Some organisations still expect VPN use for almost everything, even when systems have moved to cloud services with built-in secure connections. A VPN has its place, especially for legacy systems, but it isn’t a universal safety net.
More valuable organisational controls include:
Up to date devices
MFA across all accounts
Role-based access
Monitoring for unusual logins
These reduce far more incidents than blanket VPN use.
Antivirus is enough
Modern attacks don’t just target devices, they target people and access. Phishing, credential reuse and unpatched software cause far more organisational incidents than traditional malware.
Stronger organisational approaches are:
Endpoint protection and regular updates
Staff awareness of suspicious emails
MFA
Backups and tested recovery plans
Clear reporting routes for anything unusual
Security is layered, no single product is enough.
Staff should never click links in emails
Telling people ‘never click links’ isn’t realistic and often leads to confusion. Staff need to use links, they just need to know how to check them safely.
Better guidance for team members:
Check the sender
Hover to preview links
Treat unexpected or urgent messages with caution
When unsure, go directly to the system rather than the emailed link
Report suspicious emails so IT can investigate
This empowers staff instead of scaring them.
We’re too small to be targeted
Many small and medium organisations assume attackers won’t notice them. But most attacks are automated, they scan the internet continuously for any organisations with weak controls.
What organisations can do:
Keep systems patched
Enforce MFA
Back up data securely
Ensure team members know who to call in an incident
Use basic cyber hygiene as standard, not a ‘nice to have’
For more information on Hacklore’s, visit the Stop Hacklore website to replace fear with facts to make digital safety advice more accurate, actionable, and effective for everyone.
Former Arnold Clark CEO Eddie Hawthorne shares experience of major cyberattack at Scottish Parliament event The Cyber and Fraud Centre – Scotland has called for…
Cyber and Fraud Centre – Scotland has partnered with Stellar Elevate, the digital awareness and education division of Stellar Omada to offer organisations in Scotland…
Artificial intelligence is making it easier to create convincing emails, images, audio and video; and cyber criminals are taking notice. During our latest Cyber Byte,…