I want to start with something that happened during a client engagement last year. The company had antivirus on every machine, a password policy enforced through group policy, and an IT team that genuinely cared about security. They had done the basics. By most definitions, they were “protected.”
They got breached anyway. Ransomware. Three weeks of recovery. Significant data loss.
The entry point was a phishing email that bypassed the antivirus, a reused password that showed up in a credential dump, and an employee who thought cyber attacks only happened to banks and governments. Three myths, one breach. That is what bad security assumptions actually cost.
I keep seeing the same misconceptions across organisations of all sizes, from small businesses to mid-sized enterprises. Some of these myths are harmless on their own. Combined, they create exactly the kind of gap that attackers look for. So let me go through the ones I run into most often, and explain why they are more dangerous than most people realise.
Myth 1: Antivirus Software Means You Are Protected
This one frustrates me the most, because it is so deeply embedded. People install an antivirus, see that green checkmark, and mentally file “security” under done. I get it. The marketing around antivirus products encourages exactly this thinking.
But here is the reality. Antivirus software works by matching files against a database of known malware signatures. If the malware is already in that database, great, it gets caught. But attackers know this. Modern malware is specifically designed to evade signature detection. Techniques like polymorphic code (malware that rewrites itself to look different on each infection), fileless malware (which runs entirely in memory and never touches disk), and living-off-the-land attacks (which abuse legitimate system tools like PowerShell) routinely bypass traditional antivirus.
The Colonial Pipeline attack in 2021 is the clearest example I can point to. This was a major US fuel pipeline operator. They had security tools in place. The attackers got in through a legacy VPN account with a compromised password and no MFA. The antivirus had nothing to catch because there was nothing to catch, the attacker was using a legitimate credential to walk through the front door. The pipeline was shut down for six days. Fuel shortages across the US East Coast followed.
Antivirus is still worth running. I am not saying uninstall it. What I am saying is that it is one control among many, not a finished security posture. The gap between “I have antivirus” and “I am protected” is where most breaches happen.
What actually helps alongside it: keeping software patched (unpatched vulnerabilities are how most initial access happens), enabling endpoint detection and response (EDR) tools which catch behavioural anomalies rather than just signatures, and training staff to recognise phishing because the human layer is almost always the easiest way in. No antivirus catches a person clicking a link.
Myth 2: A Strong Password Is Enough
I have had this conversation so many times. Someone tells me they use a 16-character password with uppercase, lowercase, numbers and symbols. They are proud of it. And they should be, that is a good password. But when I ask if they use it on more than one site, the answer is usually yes.
That is the problem. The strength of your password is almost irrelevant if it has been leaked.
Here is something most people do not fully appreciate: there are billions of leaked credentials sitting in publicly accessible databases right now. Have I Been Pwned, which aggregates breach data, currently holds over 14 billion records. When a site you used years ago gets breached and your email and password leak, attackers do not manually try it somewhere. They run automated credential stuffing tools that test your credentials against hundreds of sites simultaneously. If you reused that password anywhere, they will find it, usually within hours of a breach going public.
I had a client whose email account got taken over despite having what they described as a “very strong” password. We traced it back to a data breach from a fitness app they had signed up for in 2019 and completely forgotten about. Same email, same password. The attackers had the credential from a dump and just tried it on Gmail. Done.
The fix is not a stronger password. The fix is MFA and a password manager.
MFA (multi-factor authentication) means that even if an attacker has your correct password, they still cannot get in without the second factor, usually a code from an authenticator app. Authenticator apps like Google Authenticator or Authy are significantly more secure than SMS-based codes, which can be intercepted via SIM swapping. If a service only offers SMS as its MFA option, it is still better than nothing, but push for app-based or hardware key options where the service supports it.
A password manager solves the reuse problem. You get one strong master password, and the manager generates and stores unique, complex passwords for every site. You never need to remember them, you just need to protect the vault. Bitwarden is free and open source. 1Password and Dashlane are solid paid options. Pick one and actually use it, that alone puts you ahead of a large percentage of the population.
One more thing while we are here: regularly check haveibeenpwned.com with your email address. If your credentials have appeared in a known breach, rotate that password immediately and make sure you are not using it anywhere else.
Myth 3: Hackers Only Go After Big Companies
This is the myth I hear most often from small business owners and individuals, and it is the one that causes the most damage because it leads to doing nothing at all.
The reasoning sounds logical: why would a sophisticated hacker bother with my small business or my personal accounts when there are banks and corporations to attack? The answer is that most attacks are not targeted at all. They are automated, opportunistic and volume-driven.
Attackers run bots that continuously scan the internet for exposed services, unpatched software, weak credentials and misconfigured systems. They are not looking at your company name. They are looking for an open port, an outdated WordPress plugin, a reused password, a phishing victim. If your business has an internet-facing system with a known vulnerability, it will be found, usually within hours of that vulnerability becoming public.
Ransomware groups in particular have shifted heavily toward small and mid-sized businesses precisely because the defences are weaker and the targets are less likely to have incident response plans. The Kaseya VSA attack in 2021 hit over 1,500 small businesses through a single managed service provider. Most of those businesses had probably never worried about being targeted.
Individuals are no different. Your email account, your social media, your bank credentials, your phone number, all of these have value. Stolen social media accounts get used to run scams on your contacts. Stolen email accounts are used to intercept wire transfers or reset passwords on financial accounts. Stolen phone numbers get SIM swapped to bypass MFA. There is a market for all of it.
The “I am too small to be a target” mindset is exactly what makes someone an easy target. Attackers love it when people think that way.
Myth 4: HTTPS Means a Website Is Safe
The padlock icon in the browser address bar used to be a reliable signal. If a site had HTTPS, it meant something. That is no longer true, and people are still falling for phishing sites because they see the padlock and assume the site is legitimate.
HTTPS only means the connection between your browser and the server is encrypted. It says nothing about what is on the server. Phishing sites use HTTPS. Malware distribution sites use HTTPS. Fraudulent shopping sites use HTTPS. Getting a TLS certificate is free and takes about five minutes using services like Let’s Encrypt. Attackers know this and routinely set up convincing phishing pages with valid HTTPS.
I have seen phishing pages that were nearly pixel-perfect copies of real banking login pages, complete with the padlock. The only giveaway was the domain name, something like “secure-lloydsbank-login.com” instead of “lloydsbank.com.” Most people do not look closely enough at the domain.
The habit to build: before entering any credentials anywhere, look at the actual domain name in the address bar, not just whether the padlock is there. Hover over links before clicking them. If you are on a mobile device where hovering is not possible, be extra careful about links arriving via SMS or email.
Myth 5: Incognito Mode Keeps You Private
People are surprised when I bring this one up, because it feels so obvious that incognito should mean private. The name implies it.
Incognito mode (or private browsing in Firefox) stops your browser from saving your browsing history, cookies and form data locally on your device. That is it. That is the full extent of what it does. Your internet service provider still sees your traffic. Your employer’s network still logs your requests if you’re on a work connection. The websites you visit still know your IP address. Google still knows you searched for something if you use Google to search for it.
In 2024, Google settled a $5 billion lawsuit in the US where users alleged Google tracked them even when they were browsing in Chrome’s incognito mode. The settlement resulted in Google agreeing to delete billions of data records collected during incognito sessions. The case made it fairly clear that incognito did not mean what most people thought it meant.
If actual privacy is what you need, the tools are a reputable VPN (which hides your traffic from your ISP, though shifts trust to the VPN provider), the Tor browser (which routes traffic through multiple relays, significantly harder to trace), or simply being thoughtful about what you do and where. Incognito is fine for keeping your browsing off your local device history. It is not a privacy tool in any meaningful sense.
Myth 6: You Will Know If Your Device Is Infected
This is a dangerous one. The assumption is that malware announces itself, that your computer will slow down, pop up warnings, or behave obviously differently. Sometimes that happens. Often it does not.
Modern malware is designed to be quiet. Infostealers, which are among the most common malware types targeting individuals and businesses right now, silently harvest your saved browser passwords, session cookies, crypto wallet files and documents, compress them, and exfiltrate them to an attacker-controlled server. Then they delete themselves. The whole process can take under a minute. You will never know it happened until your accounts start getting accessed or your credentials show up for sale on a dark web marketplace.
Keyloggers sit in the background recording every keystroke you make, including passwords you type, messages you send and search terms you enter. Remote access trojans give attackers persistent access to your machine. They might not use it immediately; some RAT infections sit dormant for weeks before the attacker decides what to do with the access.
The practical implication here is that you cannot rely on your own perception of “my computer seems fine” as a security signal. Regular checks matter: run a reputable malware scanner periodically, monitor your accounts for unexpected activity, check haveibeenpwned.com, look at your browser’s saved extensions and make sure you recognise all of them. Malicious browser extensions are a common delivery mechanism for infostealers and people rarely check what is installed.
Where This Leaves You
None of this is meant to be overwhelming. The point is not that security is impossible. The point is that the comfortable assumptions most people carry around are the ones that get exploited.
The client I mentioned at the start fixed things after their breach. New EDR tooling, MFA across all accounts, proper security awareness training, regular patching schedules. They are in a significantly better position now than most companies their size. The breach was expensive and stressful, but it changed how seriously they took these things.
You do not need to wait for a breach to take it seriously. The changes that matter most are not complicated: use MFA everywhere, use a password manager, stop trusting the padlock alone, keep software updated, and assume your devices need active monitoring rather than passive trust.
That is not a long list. Most of it can be done in an afternoon. The hardest part is usually just letting go of the assumption that you are already covered.