Skip to content

The Critical Top Five

Intro

The Critical Top-Five Security Checklist items listed here are the minimal expectations for everyone volunteering with DA – particularly if you are handling any voter or membership-related data. We recommend these to everyone we know (they are referenced again in some of the other checklists). We then encourage you to also review each of the other topical checklists to improve your awareness of good security practice.

Top-Five Critical Security Checklist Items

Most Critical Activities

  • Use Strong Passwords
    Priority: Critical
    If your password is too short, then it can be easily cracked through brute force or guessed by someone. Use a long, strong and unique password for each of your accounts – a Password Manager (see below) will help you create strong passwords. Length matters more than complexity – use 12+ characters, with Mix of uppercase and lowercase letters, at least one number, and at least one special character (-,#,!,&,%,*,~,§, etc.) (For example, "Marathon28-Harmful55-89Shorts", is an easy-to-read strong passphrase, "mypass" is not!)

  • Use a Secure Password Manager
    Priority: Critical
    Use a secure password manager to encrypt, store, and fill your authentication credentials, such as BitWarden, 1Password, or KeePass / KeePassXC. It is impossible to remember hundreds of strong and unique passwords. A password manager generates, stores, and auto-fills your login credentials for you. All your passwords are encrypted against a master password (which you must remember, and it should be very strong). Most password managers have browser extensions and mobile apps, so your passwords can be auto-filled on any of your devices. (DNC Jan 2026)

  • Enable Multi-Factor Authentication (2FA/MFA)
    Priority: Critical
    2FA or MFA (Two or Multi-Factor-Authentication) is where you must provide both something you know (a password) and something you have (such as a code on your phone) to log in. (MFA can also include “something you are”, like a fingerprint as biometric data.) This means that if someone has obtained your password (e.g.,through phishing, malware, or a data breach), they still cannot log into your account. Download an authenticator app like Bitwarden Authenticator or Google Authenticator Android iOS onto your phone, and then go to your account security settings and follow the steps to enable 2FA (typically this includes scanning a QR code and confirming with a 6-digit code). When you next log in, you will be prompted for the 6-digit code that is displayed in the app on your phone. It works without an internet connection and the code usually changes every 30 seconds. If possible, use an authenticator app rather than e-mail or SMS for 2FA/MFA (DNC Jan 2026).

  • Beware of Phishing/Social Engineering Attacks
    Priority: Critical
    Be skeptical of unsolicited requests for information, even if they appear to come from a trusted source, such as your bank, a friend, or a family member.
    Phishing is a type of cyber attack or scam where attackers trick individuals into revealing sensitive information, such as passwords or credit card details, by masquerading as a trustworthy entity in electronic communications. It works like "fishing," using bait to lure targets into clicking harmful links or providing confidential data. Phishing attacks often use social engineering to seem like a legitimate request.
    Beware of phone calls or messages that offer or ask for money, that say you need to fix problems with your computer when you haven't asked for it, that claim your account will be closed if you don't respond, that claim that they have "embarassing" personal information that they will expose, or that pretend to be from a relative/child/grandchild/friend in need of emergency money.

  • Verify Senders and Recipients
    Priority: Critical
    E-mails can be easily spoofed and e-mail scams are common and clever. Verify that the sender is who they say they are: Check that the e-mail address is one you are already familiar with, and use a secondary channel to confirm if something seems changed or odd (i.e. call your friend to confirm if they intended to send the message).
    If an e-mail raises suspicions, and you are not sure if it is legitimate, do not reply, forward, click on the links, scan QR codes, open attachments, or send any sensitive information.
    Always check the URL address to confirm your destination and even type a URL manually rather than clicking on suspicious links in emails. Do not respond to emails promising money, checking on the delivery of a package you didn't order, threatening you if you don't send them bitcoin, insisting that you must "act now", or saying you need to verify an account.