
Curated macOS security and privacy guide with practical instructions for threat modeling, disk encryption, firewall configuration, secure authentication, and network hardening.
This guide is a collection of techniques for improving the security and privacy of macOS on Apple silicon Macs. It targets experienced users who want security practices commonly used by organizations, but is also suitable for novice users with an interest in privacy and security.
For organization-managed Macs, see the macOS Security Compliance Project, maintained by the U.S. National Institute of Standards and Technology.
This guide is provided "as is" - without warranties of any kind. You are solely responsible for any consequences of following it.
Apply general security best practices:
Create a threat model
Keep the system and software up to date
softwareupdate command-line utility. Neither requires an Apple Account.Encrypt sensitive data
Ensure data availability
Click carefully
The most important step to meaningfully improve security and privacy is to create a threat model: a general description of what you want to protect, who might try to access it, how they could do so, and which controls are worth usability trade-offs. This creates an understanding of potential adversaries and their motivations, which leads to stronger defenses.
Assets may include a phone, laptop, credentials, and personal information, such as browsing history.
List them in order of importance, starting with those most worth protecting.
Define whom you are defending against. Start by defining the motivation each adversary might have to attack important assets. Financial gain is a big motivator for many attackers, for example.
For each adversary, list what they can and cannot do, ranking them from least to most capable. For example, a casual thief operates opportunistically: they will likely be defeated by basic controls, such as screen lock and encrypted storage with strong passwords. A more sophisticated and determined adversary may require fully powering off a device when not in use to clear credentials from memory and stronger authentication mechanisms.
Choose the best mitigation for each threat. For example, avoid writing passwords on paper if a roommate might find them, or encrypt storage to protect its data if it is stolen.
Security should be balanced with usability: every mitigation should counter some adversarial capability to justify any inconvenience. Stop adding defenses when the remaining risks are acceptable for a situation. Revisit the model when devices, data, travel, work, or adversaries change.
The following table is a simple example threat model for personal devices, including a Mac.