Beyond Antivirus: 15 Critical Windows Settings You Need to Change for Maximum Security

This guide walks you through 15 critical changes that harden your Windows operating system with built‑in controls. You’ll use the Windows Security app, core firmware protections, and smart configuration to reduce attack surface.Expect clear steps, what to enable, and why it matters, plus advanced Group Policy options for Pro/Enterprise.

Table of contents

An expert take by Ethan Cross, HakTechs.com Lead Analyst

Can a few smart tweaks stop most common attacks and keep your data safe? That question drives this guide.

Managing protection on modern Windows can feel scattered. Controls live across the Settings app and the Windows Security dashboard, which now centralizes scans, firewall controls, and device checks.

We’ll show what to change, why it matters, and how these options defend your laptop and desktop against common threats. You will enable built‑in encryption, tighten sign‑in features like Windows Hello and Dynamic Lock, confirm firmware protections such as Secure Boot and TPM, and turn on virtualization features that protect the kernel.

Advanced readers will also see how Group Policy helps enforce rules across multiple users and systems. For deeper hardening guidance, consult this resource on hardening desktop operating systems.

Key Takeaways

  • Use built‑in defenses: enable BitLocker, Controlled Folder Access, and Defender to protect data and block malware.
  • Verify firmware: confirm Secure Boot and TPM status to raise baseline protection.
  • Harden sign‑on: enable Windows Hello and Dynamic Lock to reduce credential theft.
  • Limit exposure: tune firewall rules and app permissions to narrow network paths and data access.
  • Keep systems updated: schedule updates, run scans, and maintain storage hygiene to close vulnerabilities.

Understand Your Security Baseline with the Windows Security Dashboard

Start with visibility. The Windows Security app shows antivirus status, firewall health, and device protections in one place—your baseline. Run a scan, confirm firewall profiles, enable Tamper Protection, and check Core isolation to reduce risk before hardening further.

Before you change anything, check the Windows Security dashboard to see what’s already active. Open the Windows Security app from Start and pick Virus & threat protection to run a Quick or Full scan.

A clean, well-lit Windows Security Dashboard interface, showcasing a comprehensive overview of system protection, firewall, and network security settings. The dashboard is displayed on a wide, high-resolution computer screen with a subtle, professional-looking backdrop, such as a blurred office environment or a simple gradient. The layout is intuitive and easy to navigate, with clear, color-coded sections and detailed metrics. The overall mood is one of confidence and control, conveying the impression of a powerful, centralized security hub for the Windows operating system.

“Visibility is the first defense — know what protections are on and which are off.”

In Firewall & network protection, confirm Domain, Private, and Public profiles are enabled and review apps allowed through the firewall.

Check Where to find it Action
Virus scans Virus & threat protection Run Quick/Full scan, review history
Firewall profiles Firewall & network protection Enable all profiles, remove risky exceptions
Core isolation (HVCI) Device security Check Memory integrity, enable if compatible
Tamper Protection Virus & threat protection settings Toggle on to block unauthorized changes
  • Use dashboard notifications to set a weekly reminder.
  • Open Windows Update and apply pending updates to close known gaps.
  • If protections are disabled, run the Windows Security troubleshooter under Settings > Update & Security.

Treat this dashboard as your management console: a fast process to validate defenses after installing new software, changing drivers, or joining a new network. Also check the Account protection card for user sign-in recommendations like Windows Hello and Dynamic Lock.

Lock Down Your Data with BitLocker and Device Encryption

Full‑disk encryption keeps your stored information unreadable if hardware is lost or stolen. Enable encryption early — especially on any laptop you carry outside the office.

Full‑disk protection stops thieves from reading your data even if they bypass the sign‑in screen.

When should you choose BitLocker or Device Encryption?

Use BitLocker for full control on Pro and Enterprise editions; use Device Encryption on supported Home devices.

BitLocker gives granular options: TPM integration, recovery management, and removable drive coverage. Device Encryption is simpler and often enabled on modern laptops.

How to enable BitLocker and back up the recovery key

On Windows 11 open Settings > Privacy & Security > Device encryption or Control Panel > BitLocker Drive Encryption. Choose how to save the recovery key — USB, file, or printed copy — and store copies offline.

Encrypt removable drives

Use BitLocker To Go to set a password or require a smart card on USB sticks and portable SSDs before travel. Without the recovery key, encrypted files become unreadable.

A secure digital safe with a glowing digital lock, illuminated by a warm, soft light. The safe is placed on a glossy, reflective surface, creating a sense of depth and dimension. The background is a subtle gradient, hinting at the abstract concept of data and encryption. The overall atmosphere is one of safety, protection, and technological sophistication.

Feature Best use Where to enable
BitLocker (full‑disk) Pro/Enterprise desktops and laptops needing admin control Control Panel > BitLocker Drive Encryption
Device Encryption Home laptops with modern hardware that need simple protection Settings > Privacy & Security > Device encryption
BitLocker To Go Removable drives and portable media Control Panel > BitLocker Drive Encryption

“Back up your recovery key in at least two places; without it you can lose access to your own files.”

Risk reminder: After major hardware changes, test boot with TPM or the recovery key to ensure continued access and maintain system protection.

Stop Ransomware with Controlled Folder Access

Enable Controlled Folder Access to stop untrusted apps from encrypting or deleting your files. Add your working directories and monitor block events; allow only the apps you trust.

Preventing untrusted programs from changing your files is a simple, high-impact defense. Controlled Folder Access lives in Windows Security under Virus & threat protection > Manage ransomware protection. Toggle it on to deny write access to unknown processes.

Protect common libraries like Documents, Pictures, and Desktop. Also add custom project folders that hold contracts, photos, or other sensitive data so malware cannot tamper with them.

  • How to allow a blocked app: Open the ransomware pane and use “Allow an app through Controlled Folder Access.”
  • Monitor events: Review block logs to see which app attempted access and whether behavior is expected.
  • Backup: Keep regular, offline backups so recovery is possible even if a threat bypasses protections.

A secure digital fortress, with a sturdy metal door emblazoned with the word "ACCESS" in bold, industrial lettering. The door's surface is textured with a grid-like pattern, suggesting advanced locking mechanisms. Dramatic chiaroscuro lighting casts dramatic shadows, creating a sense of tension and importance. The background is shrouded in a hazy, atmospheric mist, emphasizing the door's central position and the gravitas of the moment. A faint glow emanates from behind the door, hinting at the protected resources within, accessible only to the worthy. The overall composition conveys a sense of power, control, and the critical importance of carefully guarded access.

Action Where Why it matters
Toggle Controlled Folder Access Windows Security > Virus & threat protection > Manage ransomware protection Blocks unauthorized write operations and limits ransomware damage
Add protected folders Ransomware protection > Protected folders Shields Documents, Pictures, Desktop, and custom project folders
Allow trusted apps Ransomware protection > Allow an app through Controlled Folder Access Prevents false positives while keeping strict control

“This control denies write operations from unknown app paths, dramatically reducing the window for damage.”

Harden Sign-Ins with Windows Hello, Account Protection, and UAC

Adopt Windows Hello for PIN, fingerprint, or face recognition to strengthen authentication while speeding up sign‑ins. Use a Microsoft account with 2FA and keep UAC prompts on to block silent elevation by unknown software.

Strengthen how people sign in so unauthorized access becomes much harder.

Set up PIN, fingerprint, or face recognition

Go to Settings > Accounts > Sign‑in options and enable Windows Hello PIN, fingerprint, or facial recognition. Biometrics bind authentication to your device and you, which lowers reliance on a reusable password that can be phished.

Use a Microsoft account with two‑factor authentication

Link a Microsoft account and turn on two‑factor authentication (2FA). This forces a second factor during sign‑in and protects accounts even if a password is compromised.

A high-security authentication system, with a futuristic and technologically advanced appearance. In the foreground, a fingerprint scanner illuminates with a soft blue glow, hinting at biometric security. The middle ground features a minimalist, metallic interface with glowing status indicators, suggesting robust account protection. In the background, a grid of abstract geometric shapes and lines, conveying the complex computational processes underlying secure sign-in. The lighting is cool and directional, casting dramatic shadows and highlighting the sleek, industrial design. The overall atmosphere is one of heightened security, precision, and technological sophistication.

Search “User Account Control” and confirm the slider is at the recommended level or above. UAC prompts block silent elevation by software and give the administrator a clear approval gate.

Create a standard user for daily work and reserve an administrator account for tasks that need elevated rights.

“Use passwordless options where practical—Hello PIN plus 2FA reduces reliance on passwords and improves protection across devices.”

Action Where Why it matters
Enable Windows Hello Settings > Accounts > Sign‑in options Faster, device‑bound authentication that resists phishing
Activate 2FA on Microsoft account account.microsoft.com > Security Adds a second factor so stolen passwords alone fail
Set UAC to recommended or higher Type “User Account Control” in Start Prevents silent admin installs and service changes
Create standard user accounts Settings > Accounts > Family & other users Limits daily exposure and preserves audit clarity

Review the Account Protection card in Windows Security regularly. Add recovery contacts, rotate passwords that remain, and avoid reusing passwords across accounts. These steps keep user access practical and much safer.

Automatically Lock Your Session with Dynamic Lock

Dynamic Lock uses your phone’s Bluetooth to auto‑lock your computer when you step away. It’s simple and effective. Pair once, enable the option, and your laptop or desktop locks itself after you leave your desk.

A short walk away should not leave your files exposed — Dynamic Lock handles that automatically. Pair your phone in Settings > Bluetooth & devices > Add device and confirm a stable connection.

Then open Settings > Accounts > Sign‑in options and check “Allow Windows to automatically lock your device when you’re away” to turn it on. Expect a brief delay (about 30 seconds) after the paired device moves out of range before the screen locks.

A high-tech dynamic lock device, sleekly designed with brushed metal casing and illuminated digital display. The lock mechanism is precisely engineered, featuring advanced biometric sensors and adaptive locking algorithms. Dramatic studio lighting casts dramatic shadows, emphasizing the device's angular, futuristic aesthetic. The lock is positioned prominently, conveying a sense of robust security and sophisticated technology safeguarding the user's digital assets. The overall mood is one of high-tech reliability and cutting-edge protective measures, perfectly suited to illustrate the "Automatically Lock Your Session with Dynamic Lock" section of the security article.

  • Verify pairing stability before relying on Dynamic Lock.
  • Combine with short screen‑timeout values so manual locks aren’t your only defense.
  • Keep Bluetooth drivers current; unpair and repair if behavior is inconsistent.
  • On shared machines, remind each user to pair their own phone so individual sessions lock correctly.

Practical tip: Test by walking away with your phone. If it fails, reboot the Bluetooth stack and try the pairing again. For community tips and troubleshooting see this locking guide.

“Dynamic Lock is a low-effort guard that closes a common physical access gap.”

Use this feature on an office laptop or any computer in shared spaces to improve physical security while keeping work convenient.

Secure Boot, TPM, VBS, and HVCI: Strengthen Startup and Kernel Protection

Secure Boot, TPM, VBS, and HVCI work together to stop low‑level tampering before the operating system loads and while the kernel runs. Confirm these protections now; Windows 11 raises the baseline, but you should verify they’re actually on.

Startup and kernel defenses are the foundation of a trustworthy device.

A secure and fortified Windows computer, with a glowing holographic display showcasing the secure boot process. In the foreground, a detailed 3D render of the Trusted Platform Module (TPM) chip, radiating with energy. In the middle ground, a shimmering virtual Virtualization-Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI) interface, projecting an impenetrable barrier around the system's core. The background features a sleek, high-tech environment, with lines of code cascading across the walls, conveying the advanced security measures at work. Dramatic lighting and cinematic camera angles emphasize the importance and power of these essential Windows safeguards.

Enable UEFI Secure Boot in your firmware (UEFI/BIOS) so only signed bootloaders initialize the system. Reboot, press the firmware key (F2/Del or OEM specific), and toggle Secure Boot on.

Turn on TPM (PTT or fTPM)

TPM (Trusted Platform Module) stores encryption keys and attests to firmware integrity. On Intel this may be labeled PTT; on AMD it appears as fTPM. Enable it in firmware, then confirm it under Device security in Windows Security.

Enable VBS and HVCI in Windows

Virtualization‑Based Security (VBS) isolates sensitive processes in protected memory. Hypervisor‑Protected Code Integrity (HVCI) validates kernel code and blocks unsigned drivers. Open Windows Security > Device security > Core isolation and toggle Memory integrity.

  • Note: HVCI can impact older CPUs—test critical apps, but prioritize protection on laptops and frontline devices.
  • Tip: Pair these startup controls with disk encryption so data at rest and the boot path are both defended.
  • After hardware changes: re‑check Secure Boot and TPM; firmware updates can reset defaults.

“These security features harden early execution paths and reduce the window for stealthy, persistent attacks.”

Configure Windows Defender Firewall and Advanced Rules

Keep the firewall enabled across Domain, Private, and Public profiles, and prune unnecessary app exceptions. Use Advanced Security to create precise inbound/outbound rules that restrict risky application traffic and ports.

A good start is Windows Security > Firewall & network protection. Confirm each profile reads “On” and open Allow an app through firewall to remove stale or unknown entries.

A detailed illustration of a Windows Defender Firewall interface, showcasing its advanced rules and configuration options. In the foreground, a sleek, modern firewall dashboard with various toggles, settings, and network visualization elements. In the middle ground, a series of customizable firewall rules, each represented by an intuitive card-like interface. The background depicts a subtly blurred network topology, suggesting the broader context of the firewall's role in securing the system. The image should convey a sense of professionalism, functionality, and technical depth, suitable for an article on critical Windows security settings.

When you need precision, launch Windows Defender Firewall with Advanced Security. Create rules by executable, port, or protocol to block or permit traffic only as required.

  • Block outbound apps that should not phone home.
  • Restrict inbound ports on servers to the exact port numbers the service needs.
  • Document each rule with the app name, port, and business justification to aid audits.

Test new rules on a non‑production device first. If you use Delivery Optimization, consider Simple (HTTP only) mode to limit peer sharing across the network.

Practical rule: avoid broad “Any/Any” allows — narrow rules reduce exposure and make incidents easier to trace.

For management at scale, combine firewall rules with Group Policy and consult this guide to firewall setup and management for deeper process tips: effective firewall strategies.

Privacy First: Windows Privacy Settings and App Permissions

Review and reduce telemetry and web exposure, and grant app access only when necessary. Keep Find my device enabled only if you accept the location tradeoff.

Your device can spill data quietly; tighten what apps can access and what Windows reports back to Microsoft.

Turn off extra diagnostic data. Go to Settings > Privacy & Security > Diagnostics & feedback and disable optional diagnostics. In business environments, set the Group Policy Administrative Templates > System > Allow Diagnostic Data to Diagnostic data off to enforce stricter control.

Remove web results from search. Use Group Policy: Computer Configuration > Administrative Templates > Windows Components > Search > “Don’t search the web or display web results in search” (Enable). This keeps queries local and reduces unexpected exposure.

Manage app permissions. Open Settings > Privacy & Security > App permissions and revoke camera, microphone, location, contacts and other rights for apps that don’t need them. Limit background apps under General to reduce tracking and resource use.

Use Find my device only if you accept enabling Location services. For a practical overview of privacy choices and tradeoffs, see this privacy guide.

“Grant permissions deliberately — opt in per app and revisit after installs.”

Family Options and Standard Accounts: Limit Risk for Shared PCs

Separate admin and daily use. Standard accounts and Family Options reduce mistakes and malware impact on shared PCs. Apply screen time, content filters, and activity reports so users have the right access without excessive permissions.

Shared computers pose unique risks; a clear user plan reduces mistakes and exposure.

Set screen time, content filters, and activity monitoring

Open Windows Security or Settings > Accounts > Family & other users to add family members and set limits. Use activity reports to see app and web use and adjust age‑appropriate filters.

Create standard (non‑administrator) accounts for everyday use

Create a standard user for daily tasks so installers and system changes require admin approval via UAC. Keep the administrator credentials secure and with IT if this is a shared office computer.

  • Review apps in child profiles and remove unnecessary ones.
  • Document who has admin access and why to aid management and audits.
  • Combine Family Options with Group Policy when you need to block the Store or restrict app execution.

“Least privilege limits damage: daily users should not run as admins.”

15 critical windows settings for maximum security: Updates, Scans, and Storage Hygiene

Keep updates automatic, scan regularly, and clean residual data. These maintenance steps close gaps attackers rely on.

Schedule time for restarts and full scans so protections stay current without disrupting your work.

A predictable maintenance habit closes the gaps attackers probe first. Treat patching, deep scans, and storage cleanup as a simple, repeatable process that protects device and data.

Set Windows Update to automatic and schedule manual reboots

In Settings > Windows Update, leave automatic updates on and pick a weekly restart window. Driver updates often fix vulnerabilities, so check updates if you delay restarts.

Run full malware scans periodically and review threat history

Open Windows Security > Virus & threat protection and run a Full scan monthly. Real‑time defense stops most threats, but deep scans find dormant malware and odd files.

After scans, review the threat history and confirm detections are quarantined or removed.

Use Storage Sense for automatic cleanup to reduce residual data exposure

Enable Storage Sense in Settings > System > Storage to clear temp files and empty the recycle bin on a schedule. Less leftover data reduces leakage and speeds forensic checks after incidents.

  • If you run third‑party protection, keep that software updated and avoid running multiple engines that conflict.
  • Verify BitLocker or Device Encryption remains active after large updates and reconfirm your recovery key copies.
  • Check the firewall after major patches so app allowances haven’t changed, and advise remote workers to scan on trusted networks before travel.

“Routine maintenance is the simplest way to keep threats from taking root.”

Advanced Hardening with Group Policy (Pro/Enterprise)

Group Policy lets you enforce security settings across systems—no drift, fewer blind spots. Start with telemetry and identity hardening, then lock down apps, storage, and legacy protocols to reduce attack surface.

Use the Local Group Policy Editor (gpedit.msc) or Group Policy Management in Active Directory to apply these controls centrally. Document the target OUs and change window so updates are traceable and revertible.

Block telemetry, web results, and application telemetry

Set Computer Configuration → Administrative Templates → Windows Components → Search → “Don’t search the web or display web results in search” to Enabled. Then under Data Collection set Allow Diagnostic Data to Enabled and choose Diagnostic Data off via AD templates.

Enable Turn off Application Telemetry and Turn off Inventory Collector (Application Compatibility) to reduce unintended data flows.

Enforce password rules and audit logon events

Configure Computer Configuration → Windows Settings → Security Settings → Account Policies → Password Policy to enforce complexity, set minimum and maximum password age, and apply lockout thresholds.

Enable Advanced Audit Policy for Logon/Logoff success under Security Settings → Advanced Audit Policy Configuration → Logon/Logoff to increase visibility into user authentication activity.

Harden administrator accounts and legacy authentication

Rename the default Administrator, disable the built‑in Administrator and Guest accounts, and set Security Options → Do not store LAN Manager hash. Set LAN Manager authentication level to Send NTLMv2 response only. Refuse LM & NTLM and disable anonymous SID/name translation.

Lock down apps, store, and removable media

Use Turn off Windows Installer, Disable all apps from Microsoft Store, and enable Run only specified Windows applications or Don’t run specified Windows applications to block CMD and Regedit for standard users.

Set All Removable Storage classes: Deny all access to prevent data exfiltration and malware spread from USB devices.

Policy area GPO path (example) Recommended state
Search / Web results Computer → Admin Templates → Windows Components → Search Don’t search the web — Enabled
Diagnostic data Computer → Admin Templates → Windows Components → Data Collection Allow Diagnostic Data — Diagnostic Data off
Authentication Computer → Security Settings → Local Policies → Security Options LAN Manager auth level — NTLMv2 only; disable LM/NTLM
App control Computer → Admin Templates → System Disable Store & Windows Installer; block CMD/Regedit for users
Removable media Computer → Admin Templates → System → Removable Storage Access Deny all access — Enabled

“Audit and enforce: policy is effective only when monitored. Combine GPOs with logging and network controls to prevent drift.”

  • Management tip: Test changes on a pilot OU; then roll out with clear rollback steps.
  • Network note: Pair these policies with firewall rules and NTLM restrictions to reduce lateral risk across the network.

Conclusion

Focus on the essentials: verify boot protections, encrypt drives, harden sign‑ins, limit app and network exposure, and keep maintenance on schedule.

Use Group Policy where possible to lock in secure defaults and prevent drift across every computer and laptop you manage.

Treat the Windows Security dashboard as your first stop to confirm protections are enabled and healthy on each device. Keep BitLocker active and store the recovery key offline.

Use Windows Hello with 2FA, keep UAC at the recommended level, and use a standard account for daily work. Keep the firewall enabled, trim exceptions, and review privacy options and diagnostic choices.

Schedule updates, full scans, and Storage Sense cleanup. Translate this guidance into Group Policy baselines for fleets. Security is a practice—revisit configs after updates or hardware changes so protections remain enabled by default.

FAQ

What should I check first in the Windows Security dashboard?

Start by running a full virus and threat scan, then review Firewall & network protection and Device security. Make sure Tamper Protection is on and check Core isolation (Memory integrity) to reduce kernel-level attacks.

When should I choose BitLocker over Device Encryption?

Use BitLocker on Pro and Enterprise editions or when you need advanced key management, network unlock, or group policy control. Device Encryption is suitable for many modern consumer devices when BitLocker isn’t available, but it offers fewer administrative options.

How do I enable BitLocker and back up the recovery key safely?

Turn on BitLocker from Control Panel or Settings > Device encryption/BitLocker. Save the recovery key to your Microsoft account, an external USB, or an enterprise key escrow (like AD or Azure AD). Store at least one offline copy in a secure location.

Can I encrypt removable drives and should I?

Yes. Use BitLocker To Go to encrypt USB drives and SD cards. Always encrypt removable media that hold sensitive files to prevent data loss if the device is lost or stolen.

How does Controlled Folder Access stop ransomware?

Controlled Folder Access blocks unauthorized apps from modifying protected folders (Documents, Pictures, Desktop, and custom folders). Add trusted apps manually and keep the allowed app list tight to reduce ransomware and unauthorized tampering.

What’s the best way to harden sign-ins on Windows?

Enable Windows Hello (PIN, fingerprint, or facial recognition) for faster, phishing-resistant sign-ins. Use a Microsoft account or Azure AD with two-factor authentication (2FA). Keep User Account Control (UAC) at recommended or higher to require elevation for admin tasks.

How does Dynamic Lock improve session security?

Dynamic Lock pairs your PC with a Bluetooth device (like a phone). When the paired device moves out of range, Windows can automatically lock the session to prevent unauthorized access when you step away.

What startup protections should I verify (Secure Boot, TPM, VBS, HVCI)?

Enable UEFI Secure Boot and confirm the Trusted Platform Module (TPM) is active. Turn on Virtualization‑Based Security (VBS) and Hypervisor‑Protected Code Integrity (HVCI) to isolate and protect critical processes and the kernel from advanced attacks.

How do I configure Windows Defender Firewall correctly?

Ensure the firewall is enabled for Domain, Private, and Public profiles. Review allowed apps and remove unnecessary exceptions. Create targeted inbound/outbound rules for high‑risk apps, restrict ports, and log blocked connections for auditing.

Which privacy settings should I change to limit data collection?

Disable unnecessary diagnostics and app background activity, turn off web results in Windows search, and review diagnostic levels. Control app permissions for camera, microphone, location, and sensors—grant only what each app truly needs.

Should I enable Find my device and how to manage location privacy?

Enable Find my device on laptops you don’t want to lose, but audit which accounts can see location data. Use location settings to restrict apps from continuous tracking and clear location history periodically.

How do Family Options and standard accounts reduce risk on shared PCs?

Use Family Options to set screen time, content filters, and activity reporting for children. Create standard (non‑administrator) accounts for daily tasks to limit accidental system changes and reduce malware impact.

How should I handle Windows Update, scans, and storage hygiene?

Set Windows Update to automatic and schedule active hours to avoid unexpected reboots. Run full malware scans regularly and review threat history. Enable Storage Sense to remove temporary files and reduce leftover data exposure.

What Group Policy controls help harden systems in Pro/Enterprise?

Use Group Policy to block unwanted telemetry and web search results, enforce password complexity and rotation, disable unused accounts (Guest/hidden Administrator), and require NTLMv2 only. Control app execution policies, restrict Microsoft Store access, and block removable storage if needed.

How often should I review and test these protections?

Review security settings monthly, run scheduled scans weekly, and test recovery keys and backups quarterly. After major updates or new software installs, re-check firewall rules, app permissions, and endpoint protections to ensure nothing was weakened.

Ethan Cross

Ethan Cross is a cybersecurity analyst and tech journalist with over a decade of experience in ethical hacking, malware analysis, and digital forensics. At HakTechs.com, he delivers in-depth reports, security tips, and expert analysis to help readers stay ahead of emerging cyber threats.