Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Protect infrastructure used to build or run AI by securing identities, keeping software current, controlling access to data and applications, and making security an owned part of development and operations. These nine blunders are a practical framework—not an official ranking or a list published by CISA.
1. Leaving important accounts protected by passwords alone
A stolen password can expose email, remote access, administrative consoles, or sensitive data. Require multifactor authentication (MFA) wherever it is available, starting with administrator accounts, remote access, email, and systems that hold sensitive information.
For higher-risk access, favor phishing-resistant MFA where your identity provider and devices support it. CISA’s communications infrastructure guidance gives FIDO authentication as an example. A compatible hardware security key can be one way to use FIDO, but check account recovery procedures and organizational policy before adopting keys. A key does not secure an account if other access paths remain weak.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors- Inventory accounts and identify which can change configurations, grant access, or reach sensitive data.
- Enforce MFA for those accounts and review exceptions rather than letting them become permanent.
- Test sign-in recovery and emergency access without weakening the normal MFA requirement.
2. Reusing weak passwords
MFA adds a second barrier, but it does not make weak or reused passwords a good choice. If a password is reused and exposed through another service, an attacker may try it against business accounts as well.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
CISA’s Secure Our World guidance recommends strong, unique passwords and password managers. Use a managed password manager to generate and store a distinct password for each account, and protect the manager itself with MFA. Prioritize replacing reused credentials on email, administrator, cloud, and recovery accounts.
3. Treating phishing as only a user-awareness problem
People should know how to recognize and report suspicious messages, but training alone cannot carry the defense. Phishing can exploit convincing requests, compromised accounts, or hurried workflows; organizational controls should limit what a successful lure can achieve.
CISA’s Secure Our World guidance emphasizes phishing awareness. Its September 2024 tip sheet, “Stay Safe Online When Using AI,” applies the same core behaviors—strong unique passwords, MFA, software updates, and phishing awareness—to generative AI use. For infrastructure teams, pair awareness with MFA, clear reporting routes, and access controls that restrict accounts to the resources and actions their owners need.
- Give staff a straightforward way to report suspicious messages or unexpected login prompts.
- Make sure responders know how to assess a report and contain a compromised account.
- Review privileges so a compromised everyday account cannot automatically administer critical systems.
4. Delaying software and vulnerability updates
Outdated software can leave known weaknesses available to attackers. Keep operating systems, applications, dependencies, and infrastructure components on a defined update process, with an owner responsible for tracking what is deployed and what needs attention.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
CISA identifies software updates as a foundational protective behavior. In an update announced on January 17, 2025, CISA and the FBI clarified their Product Security Bad Practices guidance on patching Known Exploited Vulnerabilities. That guidance is a reason to take actively exploited flaws seriously, not a universal patch deadline: set urgency according to exposure, exploit status, and the risk and feasibility of applying the fix.
- Maintain an inventory of software and services, including components used to build and operate AI systems.
- Track vendor security updates and known exploited vulnerabilities relevant to that inventory.
- Prioritize fixes for exposed or critical systems, test changes where needed, and verify that updates were applied.
- Record systems that cannot be patched promptly and apply compensating safeguards while a fix is pending.
5. Leaving cloud and business application settings unchecked
Default or poorly reviewed settings can expose data, accounts, and administrative functions. Treat each cloud service and business application as part of your infrastructure, including AI-related services that connect to organizational accounts or information.
Review who can sign in, what each role can do, which data is shared, and whether externally accessible features are actually required. CISA’s small-business resource hub points organizations to Secure Cloud Business Applications resources for assessment and hardening. These resources can inform a review; using a checklist or tool does not guarantee that an environment is secure.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Remove access that is no longer needed and review privileged roles regularly.
- Check sharing, public-access, and integration settings against the organization’s intended use.
- Document approved exceptions and assign someone to revisit them.
6. Failing to preserve recoverable data
A backup is useful only if the organization can restore the data and systems it needs. Identify what must be recovered to resume essential work, then choose a backup and retention approach that fits those recovery needs. CISA’s business resources identify data backups as a security practice, but do not prescribe one schedule or retention period for every organization.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Include important data and configurations in the recovery plan, and test restoration rather than assuming that a successful backup job proves recovery will work. Decide who can access or change backup copies, and protect that access so an incident affecting production systems does not automatically compromise recovery data too.
7. Collecting too little security telemetry
Without useful records, it can be difficult to investigate suspicious access or understand what happened during an incident. CISA’s business resources point to logging and threat-detection guidance. Logging supports detection and investigation; it does not prevent every intrusion.
Decide which events matter for your environment, such as sign-ins, privilege changes, configuration changes, and access to important systems or data. Ensure someone can review relevant alerts and investigate them. Set access and retention practices for logs, since they may contain sensitive operational details. For AI systems, consider what activity needs to be visible to understand access and changes without assuming that every deployment has the same logging needs.
8. Neglecting encryption and data handling
Encryption is one part of protecting business data, not a substitute for deciding what data should be collected, who should access it, or how it may be used. CISA lists encryption of business data among its security practices. Apply protections appropriate to the data and system context, including where information is stored and how it is transmitted.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
For AI-enabled services, establish what information may be submitted or connected, who is permitted to use it, and what safeguards apply to that information. Review service settings and organizational policies before enabling data flows. Avoid assuming that a single encryption setting resolves risks created by excessive access or unsuitable data handling.
9. Building or buying AI-enabled technology without security ownership
AI does not remove the need for ordinary security controls, and a generic AI checklist cannot replace understanding a particular system. Assign responsibility for security outcomes across development, procurement, deployment, and ongoing operation. Define who approves changes, handles vulnerabilities, reviews access, and responds to incidents.
CISA and the UK National Cyber Security Centre announced their joint Guidelines for Secure AI System Development on November 26, 2023. The guidance emphasizes secure-by-design principles and ownership of security outcomes. CISA and partner agencies describe secure-by-design products as built to reasonably protect devices, data, and connected infrastructure; their guidance also supports threat modeling and defense in depth.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Use those principles to ask system-specific questions before deployment: what assets and data are involved, who can access or change them, where the system depends on other components, and what could go wrong if an account or component is compromised? Then choose safeguards based on the answers, and revisit them when the system, its integrations, or its use changes. A purchased product still needs an accountable owner and configuration appropriate to the organization.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

