Your Digital Footprint: Stay Safe Online

Understand the online trail you leave behind, recognise everyday risks, and take simple steps to protect your accounts, money, privacy and reputation.

Digital Security Centre

Click on Digital Security Centre button for enhanced, easy-to-follow security guides for your accounts, banking, privacy and devices.

What you will learn

This page explains the ideas behind online safety: what the protections mean, why they matter and where their limits lie. For practical instructions, visit the Digital Security Centre and its step-by-step guides.

👣
UnderstandWhat a digital footprint is and where it comes from.
🔎
RecogniseScams, unsafe links, fake messages and risky sharing.
🛡️
ProtectPasswords, devices, accounts, money and personal data.
🚨
RespondAct quickly and calmly if something goes wrong.
Remember: Your online activity tells a story about you. You can make that story safer and more positive by making small, regular choices.

🛡️ Secure your essentials first

Highest priority

You do not need advanced technical skills. Start with the accounts that can unlock other accounts, hold your money, prove your identity or receive security codes.

Start with these five: your main email, government-service logins, banking apps and websites, your password manager, and your mobile phone. If a criminal controls one of these, they may be able to reset other accounts.
1EmailUsed for password resets.
→
2PhoneReceives security checks.
→
3BankingProtect money and alerts.
→
4GovernmentProtect identity records.
→
5Password managerProtects every stored login.

Why a password alone may not be enough

A stolen password can expose more than one service when it is reused. Two-factor authentication (2FA) adds proof from a different type of factor, such as a device you control. It reduces reliance on the password, but recovery settings and the way you respond to prompts still matter.

PASSWORD ONLY
🔓 A stolen password may be enough to log in

If a password is guessed, reused after a data breach or tricked out of someone, there is no second check.

PASSWORD + 2FA
🔐 The attacker also needs your second proof

An extra check makes a stolen password less useful. However, scammers may also ask for a code or trick someone into approving a sign-in.

Authenticator apps: what their codes mean
  1. An authenticator app generates temporary sign-in codes for accounts that support it.
  2. A code usually accompanies your password. It is not a replacement password or a recovery code.
  3. Many codes change about every 30 seconds and can be generated without a mobile signal.
  4. The setup QR code contains a secret used to create codes. Treat it as sensitive information.
  5. A convincing fake login page can ask for both your password and the current code.
  6. Transfer and backup options differ between apps. Losing a phone may affect access to your accounts.
  7. An independent recovery method helps if the app or the account holding its backup becomes unavailable.

Ready to set it up? Follow the two-factor authentication guide for the practical steps.

Never share security codes: a real bank, government service, email provider or password manager should not ask you to read out, forward or type a one-time code into an unexpected call, message or website.

Recovery methods are spare keys

Recovery options help prove ownership when your usual sign-in method is unavailable. They deserve the same care as your main login. Account recovery restores access to a service, while a file backup helps recover its contents.

  • A recovery email is another inbox you can still access if your main account is locked.
  • A recovery phone number needs to stay current when you change numbers or providers.
  • A backup code is an emergency credential. Availability, length and use vary by service.
  • Keep a recovery route independent of the phone or account it is intended to recover.
  • Before changing devices, check your fallback options. See the account recovery and safety codes guide.

What are passkeys?

A passkey is a digital sign-in credential linked to a particular service. Your device can authorise its use with a fingerprint, face check or PIN. The website receives cryptographic proof, not your fingerprint or device PIN. Passkeys resist phishing because they are bound to the genuine service.

  1. A passkey replaces a typed password for supported sign-ins. It is not a six-digit authenticator code.
  2. A synced passkey can be available through a provider on compatible devices.
  3. A device-bound passkey remains on one device or security key, so another access route matters.
  4. A biometric check authorises use of the passkey locally. The biometric itself is not the passkey.
  5. Recovery depends on your provider and setup. Losing a device does not have the same outcome for everyone.

Practical guide: Set up and use passkeys. Choose the route for your device and retain a recovery option.

Password management: make remembering easier, not weaker

A password manager stores credentials in an encrypted vault and can generate a different password for each account. Browser and device managers can be suitable choices. A dedicated manager such as Bitwarden may suit people using several browsers or device types.

  • A master password protects access to a vault. It should be long, unique and kept private.
  • Autofill supplies saved credentials to matching sites or apps, reducing the need to copy them.
  • A Bitwarden two-step recovery code disables its second-step requirement. It does not replace a forgotten master password.
  • For vault creation, protection and everyday use, follow the Bitwarden step-by-step guide.

🍪 Cookies and the data your browser keeps

Browser basics

A cookie is a small piece of information that a website saves in your browser. It can help a site remember you, but it can also be used to track browsing activity for advertising or analytics.

🛒

Useful cookies

They remember items in a shopping basket, language choice or that you are signed in during a visit.

📊

Analytics cookies

They help a site understand how people use its pages so it can improve them.

🎯

Advertising cookies

They can help build a picture of interests and show more targeted adverts across sites.

Privacy and security: Cookies are stored data, not programs. Some support essential functions, while others support measurement or advertising. A stolen sign-in cookie can expose a session. Clearing cookies does not erase information already held by a website.

Before you clear cookies

Clearing cookies can sign you out and remove preferences. History, cached files and saved passwords are separate categories. The cookies and browser cleanup guide explains the practical choices for different devices.

Cookies, cache and history: different jobs
  1. Cookies help a website remember a session, preference or identifier.
  2. Cached files are saved copies of page resources, such as images, that can speed up loading.
  3. History is the browser’s record of pages visited in ordinary browsing.
  4. Saved passwords are login credentials, managed separately from cookies.
  5. The selected data category matters more than the general label “clear browsing data”.
What clearing browser data changes
  1. Removing cookies may end sessions and reset language choices or other preferences.
  2. Clearing cached files can help with a stale page, but the browser may download those files again.
  3. Deleting local history does not remove records held by websites or account providers.
  4. Choosing saved passwords for deletion can remove credentials you still need.
  5. Access to your password manager and second factor helps you sign back in after cleanup.
Private browsing: useful, but limited
  1. Private browsing separates the session from ordinary browsing and limits traces kept in the browser.
  2. In Chrome, session cookies and site data are discarded when all Incognito windows close.
  3. Downloaded files and saved bookmarks remain. Websites can recognise you when you sign in.
  4. Private browsing does not make you anonymous or protect you from scams and unsafe downloads.
A useful distinction: First-party and third-party describe who sets a cookie. Necessary, analytics and advertising describe its purpose. A first-party cookie is not automatically privacy-friendly.

🧰 Understand computer care and protection

Windows and Mac

Maintenance keeps software supported, storage usable and important files recoverable. Cleaning temporary files, checking for threats and making backups serve different purposes. No single tool does all three.

1UpdateInstall Windows, browser and app updates.
→
2ProtectKeep Windows Security turned on.
→
3CleanRemove unused apps and temporary files.
→
4Back upCopy important files regularly.
Protection or taskWhat it is forWhen it matters
System and app updatesFix known faults and security weaknesses in supported software.When updates become available.
Security scanningChecks for known threats. A clear scan cannot prove that every account is safe.Alongside ongoing protection, or after suspicious activity.
Storage managementRemoves unneeded files to free space. It does not replace malware protection.When storage is low or unused files accumulate.
Removing unused appsReduces clutter and software you need to maintain.When an app is no longer needed or supported.
File backupsKeep recoverable copies beyond the original device.As often as needed to limit work you could lose.

Windows protection and Mac encryption

Windows Security brings together built-in security controls. On a Mac, FileVault protects access to stored data through disk encryption. Encryption helps protect confidentiality if a device is lost, but cannot replace a backup. For Apple computers, see the Mac security and care guide.

USEFUL AND LOW RISK
✅ Built-in storage cleanup and uninstalling unused apps

These are usually enough for normal maintenance. Review what is selected before deleting files.

BE CAREFUL
⚠️ “PC cleaner” pop-ups and registry cleaners

A pop-up claiming to find serious faults may be selling unnecessary software or trying to gain access. Built-in maintenance tools are a sensible starting point. Storage cleanup is not a cure for account theft, missing backups or unsupported software.

Browser extensions: less is safer

Extensions can read or change what you see in your browser. Install only extensions you genuinely need, from the official browser store, made by a recognisable publisher. Review and remove old extensions regularly. Never install an extension because a pop-up claims it will “fix” a problem.

What a useful backup should provide

✓Separate storage: another folder on the same device does not protect against losing that device.
✓The 3-2-1 principle: three copies, on two storage types, with one copy kept off-site.
✓A disconnected copy helps protect against damage spreading from the working device.
✓Cloud synchronisation keeps files in step. Deletions may sync too, so recovery options matter.
✓A restore check shows whether a copy is usable. See the backups and recovery guide.

👣 What is a digital footprint?

Start here

A digital footprint is the trail of information connected to you when you use the internet. It includes what you choose to share and information collected in the background.

✍️

Active footprint

Information you deliberately create or share: a post, comment, online review, CV, photo, email or form.

👀

Passive footprint

Information collected while you browse: cookies, device type, approximate location, pages visited and adverts you click.

🧩

Digital imprint

Another name for your online trace. Small pieces of data can build a detailed picture when combined.

Simple example: one ordinary afternoon online

1SearchYou look up trainers.
→
2BrowseA website stores a cookie.
→
3ClickYou open a social-media advert.
→
4ShareYou post a photo wearing them.

The result: each action can add to your footprint. This does not mean every action is bad. It means it is worth being deliberate.

RISKY SHARE
⚠️ “Away for two weeks. Our house is empty!”

This may reveal that your home is unoccupied and show when you will return.

SAFER SHARE
✅ Post holiday photos after you return

You can still enjoy sharing memories without advertising your location in real time.

Quick footprint check

✓Search your name occasionally and see what is public.
✓Think before posting a photo, location or personal detail.
✓Remove accounts you no longer use.
✓Review privacy settings at least twice a year.

📱 Where does your data come from?

Everyday activity

Data is created in many places, not only on social media. The goal is to give only the information that is genuinely needed.

Everyday activityPossible information createdSimple safer habit
Using an appDevice details, contacts, location, camera accessCheck permissions. Turn off access an app does not need.
Online shoppingName, address, card details, products viewedUse reputable sites and avoid saving card details everywhere.
Social mediaPhotos, friends, interests, location and commentsChoose who can see posts and avoid live-location sharing.
Public Wi-FiBrowsing activity may be exposed on unsafe networksAvoid banking or entering sensitive details on public Wi-Fi.
Online formsContact details, date of birth, documentsAsk: “Why do they need this?” before submitting.
Useful rule: Before pressing “Allow”, ask yourself: Does this app need this information to do its job? A torch app does not need your contacts. A map app may need your location while you use it.
What app permissions allow
  1. Camera and microphone: support calls, photographs and recording when access is allowed.
  2. Location: may provide an approximate area or precise position, depending on your choice.
  3. Contacts and photos: can expose information about other people as well as you.
  4. Background access: can let a feature work when you are not actively using the app.
  5. Choose access that fits the task. Practical routes: Android security or iPhone and iPad security.

🗣️ Privacy, reputation and respect

Pause before posting

Privacy concerns who can see or use your information. Security concerns protecting access to it. A private post can still be copied or shared by someone in its audience, even after you delete the original.

The 10-second sharing test

Before you post, comment, send or forward: “Would I be comfortable if my family, employer, school or future employer saw this?”
↓
Does it reveal private information, a live location, a password, a child’s details, or something about another person without permission?
↓
Yes or not sure? Pause. Change it, make it private, or do not share it.
No? Check the audience and share respectfully.
DO NOT POST
📄 A photo of a boarding pass, bank card or certificate

It may show a booking code, full name, date of birth, address or other details that can be misused.

BETTER OPTION
🖼️ Share a cropped photo with private details hidden

Or keep personal documents completely offline and private.

Create a positive footprint too

Your footprint can help you. A professional profile, helpful work, qualifications, respectful comments and accurate contact details can support jobs, education and business opportunities.

  • Use a professional email address for applications and work.
  • Keep LinkedIn and professional profiles accurate and up to date.
  • Ask permission before posting photographs of other people.
  • Do not forward embarrassing content about someone else.

🔐 Protect your accounts

Understand your sign-in options

Passwords, biometrics and account checks perform different jobs. A screen lock protects a device, while an online sign-in controls access to a service. Both matter when that device holds email, banking apps or saved credentials.

🔑

Passwords and passphrases

A password is a secret used to sign in. A passphrase uses several words. Length and uniqueness matter because a reused secret can expose several accounts.

🧠

Biometric checks

Fingerprint and face checks can unlock a device or approve an action. A PIN or passcode remains important. See the biometric security guide.

📲

Two-factor authentication

2FA combines different types of proof. An authenticator code can supplement a password, but can still be requested by a fake login page.

🤫

Passkeys

A passkey provides proof tied to the genuine service. It can use the same device unlock gesture as other features, but works differently from a password.

WEAK
❌ Umer123 or same password everywhere

Easy to guess or reuse after a data breach.

STRONGER
✅ A long, unique passphrase

Several randomly chosen words can make a memorable passphrase. Avoid personal facts, familiar quotations and published examples. A password manager can generate unique passwords for other accounts.

Five parts of email account protection

1Sign-inA unique password or supported passkey.
→
2VerificationExtra proof for password-based access.
→
3RecoveryA fallback you can still use.
→
4SessionsDevices already signed in.
→
5Mail rulesForwarding and filters in your inbox.
Why email needs attention: An intruder may leave a forwarding rule or an active session behind. A password change alone may not address every route. Follow the email security guide to review the account.

🎣 Scams and phishing

Stop • Check • Protect

Phishing uses impersonation to persuade you to reveal information, open a link or approve an action. It can arrive by email, text, call or QR code. A polished message can be fraudulent. See the phishing and scams guide for examples and responses.

Messages
Royal Parcel Service
Your parcel is held. Pay £1.99 now to avoid return.
bit.ly/claim-parcel-now
Bank Security
Urgent: confirm your code to stop fraud.
Reply with the 6-digit code.

These are examples. A real-looking name does not prove a message is genuine.

Warning signs

  • Pressure: “Act now”, “final warning” or “your account will close”.
  • A request for money, password, code or bank details.
  • An unexpected link, attachment or QR code.
  • An unfamiliar sender, unusual request or unexpected change in payment details. Correct spelling does not prove authenticity.
  • An offer that sounds too good to be true.
SAFE ACTION
✅ Never use the message link to check

Instead, open the official app yourself, type the official website address manually, or use a phone number from a trusted statement or card. Do not use a number supplied by the suspicious message.

The “Stop, Check, Protect” method

  1. Stop: do not click, reply, download or send money.
  2. Check: independently contact the organisation using a trusted route.
  3. Protect: block and report the message. Tell someone if you are unsure.

How fake web addresses fool people

A web address contains a host name and may include a path to a particular page. A brand name can appear in a misleading subdomain or path. Compare the actual domain with the organisation’s known address. HTTPS protects the connection, not the honesty of its owner.

Example of a genuine-looking domain patternhttps://www.paypal.com/signin
Fake example: the real domain is “secure-check.example”https://paypal.com.secure-check.example/signin
Fake example: a small spelling changehttps://www.paypaI.com/signin — this uses a capital “I” instead of a lower-case “l”

Simple rule: read the address from right to left. In the second example, the site belongs to secure-check.example, not PayPal. The examples above are shown for learning only and should not be visited.

What a suspicious link can hide
  1. Displayed text: the words on a link can differ from its destination.
  2. Misleading subdomains: a familiar name at the beginning does not identify the owner.
  3. Lookalike spelling: a changed letter can be hard to notice at a glance.
  4. Short links and QR codes: conceal the full destination until examined. They are formats, not proof of safety.
  5. Independent checks: a checker cannot guarantee safety. Follow the safe links and website addresses guide for device-specific checks.
What if a caller says they are from your bank?

Do not trust the caller ID. Say you will call back. Use a different phone if possible, or wait a short time before calling the number printed on your bank card. Never move money to a “safe account” because of an unexpected call.

📸 Social media and messaging safely

Share with care

Social-media safety has two parts: protecting access to your account and controlling what others can see. Sign-in checks, recovery options and linked-device reviews address access. Audience, messaging and location settings address privacy.

RiskEveryday exampleWhat to do
Live locationA public post says you are at the airport or on holiday.Share after you leave or return. Turn off location tagging unless needed.
Fake profiles“Your friend” asks for money, but their account was copied.Call or message them using a known number before sending anything.
OversharingA child’s school uniform, name and daily routine are visible in a photo.Crop images, hide names and keep family posts private.
Private groupsA message from a private group is screenshot and shared.Assume anything online can be copied.

Account security and privacy work together

  1. Sign-in protection: a unique password, supported passkey or additional verification helps restrict access. Available methods differ between platforms.
  2. Recovery: current contact details and supported backup options help if your normal sign-in method becomes unavailable.
  3. Active sessions and connected apps: these show devices and services with access. An old browser or unused app may still be connected.
  4. Audience and message controls: govern who can view posts, tag you or contact you. A private audience can still copy what you share.
  5. Location and contacts: sharing settings can reveal your whereabouts or address book. Allow only what fits your intended use.
Practical help: Follow the social-media account security guide for Instagram, WhatsApp, Facebook, X, TikTok, LinkedIn, Snapchat and YouTube. Options vary by platform. For bullying, threats or blackmail, save evidence and seek trusted help.

💻 Safe browsing, downloads and devices

Keep it updated

Device protection combines restricted access, trustworthy software and a recovery plan. Your Apple or Google account may also control device-finding services, saved credentials and backups, making its security particularly important.

⬆️

Updates and trusted apps

Updates address known faults. Trusted download sources reduce risk, but an app’s permissions still need to fit its purpose.

🔒

Screen locks and app locks

A screen lock controls access to the device. An app lock adds a separate check. Android Private Space and Samsung Secure Folder offer separation for supported apps.

⬇️

Finding a lost device

Finding services can help locate or lock a missing device. Availability depends on prior setup, connectivity and the device. Never confront a suspected thief.

💾

Backups and synchronisation

Synchronisation keeps selected data aligned across devices. Backups retain recoverable copies. What is included depends on the service and settings.

PUBLIC WI-FI RISK
☕ Logging in to banking on free café Wi-Fi

Public networks can be unsafe or even fake. Avoid banking, shopping and sensitive logins on them.

SAFER CHOICE
📶 Use mobile data or wait for a trusted network

If you must use public Wi-Fi, avoid sensitive activity and turn off automatic network connection afterwards.

Choose your device: The Android guide covers device and app protection. The iPhone and iPad guide covers Apple’s supported protections, including Find My and Stolen Device Protection. Features vary by device and software version.

🛒 Online shopping and banking

Protect your money

Criminals often copy the appearance of known shops, banks and delivery companies. A professional-looking website is not proof that it is genuine.

Before you pay: a simple check

Did you arrive at this site from an unexpected advert, text, social-media post or link?
↓
Is the price unbelievably low, are contact details missing, or does the web address look slightly wrong?
↓
Yes or unsure? Do not pay. Search for the retailer independently and check reviews from reliable sources.
No obvious warning signs? Still use a protected payment method and keep your confirmation.

What banking protections do

  • App locks: add an access check when someone can already use your phone.
  • Transaction alerts: help you notice activity. They do not prevent every unauthorised payment.
  • Approval prompts: may authorise a sign-in, new payee or payment. The action described matters.
  • Independent verification: helps detect impersonation before you approve a request.
  • Payment records: help you report a problem. Follow the banking app security guide for practical protection.
Never be rushed: a genuine bank will not ask you to transfer your money to a “safe account”, give your PIN, or share a one-time code. If in doubt, stop and contact the bank through its official app or number.

🚨 If something goes wrong

Act quickly, do not panic

A hacked account, a forgotten login and missing files need different responses. Account recovery restores access, while restoring a backup recovers data. If money is at risk, contact your bank immediately through a trusted route.

1StopDo not send more money or information.
→
2ContactBank or provider first if money or access is at risk.
→
3SecureProtect affected accounts using a trusted device.
→
4ReportReport the scam and keep evidence.
If this happened…Do this now
You clicked a suspicious linkClose the page. Do not enter details. Run a security scan and change any password you entered.
You gave away a password or codeUse a trusted device to secure the affected account and review active sessions. Follow the hacked-account response guide.
You sent money to a scammerContact your bank immediately using the number on your card or official app. Explain exactly what happened.
Your social account was hackedUse the provider’s official recovery route and secure the linked email. For a lockout, see account recovery.
You are being bullied, threatened or blackmailedDo not engage. Save evidence, block/report, and tell a trusted person. Seek urgent help if there is immediate danger.
Ask for help early: Being scammed is not something to be ashamed of. Avoid people demanding payment to “hack back” an account. For deleted or lost files, use the backups and recovery guide.

✅ Your everyday online safety checklist

Take action today

Use this as a reminder, then choose one practical task from the Digital Security Centre. Start with your main email, phone and banking accounts.

10 habits that make a real difference

1Use a supported passkey or a unique, strong password for each important account.
2Turn on 2-step verification, especially for email and banking.
3Keep phones, apps, browsers and computers updated.
4Pause before clicking unexpected links or attachments.
5Never share one-time codes, PINs or full passwords.
6Review app permissions and social-media privacy settings.
7Do not announce live location, holidays or an empty home publicly.
8Use official websites and apps for shopping, banking and deliveries.
9Back up important files and lock your devices.
10Keep recovery options usable if your phone is lost or replaced.

Quick knowledge check

You receive a text saying your bank needs a six-digit code to stop fraud. What is the safest action?