I do all the usual things; I use a password manager, enable 2FA on critical accounts, never give my passwords or passcodes to anyone, even those I trust.
However I constantly stumble on the same question: if a hacker found a crack in my defenses, to what extent could they wreck my life? Today I nearly fell victim to a spearphishing attempt. I hung up before any damage was done, but the experience shook me up.
I've been considering hiring a white-hat hacker to essentially do a dry-run of what a malicious actor would do to me if I were their target. How far could they get? How much of my personal information could they glean? What accounts could they access by abusing that information?
My question is twofold: * Is this a good idea? Or is putting my security in the hands of a third-party equally dangerous? * If hiring someone is ill-advised, are there guides for securing myself to a point where I am safe from the majority of attacks?