Online Safety Center
Stay Safe Online
Six areas cover most of the risk that individuals and families actually face. Work through them in order; each one takes under thirty minutes.
Password Safety
- Use a unique password for every account.
- Use a reputable password manager to store and generate them.
- Never reuse a password across sites — one breach then unlocks many accounts.
- Create long passphrases of several unrelated words rather than short complex strings.
2FA / MFA
- Authenticator apps generate offline codes and work without signal.
- Security keys are hardware devices bound to the real site's domain.
- Passkeys give the same phishing resistance, synced across your devices.
- SMS verification is a fallback: it is exposed to SIM-swap and real-time relay phishing.
Phishing
- Fake login pages that copy a real service pixel for pixel.
- Fake support messages claiming your account is at risk.
- Suspicious attachments and unexpected invoices.
- Urgent payment requests, fake job offers and fake cryptocurrency offers.
Social Media Safety
- Limit personal information such as birth dates, addresses and travel plans.
- Review privacy settings after every major app update.
- Turn on login alerts for new devices.
- Remove unknown active sessions and be cautious with direct messages.
Device Security
- Keep operating systems and apps on automatic updates.
- Use reputable security software and keep it current.
- Encrypt laptops, phones and removable drives holding sensitive data.
- Lock devices with a PIN or biometric, and never plug in unknown USB devices.
Wi-Fi Security
- Change the default router administrator password.
- Use WPA3 or WPA2 with a long, unique Wi-Fi password.
- Update router firmware — it is the most forgotten device on the network.
- Disable remote administration and UPnP unless you genuinely need them.