Field guide · No. 25 · Security

Staying safe onlinewithout the jargon

Plain-English basics on passwords, updates and spotting scams. You don't need to be technical — just a handful of simple habits stops the overwhelming majority of trouble.

Skill neededNone
SetupAn hour, once
Protects againstMost attacks
Golden ruleSlow down

Online security sounds like a job for experts, but the reality is reassuring: almost all everyday attacks rely on a few weak points, and a few basic habits close nearly all of them. You don't need special software or technical knowledge — you need strong passwords, an extra lock on important accounts, software that's kept up to date, and a healthy suspicion of messages that try to rush you.

That's the whole of it, really. This guide covers those basics in plain English, shows you how to spot the scams that catch people out, and tells you exactly what to do if something does go wrong. No jargon, no fear — just the handful of things that actually matter.

The four habits that do the heavy lifting

Master these and you're most of the way there

If you do nothing else, do these four. Together they stop the overwhelming majority of real-world attacks — far more than any antivirus or clever trick. Everything below is just detail on these.

Habit 01

Strong, unique passwords

Different password for every important account, so one leak doesn't unlock the rest. A password manager makes this effortless.

Habit 02

Two-factor on key accounts

A second step — usually a code on your phone — so a stolen password alone isn't enough to get in. The single biggest upgrade.

Habit 03

Keep things updated

Updates patch the holes attackers use. Turn on automatic updates for your phone, computer and apps, and let them run.

Habit 04

Slow down on messages

Most scams work by rushing you. Treating any urgent, unexpected message with suspicion defeats nearly all of them.

01
The foundation

Passwords, made painless

The biggest password risk isn't a weak one — it's the same one reused everywhere. When one site is breached (and sites are breached constantly), reused passwords hand attackers the keys to all your other accounts. Here's how to fix that for good.
Use a password managerIt creates and remembers a strong, different password for every site, so you only remember one master password. The single best move you can make.
Longer beats complicatedA long passphrase of a few random words is both stronger and easier to remember than a short jumble of symbols. Length is what matters most.
Never reuse important onesEspecially your email and banking. Your email is the master key — it can reset every other account — so it gets its own strong, unique password.
Protect the manager itselfGive the password manager a strong master password and turn on two-factor for it. One lock to guard all the others.
The trick

You don't have to fix every account at once. Start with the three that matter most — email, banking, and your password manager — give them strong, unique passwords today, and update the rest gradually as you log in.

02
The extra lock & the patches

Two-factor & updates

Two simple settings that quietly do an enormous amount of work. Two-factor means a stolen password isn't enough on its own; updates close the security holes attackers depend on. Both are largely "turn on and forget".
Turn on two-factor for key accountsEmail, banking and main social accounts first. It adds a second step — usually a code from your phone — that a thief can't supply with just your password.
Prefer an app or key over SMSAn authenticator app (or a physical security key) is safer than codes by text. But SMS two-factor is still far better than none — start there if it's easier.
Switch on automatic updatesPhone, computer, browser and apps. Updates fix newly found security holes — running old software is the most common way devices get compromised.
Don't ignore the restart promptMany updates only finish when you restart. Putting it off for weeks leaves the hole open — let the device restart when it asks.
The honest take

Two-factor on your email alone is probably the highest-value five minutes in this whole guide. Your email can reset almost every other account you own — lock it down first, and everything else gets safer behind it.

Spotting a scam

The warning signs, in plain sight

Most scams — by text, email or call — share the same handful of tells. You don't need to identify the specific trick; you just need to recognise the pattern. When a message ticks one of these boxes, slow right down.

!It's urgent

"Act now", "account suspended", "you'll be charged". Manufactured panic is the number-one scam tactic — real organisations rarely rush you like this.

!It came out of nowhere

An unexpected message about a parcel, fine, refund or login. If you weren't expecting it, treat it as suspect until you've checked independently.

!It wants you to click a link

Links in messages can lead to fake login pages. Don't click — go to the website yourself by typing the address you know.

!It asks for a code or password

No genuine bank or company asks for your password, PIN or a one-time code. Anyone who does is a scammer. Full stop.

!The payment method is odd

Gift cards, crypto or unusual transfers are scam favourites because they can't be reversed. A legitimate body never demands these.

!Something just feels off

Odd wording, a slightly-wrong address, a too-good offer. Trust the instinct — and check before you act, never after.

The one rule under all of these: stop and check independently. Don't use the number or link in the message — look up the organisation yourself and contact them directly. That single habit defeats almost every scam there is.

If something goes wrong

Act fast, in this order

Even careful people get caught sometimes — it's nothing to be ashamed of, and acting quickly limits the damage. If you've clicked something you shouldn't have or shared a password, work through these in order.

1
Change the password immediatelyFor the affected account, and anywhere you reused that same password. Do email and banking first.
2
Turn on two-factor if it isn't alreadyThis stops an attacker getting back in even if they have the old password.
3
Contact the bank if money's involvedCall the number on your card. Banks have 24-hour fraud lines and can freeze cards and reverse some transactions if you're quick.
4
Watch for follow-on activityCheck statements and account logins over the following weeks. One breach often leads to further attempts.
5
Report itReporting helps stop others being caught. In Australia, report scams to Scamwatch; identity theft support is available through IDCARE.
The trick

Speed matters more than perfection. Don't freeze up trying to do everything right — change the key passwords and call the bank first. You can tidy up the rest once the urgent doors are shut.

Your security basics

// An hour now buys a lot of peace of mind.