Click on Digital Security Centre button for enhanced, easy-to-follow security guides for your accounts, banking, privacy and devices.
What you will learn
This page explains the ideas behind online safety: what the protections mean, why they matter and where their limits lie. For practical instructions, visit the Digital Security Centre and its step-by-step guides.
👣
UnderstandWhat a digital footprint is and where it comes from.
🔎
RecogniseScams, unsafe links, fake messages and risky sharing.
🛡️
ProtectPasswords, devices, accounts, money and personal data.
🚨
RespondAct quickly and calmly if something goes wrong.
Remember: Your online activity tells a story about you. You can make that story safer and more positive by making small, regular choices.
🛡️ Secure your essentials first
Highest priority
You do not need advanced technical skills. Start with the accounts that can unlock other accounts, hold your money, prove your identity or receive security codes.
Start with these five: your main email, government-service logins, banking apps and websites, your password manager, and your mobile phone. If a criminal controls one of these, they may be able to reset other accounts.
1EmailUsed for password resets.
→
2PhoneReceives security checks.
→
3BankingProtect money and alerts.
→
4GovernmentProtect identity records.
→
5Password managerProtects every stored login.
Why a password alone may not be enough
A stolen password can expose more than one service when it is reused. Two-factor authentication (2FA) adds proof from a different type of factor, such as a device you control. It reduces reliance on the password, but recovery settings and the way you respond to prompts still matter.
PASSWORD ONLY
🔓 A stolen password may be enough to log in
If a password is guessed, reused after a data breach or tricked out of someone, there is no second check.
PASSWORD + 2FA
🔐 The attacker also needs your second proof
An extra check makes a stolen password less useful. However, scammers may also ask for a code or trick someone into approving a sign-in.
Authenticator apps: what their codes mean
An authenticator app generates temporary sign-in codes for accounts that support it.
A code usually accompanies your password. It is not a replacement password or a recovery code.
Many codes change about every 30 seconds and can be generated without a mobile signal.
The setup QR code contains a secret used to create codes. Treat it as sensitive information.
A convincing fake login page can ask for both your password and the current code.
Transfer and backup options differ between apps. Losing a phone may affect access to your accounts.
An independent recovery method helps if the app or the account holding its backup becomes unavailable.
Never share security codes: a real bank, government service, email provider or password manager should not ask you to read out, forward or type a one-time code into an unexpected call, message or website.
Recovery methods are spare keys
Recovery options help prove ownership when your usual sign-in method is unavailable. They deserve the same care as your main login. Account recovery restores access to a service, while a file backup helps recover its contents.
A recovery email is another inbox you can still access if your main account is locked.
A recovery phone number needs to stay current when you change numbers or providers.
A backup code is an emergency credential. Availability, length and use vary by service.
Keep a recovery route independent of the phone or account it is intended to recover.
A passkey is a digital sign-in credential linked to a particular service. Your device can authorise its use with a fingerprint, face check or PIN. The website receives cryptographic proof, not your fingerprint or device PIN. Passkeys resist phishing because they are bound to the genuine service.
A passkey replaces a typed password for supported sign-ins. It is not a six-digit authenticator code.
A synced passkey can be available through a provider on compatible devices.
A device-bound passkey remains on one device or security key, so another access route matters.
A biometric check authorises use of the passkey locally. The biometric itself is not the passkey.
Recovery depends on your provider and setup. Losing a device does not have the same outcome for everyone.
Practical guide:Set up and use passkeys. Choose the route for your device and retain a recovery option.
Password management: make remembering easier, not weaker
A password manager stores credentials in an encrypted vault and can generate a different password for each account. Browser and device managers can be suitable choices. A dedicated manager such as Bitwarden may suit people using several browsers or device types.
A master password protects access to a vault. It should be long, unique and kept private.
Autofill supplies saved credentials to matching sites or apps, reducing the need to copy them.
A Bitwarden two-step recovery code disables its second-step requirement. It does not replace a forgotten master password.
A cookie is a small piece of information that a website saves in your browser. It can help a site remember you, but it can also be used to track browsing activity for advertising or analytics.
🛒
Useful cookies
They remember items in a shopping basket, language choice or that you are signed in during a visit.
📊
Analytics cookies
They help a site understand how people use its pages so it can improve them.
🎯
Advertising cookies
They can help build a picture of interests and show more targeted adverts across sites.
Privacy and security: Cookies are stored data, not programs. Some support essential functions, while others support measurement or advertising. A stolen sign-in cookie can expose a session. Clearing cookies does not erase information already held by a website.
Before you clear cookies
Clearing cookies can sign you out and remove preferences. History, cached files and saved passwords are separate categories. The cookies and browser cleanup guide explains the practical choices for different devices.
Cookies, cache and history: different jobs
Cookies help a website remember a session, preference or identifier.
Cached files are saved copies of page resources, such as images, that can speed up loading.
History is the browser’s record of pages visited in ordinary browsing.
Saved passwords are login credentials, managed separately from cookies.
The selected data category matters more than the general label “clear browsing data”.
What clearing browser data changes
Removing cookies may end sessions and reset language choices or other preferences.
Clearing cached files can help with a stale page, but the browser may download those files again.
Deleting local history does not remove records held by websites or account providers.
Choosing saved passwords for deletion can remove credentials you still need.
Access to your password manager and second factor helps you sign back in after cleanup.
Private browsing: useful, but limited
Private browsing separates the session from ordinary browsing and limits traces kept in the browser.
In Chrome, session cookies and site data are discarded when all Incognito windows close.
Downloaded files and saved bookmarks remain. Websites can recognise you when you sign in.
Private browsing does not make you anonymous or protect you from scams and unsafe downloads.
A useful distinction: First-party and third-party describe who sets a cookie. Necessary, analytics and advertising describe its purpose. A first-party cookie is not automatically privacy-friendly.
🧰 Understand computer care and protection
Windows and Mac
Maintenance keeps software supported, storage usable and important files recoverable. Cleaning temporary files, checking for threats and making backups serve different purposes. No single tool does all three.
1UpdateInstall Windows, browser and app updates.
→
2ProtectKeep Windows Security turned on.
→
3CleanRemove unused apps and temporary files.
→
4Back upCopy important files regularly.
Protection or task
What it is for
When it matters
System and app updates
Fix known faults and security weaknesses in supported software.
When updates become available.
Security scanning
Checks for known threats. A clear scan cannot prove that every account is safe.
Alongside ongoing protection, or after suspicious activity.
Storage management
Removes unneeded files to free space. It does not replace malware protection.
When storage is low or unused files accumulate.
Removing unused apps
Reduces clutter and software you need to maintain.
When an app is no longer needed or supported.
File backups
Keep recoverable copies beyond the original device.
As often as needed to limit work you could lose.
Windows protection and Mac encryption
Windows Security brings together built-in security controls. On a Mac, FileVault protects access to stored data through disk encryption. Encryption helps protect confidentiality if a device is lost, but cannot replace a backup. For Apple computers, see the Mac security and care guide.
USEFUL AND LOW RISK
✅ Built-in storage cleanup and uninstalling unused apps
These are usually enough for normal maintenance. Review what is selected before deleting files.
BE CAREFUL
⚠️ “PC cleaner” pop-ups and registry cleaners
A pop-up claiming to find serious faults may be selling unnecessary software or trying to gain access. Built-in maintenance tools are a sensible starting point. Storage cleanup is not a cure for account theft, missing backups or unsupported software.
Browser extensions: less is safer
Extensions can read or change what you see in your browser. Install only extensions you genuinely need, from the official browser store, made by a recognisable publisher. Review and remove old extensions regularly. Never install an extension because a pop-up claims it will “fix” a problem.
What a useful backup should provide
✓Separate storage: another folder on the same device does not protect against losing that device.
✓The 3-2-1 principle: three copies, on two storage types, with one copy kept off-site.
✓A disconnected copy helps protect against damage spreading from the working device.
✓Cloud synchronisation keeps files in step. Deletions may sync too, so recovery options matter.
A digital footprint is the trail of information connected to you when you use the internet. It includes what you choose to share and information collected in the background.
✍️
Active footprint
Information you deliberately create or share: a post, comment, online review, CV, photo, email or form.
👀
Passive footprint
Information collected while you browse: cookies, device type, approximate location, pages visited and adverts you click.
🧩
Digital imprint
Another name for your online trace. Small pieces of data can build a detailed picture when combined.
Simple example: one ordinary afternoon online
1SearchYou look up trainers.
→
2BrowseA website stores a cookie.
→
3ClickYou open a social-media advert.
→
4ShareYou post a photo wearing them.
The result: each action can add to your footprint. This does not mean every action is bad. It means it is worth being deliberate.
RISKY SHARE
⚠️ “Away for two weeks. Our house is empty!”
This may reveal that your home is unoccupied and show when you will return.
SAFER SHARE
✅ Post holiday photos after you return
You can still enjoy sharing memories without advertising your location in real time.
Quick footprint check
✓Search your name occasionally and see what is public.
✓Think before posting a photo, location or personal detail.
✓Remove accounts you no longer use.
✓Review privacy settings at least twice a year.
📱 Where does your data come from?
Everyday activity
Data is created in many places, not only on social media. The goal is to give only the information that is genuinely needed.
Everyday activity
Possible information created
Simple safer habit
Using an app
Device details, contacts, location, camera access
Check permissions. Turn off access an app does not need.
Online shopping
Name, address, card details, products viewed
Use reputable sites and avoid saving card details everywhere.
Social media
Photos, friends, interests, location and comments
Choose who can see posts and avoid live-location sharing.
Public Wi-Fi
Browsing activity may be exposed on unsafe networks
Avoid banking or entering sensitive details on public Wi-Fi.
Online forms
Contact details, date of birth, documents
Ask: “Why do they need this?” before submitting.
Useful rule: Before pressing “Allow”, ask yourself: Does this app need this information to do its job? A torch app does not need your contacts. A map app may need your location while you use it.
What app permissions allow
Camera and microphone: support calls, photographs and recording when access is allowed.
Location: may provide an approximate area or precise position, depending on your choice.
Contacts and photos: can expose information about other people as well as you.
Background access: can let a feature work when you are not actively using the app.
Privacy concerns who can see or use your information. Security concerns protecting access to it. A private post can still be copied or shared by someone in its audience, even after you delete the original.
The 10-second sharing test
Before you post, comment, send or forward: “Would I be comfortable if my family, employer, school or future employer saw this?”
↓
Does it reveal private information, a live location, a password, a child’s details, or something about another person without permission?
↓
Yes or not sure? Pause. Change it, make it private, or do not share it.
No? Check the audience and share respectfully.
DO NOT POST
📄 A photo of a boarding pass, bank card or certificate
It may show a booking code, full name, date of birth, address or other details that can be misused.
BETTER OPTION
🖼️ Share a cropped photo with private details hidden
Or keep personal documents completely offline and private.
Create a positive footprint too
Your footprint can help you. A professional profile, helpful work, qualifications, respectful comments and accurate contact details can support jobs, education and business opportunities.
Use a professional email address for applications and work.
Keep LinkedIn and professional profiles accurate and up to date.
Ask permission before posting photographs of other people.
Do not forward embarrassing content about someone else.
🔐 Protect your accounts
Understand your sign-in options
Passwords, biometrics and account checks perform different jobs. A screen lock protects a device, while an online sign-in controls access to a service. Both matter when that device holds email, banking apps or saved credentials.
🔑
Passwords and passphrases
A password is a secret used to sign in. A passphrase uses several words. Length and uniqueness matter because a reused secret can expose several accounts.
🧠
Biometric checks
Fingerprint and face checks can unlock a device or approve an action. A PIN or passcode remains important. See the biometric security guide.
📲
Two-factor authentication
2FA combines different types of proof. An authenticator code can supplement a password, but can still be requested by a fake login page.
🤫
Passkeys
A passkey provides proof tied to the genuine service. It can use the same device unlock gesture as other features, but works differently from a password.
WEAK
❌ Umer123 or same password everywhere
Easy to guess or reuse after a data breach.
STRONGER
✅ A long, unique passphrase
Several randomly chosen words can make a memorable passphrase. Avoid personal facts, familiar quotations and published examples. A password manager can generate unique passwords for other accounts.
Five parts of email account protection
1Sign-inA unique password or supported passkey.
→
2VerificationExtra proof for password-based access.
→
3RecoveryA fallback you can still use.
→
4SessionsDevices already signed in.
→
5Mail rulesForwarding and filters in your inbox.
Why email needs attention: An intruder may leave a forwarding rule or an active session behind. A password change alone may not address every route. Follow the email security guide to review the account.
🎣 Scams and phishing
Stop • Check • Protect
Phishing uses impersonation to persuade you to reveal information, open a link or approve an action. It can arrive by email, text, call or QR code. A polished message can be fraudulent. See the phishing and scams guide for examples and responses.
Messages
Royal Parcel Service Your parcel is held. Pay £1.99 now to avoid return. bit.ly/claim-parcel-now
Bank Security Urgent: confirm your code to stop fraud. Reply with the 6-digit code.
These are examples. A real-looking name does not prove a message is genuine.
Warning signs
Pressure: “Act now”, “final warning” or “your account will close”.
A request for money, password, code or bank details.
An unexpected link, attachment or QR code.
An unfamiliar sender, unusual request or unexpected change in payment details. Correct spelling does not prove authenticity.
An offer that sounds too good to be true.
SAFE ACTION
✅ Never use the message link to check
Instead, open the official app yourself, type the official website address manually, or use a phone number from a trusted statement or card. Do not use a number supplied by the suspicious message.
The “Stop, Check, Protect” method
Stop: do not click, reply, download or send money.
Check: independently contact the organisation using a trusted route.
Protect: block and report the message. Tell someone if you are unsure.
How fake web addresses fool people
A web address contains a host name and may include a path to a particular page. A brand name can appear in a misleading subdomain or path. Compare the actual domain with the organisation’s known address. HTTPS protects the connection, not the honesty of its owner.
Example of a genuine-looking domain patternhttps://www.paypal.com/signin
Fake example: the real domain is “secure-check.example”https://paypal.com.secure-check.example/signin
Fake example: a small spelling changehttps://www.paypaI.com/signin — this uses a capital “I” instead of a lower-case “l”
Simple rule: read the address from right to left. In the second example, the site belongs to secure-check.example, not PayPal. The examples above are shown for learning only and should not be visited.
What a suspicious link can hide
Displayed text: the words on a link can differ from its destination.
Misleading subdomains: a familiar name at the beginning does not identify the owner.
Lookalike spelling: a changed letter can be hard to notice at a glance.
Short links and QR codes: conceal the full destination until examined. They are formats, not proof of safety.
Do not trust the caller ID. Say you will call back. Use a different phone if possible, or wait a short time before calling the number printed on your bank card. Never move money to a “safe account” because of an unexpected call.
📸 Social media and messaging safely
Share with care
Social-media safety has two parts: protecting access to your account and controlling what others can see. Sign-in checks, recovery options and linked-device reviews address access. Audience, messaging and location settings address privacy.
Risk
Everyday example
What to do
Live location
A public post says you are at the airport or on holiday.
Share after you leave or return. Turn off location tagging unless needed.
Fake profiles
“Your friend” asks for money, but their account was copied.
Call or message them using a known number before sending anything.
Oversharing
A child’s school uniform, name and daily routine are visible in a photo.
Crop images, hide names and keep family posts private.
Private groups
A message from a private group is screenshot and shared.
Assume anything online can be copied.
Account security and privacy work together
Sign-in protection: a unique password, supported passkey or additional verification helps restrict access. Available methods differ between platforms.
Recovery: current contact details and supported backup options help if your normal sign-in method becomes unavailable.
Active sessions and connected apps: these show devices and services with access. An old browser or unused app may still be connected.
Audience and message controls: govern who can view posts, tag you or contact you. A private audience can still copy what you share.
Location and contacts: sharing settings can reveal your whereabouts or address book. Allow only what fits your intended use.
Practical help: Follow the social-media account security guide for Instagram, WhatsApp, Facebook, X, TikTok, LinkedIn, Snapchat and YouTube. Options vary by platform. For bullying, threats or blackmail, save evidence and seek trusted help.
💻 Safe browsing, downloads and devices
Keep it updated
Device protection combines restricted access, trustworthy software and a recovery plan. Your Apple or Google account may also control device-finding services, saved credentials and backups, making its security particularly important.
⬆️
Updates and trusted apps
Updates address known faults. Trusted download sources reduce risk, but an app’s permissions still need to fit its purpose.
🔒
Screen locks and app locks
A screen lock controls access to the device. An app lock adds a separate check. Android Private Space and Samsung Secure Folder offer separation for supported apps.
⬇️
Finding a lost device
Finding services can help locate or lock a missing device. Availability depends on prior setup, connectivity and the device. Never confront a suspected thief.
💾
Backups and synchronisation
Synchronisation keeps selected data aligned across devices. Backups retain recoverable copies. What is included depends on the service and settings.
PUBLIC WI-FI RISK
☕ Logging in to banking on free café Wi-Fi
Public networks can be unsafe or even fake. Avoid banking, shopping and sensitive logins on them.
SAFER CHOICE
📶 Use mobile data or wait for a trusted network
If you must use public Wi-Fi, avoid sensitive activity and turn off automatic network connection afterwards.
Choose your device: The Android guide covers device and app protection. The iPhone and iPad guide covers Apple’s supported protections, including Find My and Stolen Device Protection. Features vary by device and software version.
🛒 Online shopping and banking
Protect your money
Criminals often copy the appearance of known shops, banks and delivery companies. A professional-looking website is not proof that it is genuine.
Before you pay: a simple check
Did you arrive at this site from an unexpected advert, text, social-media post or link?
↓
Is the price unbelievably low, are contact details missing, or does the web address look slightly wrong?
↓
Yes or unsure? Do not pay. Search for the retailer independently and check reviews from reliable sources.
No obvious warning signs? Still use a protected payment method and keep your confirmation.
What banking protections do
App locks: add an access check when someone can already use your phone.
Transaction alerts: help you notice activity. They do not prevent every unauthorised payment.
Approval prompts: may authorise a sign-in, new payee or payment. The action described matters.
Independent verification: helps detect impersonation before you approve a request.
Payment records: help you report a problem. Follow the banking app security guide for practical protection.
Never be rushed: a genuine bank will not ask you to transfer your money to a “safe account”, give your PIN, or share a one-time code. If in doubt, stop and contact the bank through its official app or number.
🚨 If something goes wrong
Act quickly, do not panic
A hacked account, a forgotten login and missing files need different responses. Account recovery restores access, while restoring a backup recovers data. If money is at risk, contact your bank immediately through a trusted route.
1StopDo not send more money or information.
→
2ContactBank or provider first if money or access is at risk.
→
3SecureProtect affected accounts using a trusted device.
→
4ReportReport the scam and keep evidence.
If this happened…
Do this now
You clicked a suspicious link
Close the page. Do not enter details. Run a security scan and change any password you entered.
You gave away a password or code
Use a trusted device to secure the affected account and review active sessions. Follow the hacked-account response guide.
You sent money to a scammer
Contact your bank immediately using the number on your card or official app. Explain exactly what happened.
Your social account was hacked
Use the provider’s official recovery route and secure the linked email. For a lockout, see account recovery.
You are being bullied, threatened or blackmailed
Do not engage. Save evidence, block/report, and tell a trusted person. Seek urgent help if there is immediate danger.
Ask for help early: Being scammed is not something to be ashamed of. Avoid people demanding payment to “hack back” an account. For deleted or lost files, use the backups and recovery guide.
✅ Your everyday online safety checklist
Take action today
Use this as a reminder, then choose one practical task from the Digital Security Centre. Start with your main email, phone and banking accounts.
10 habits that make a real difference
1Use a supported passkey or a unique, strong password for each important account.
2Turn on 2-step verification, especially for email and banking.
3Keep phones, apps, browsers and computers updated.
4Pause before clicking unexpected links or attachments.
5Never share one-time codes, PINs or full passwords.
6Review app permissions and social-media privacy settings.
7Do not announce live location, holidays or an empty home publicly.
8Use official websites and apps for shopping, banking and deliveries.
9Back up important files and lock your devices.
10Keep recovery options usable if your phone is lost or replaced.
Quick knowledge check
You receive a text saying your bank needs a six-digit code to stop fraud. What is the safest action?
📸 Social media and messaging safely
Share with careSocial-media safety has two parts: protecting access to your account and controlling what others can see. Sign-in checks, recovery options and linked-device reviews address access. Audience, messaging and location settings address privacy.
Account security and privacy work together