Plain-English basics on passwords, updates and spotting scams. You don't need to be technical — just a handful of simple habits stops the overwhelming majority of trouble.
Online security sounds like a job for experts, but the reality is reassuring: almost all everyday attacks rely on a few weak points, and a few basic habits close nearly all of them. You don't need special software or technical knowledge — you need strong passwords, an extra lock on important accounts, software that's kept up to date, and a healthy suspicion of messages that try to rush you.
That's the whole of it, really. This guide covers those basics in plain English, shows you how to spot the scams that catch people out, and tells you exactly what to do if something does go wrong. No jargon, no fear — just the handful of things that actually matter.
If you do nothing else, do these four. Together they stop the overwhelming majority of real-world attacks — far more than any antivirus or clever trick. Everything below is just detail on these.
Different password for every important account, so one leak doesn't unlock the rest. A password manager makes this effortless.
A second step — usually a code on your phone — so a stolen password alone isn't enough to get in. The single biggest upgrade.
Updates patch the holes attackers use. Turn on automatic updates for your phone, computer and apps, and let them run.
Most scams work by rushing you. Treating any urgent, unexpected message with suspicion defeats nearly all of them.
You don't have to fix every account at once. Start with the three that matter most — email, banking, and your password manager — give them strong, unique passwords today, and update the rest gradually as you log in.
Two-factor on your email alone is probably the highest-value five minutes in this whole guide. Your email can reset almost every other account you own — lock it down first, and everything else gets safer behind it.
Most scams — by text, email or call — share the same handful of tells. You don't need to identify the specific trick; you just need to recognise the pattern. When a message ticks one of these boxes, slow right down.
"Act now", "account suspended", "you'll be charged". Manufactured panic is the number-one scam tactic — real organisations rarely rush you like this.
An unexpected message about a parcel, fine, refund or login. If you weren't expecting it, treat it as suspect until you've checked independently.
Links in messages can lead to fake login pages. Don't click — go to the website yourself by typing the address you know.
No genuine bank or company asks for your password, PIN or a one-time code. Anyone who does is a scammer. Full stop.
Gift cards, crypto or unusual transfers are scam favourites because they can't be reversed. A legitimate body never demands these.
Odd wording, a slightly-wrong address, a too-good offer. Trust the instinct — and check before you act, never after.
The one rule under all of these: stop and check independently. Don't use the number or link in the message — look up the organisation yourself and contact them directly. That single habit defeats almost every scam there is.
Even careful people get caught sometimes — it's nothing to be ashamed of, and acting quickly limits the damage. If you've clicked something you shouldn't have or shared a password, work through these in order.
Speed matters more than perfection. Don't freeze up trying to do everything right — change the key passwords and call the bank first. You can tidy up the rest once the urgent doors are shut.
// An hour now buys a lot of peace of mind.