Digital Safety for Beginners: The Habits That Protect You Most

Digital safety for beginners: 6 habits drawn from agencies in the UK, US, Australia and EU, from guarding your email first to backups and scam checks.

An illustrated cover card headed “Digital Safety for Beginners”, with the line “The habits that protect you most”. Line drawing of a hall table: a phone on a small stand shows a message bubble with a parcel icon and an underlined link, a round pause sign floats above it, and a taped cardboard parcel sits on the table beside it.

A password nobody could guess is no safer once a site you forgot about leaks it. A text saying the courier missed you, with a small redelivery fee to pay through a link, can be spelled perfectly and still be a scam, sent on a day you happen to be expecting a parcel. Neither attack needs to know who you are.

Digital safety for beginners comes down to a handful of habits that guard the main doors everyday attacks use: stolen passwords, messages that trick you, and software with known holes. Government agencies in the UK, the US, Australia and the European Union give ordinary people overlapping short lists: all four include two-step verification, prompt updates and backups, alongside unique passwords or caution with unexpected messages.1234 In practice, that gives six habits:

  1. Protect your email account first
  2. Use a different password for every account
  3. Add a second sign-in step, or a passkey
  4. Install updates promptly
  5. Pause before you act on a message
  6. Back up what you can’t replace, and set up phone finding

With only ten minutes today, spend them on the first item: your email is the account that can reset all the others.

A delivery text, a parcel you are expecting, and a pause before you tap.

Everyday attacks come through three main doors

Many attacks on ordinary people are sent in bulk rather than aimed at anyone in particular; the US Federal Trade Commission (FTC) says scammers launch thousands of phishing attacks every day.2 They come through three main doors: a password stolen somewhere else, a message that tricks you, and software with a known flaw. Britain’s National Cyber Security Centre (NCSC) says the most common way passwords are stolen is a data breach at an organization holding your details, after which criminals try them on other accounts.5

The other two doors top the 2025 threat report of ENISA, the European Union’s cyber-security agency. In the incidents it analyzed, mostly attacks on organizations in the EU between mid-2024 and mid-2025, phishing was the way in for about 60 percent, and exploiting software weaknesses for about a fifth.6 Those figures come mainly from public reports about organizations, not households, so read them as a guide to which doors attackers try most, not as your personal odds.

Scale is why simple habits work: a program running through leaked logins succeeds wherever a password alone opens the account and usually fails where a second step is needed. Picture an old photo-printing account you forgot about. The site is breached, your password lands on a list, and the program tries it on your email, your shopping account and your bank.

The lesson is that you don’t need to outwit an attacker. You need each door to demand more than one lucky guess or one careless tap.

The six digital safety habits

The habits below are ordered by payoff: the first three protect your accounts, the next two protect your devices and your attention, and the last protects your data when something breaks or goes missing.

1. Protect your email account first

Your email account is the master key to the rest of your online life, because the “forgot password” link on most other accounts sends a reset message there. The NCSC warns that someone who gets into your email can reset your other passwords, read private information and send messages pretending to be you. Its advice is a strong password you use for no other account, at home or at work, plus two-step verification on the email account itself.7

Whoever controls your email can reset the rest. A schematic, not measured data.

Think about what an intruder can do with only your inbox. They can ask your shopping site for a reset link and use it. They can also add a forwarding rule so that every future reset email is quietly copied to them, a tactic the NCSC’s recovery guide calls common.8 Forwarding rules sit in the same settings as email filters and rules that sort your inbox, so it is worth knowing where yours live.

So do email before anything else. Change its password if you have used it anywhere else, switch on two-step verification, and look once at the forwarding settings to confirm they send nothing to an address you don’t recognize.

2. Use a different password for every account

A different password for each account turns a breach at one site into a problem at one site. Australia’s Cyber Security Centre (ACSC) says not to reuse passphrases on multiple accounts and suggests a password manager if you struggle to remember them all. For the few you must remember, such as the one that opens the manager, it suggests four or more random words and at least 15 characters.3

Myth
A strong password keeps my account safe.
Fact
The UK's NCSC points out that a password that is hard to guess is no harder to steal. Breaches and fake login pages take it whole.

Nobody can remember a different random passphrase for dozens of accounts, which is why a manager does the work. How to choose a password manager, and why letting it generate passwords matters covers the choice in detail.

3. Add a second sign-in step, or a passkey

Two-step verification (2SV, also called two-factor or multi-factor authentication) asks for something besides your password, such as a code, a prompt on your phone or your fingerprint, so a stolen password alone no longer opens the account. The NCSC calls turning it on one of the most effective ways to protect your accounts.5

The clearest real-world measurement comes from Google’s own sign-in records.

The study

Moderate evidence

What an extra sign-in check did to stolen passwords at Google

Researchers from Google and New York University traced sign-in attempts made with stolen passwords and checked what happened when Google asked a suspicious sign-in for extra proof. A code texted to the account holder’s phone stopped every automated attempt and 96% of attempts that began with phishing. A prompt on the owner’s phone stopped 99% of phishing-based attempts. Questions such as the last place you signed in from stopped as few as 10%, probably because a fake page can ask for those too.9

For you, the lesson is that something you have, like your phone, beats something you know, because a scam page can collect anything you type. Keep the limits in mind: these were Google’s own checks, shown only when a sign-in looked suspicious, the data are from 2018, and attacks may have changed since.

Passkeys go a step further. With a passkey, you sign in by approving the login on your device, with no password to type. In April 2026 the NCSC began recommending passkeys as people’s first choice wherever a service offers them, saying they are at least as secure as, and generally more secure than, the strongest password paired with 2SV.10

When you can choose between second steps, ENISA advises a passkey, a security key or an authenticator app over codes sent by text message. It also says never to share a verification code or approve a sign-in request you did not start yourself.4

Australia’s ACSC suggests an order for adding the second step: email first, then online banking, then social media.3 Set up the backup options each account offers at the same time, so a lost phone does not lock you out.

4. Install updates promptly

Updates matter because many of them fix security weaknesses that criminals already know how to use. Australia’s ACSC says cybercriminals break into devices through known weaknesses in systems or apps, that updates fix those weaknesses, and that you should turn on automatic updates on all your devices.3

The NCSC adds a point people miss: manufacturers eventually stop sending updates to older devices, and a phone that no longer receives security updates is less secure. It suggests avoiding phones that are no longer supported where you can.11

The “remind me tonight” button is where this habit breaks. A phone that postpones updates for weeks keeps open a door its maker has already offered to close. An old tablet handed down to a child may still run perfectly while missing every fix. Turn on automatic updates for your phone, computer, browser and apps, restart when asked, and check once whether your older devices still get updates.

5. Pause before you act on a message

Scam messages work by getting you to act before you think, and their warning signs are more reliable than spelling mistakes. The NCSC lists five: a message that claims authority, creates urgency, stirs emotion, offers something scarce, or hooks onto current events or a time of year. Polish is no longer a clue: the NCSC notes that scams used to be easier to spot through bad spelling or odd design, but are getting smarter, and some fool the experts.12

Go back to the redelivery text. It scores on urgency (pay today or the parcel goes back) and on timing (you are expecting a parcel). The FTC lists fake package delivery notices among the scam texts it warns about.13 The fix is a habit, not a skill: don’t use the link or number in the message. Check through something you already trust, such as the courier’s app, a website address you type yourself or the company’s advertised phone number, which is what the ACSC advises.3

The same pressure drives money offers; the patterns behind passive income scams shows how it looks when the bait is an income rather than a parcel.

6. Back up what you can’t replace, and set up phone finding

A backup is a copy of your data kept somewhere separate, so a lost phone, a broken laptop or ransomware costs you a device rather than your photos and documents. The NCSC suggests backing up your important data, such as photos, documents and contacts, to cloud storage or removable media, then checking that the backup really contains your recent files. It adds two details: protect the cloud account with a strong password and 2SV, and unplug an external drive when you are not using it, because ransomware can reach any drive that stays plugged in.14

Now the lost phone. Say you leave it in a taxi. If Apple’s Find My was switched on beforehand, you can locate the iPhone, lock it with Lost Mode or erase it from another device or a browser; Apple says that if it was not on before the loss, you cannot mark the phone as lost or erase it remotely.15 On Android, Google’s Find Hub is turned on automatically once a Google account is added, and it can locate, lock or erase the device.16

The lesson is to set these up while nothing is wrong. Spend two minutes confirming that phone finding is on, that your phone has a screen lock, and that your backup includes this month’s photos.

Eight small fixes for this week

What backs each habit, and how firmly

We found no trial that randomly assigned people to these habits and counted whose accounts were taken over. The list rests on agreement between national agencies and on measurements such as Google’s, which is why the table below labels each row.

Protective habit What the best evidence found Evidence
Email first, unique passwords Access to email lets an attacker reset other accounts; reused passwords let one theft open many Expert guidance, UK NCSC7
A second sign-in step Phone-based checks stopped all automated and most phishing-based takeover attempts Observational, moderate: one company’s 2018 data9
Updates and caution with messages Phishing and software weaknesses were the two most common ways into EU organizations Incident data from organizations, not individuals6
Backups and phone finding We found no study of the benefit for households Gap: expert guidance only

Read the labels as confidence, not priority. Nobody has counted the photo albums that backups rescued, yet a lost phone with no copy is easy to picture, and setting one up takes minutes.

If an account is taken over anyway

If an account is taken over, the NCSC’s recovery guide sets out an order that limits the damage. Recover the account through the provider’s own help pages, check your email forwarding rules, and change the password on that account and on any other that shares it. Then sign out other devices, turn on 2SV, update your devices, warn your contacts and check your bank and shopping accounts, reaching your bank only through its official website. If you have lost money, tell your bank and report it as a crime; for UK readers, the NCSC names Report Fraud (in Scotland, the police on 101).8

  1. 1Recover the accountthrough the provider's official help pages
  2. 2Check forwarding rulesso reset emails reach only you
  3. 3Change reused passwordson every account that shared it
  4. 4Sign out everywhere, turn on 2SV
  5. 5Warn contacts, check bank
The NCSC's recovery order, shortened: take the inbox back first, then close the other doors.

The order has a reason. Until a hidden forwarding rule is gone, every password reset you request may land in the intruder’s inbox too. And the warning to contacts matters because a hijacked account can be used to send the next round of scam messages to people who trust you. If a friend asks why you sent them an odd link last night, that question is your cue to start at step one.

Wherever you live, your local police or your country’s national fraud or cyber-crime reporting service is the place to report. A few examples: in Australia, the ACSC points to ReportCyber for cybercrime and Scamwatch for scams.3 In Canada, the Canadian Anti-Fraud Centre asks victims to contact local police and to report to the centre as well.17 US readers can report to the Federal Trade Commission through ReportFraud.ftc.gov.2

Later guides in the digital safety section will go deeper on each habit, from passkeys and scam texts to reporting fraud country by country.

The bottom line

Start with your email: a password used nowhere else and a second sign-in step, preferably on your phone or as a passkey. Then let updates install themselves, keep a copy of what you can’t replace, and treat any message that rushes you as a reason to check through a route you already trust. None of it needs technical skill, and together it guards the main doors everyday attacks use.

Frequently asked questions

Are text-message codes still worth using?

Yes, where nothing stronger is offered. In Google's 2019 study of its own sign-in checks, a code texted to the account holder's phone still stopped most takeover attempts that began with phishing, though a prompt on the phone did better. When you have a choice, ENISA, the EU's cyber-security agency, advises a passkey, a security key or an authenticator app instead.

What if I lose the phone I use for two-step verification?

Plan for it before it happens. Google's Android help points people who use its 2-Step Verification to backup options, and Apple says you can sign in to its Find My website to mark a lost iPhone as lost without a verification code. Set up the backup options your main accounts offer, such as backup codes, and keep them somewhere other than the phone.

Is it safe to keep using an old phone or laptop?

It keeps working, but it becomes less secure once the maker stops sending updates. The UK's NCSC says an unsupported device no longer receives the manufacturer's security updates, and suggests avoiding phones that are no longer supported where possible. Check the maker's support pages; if updates have ended, consider moving banking and email to a device that still gets them.

Sources

  1. Top tips for staying secure online. UK National Cyber Security Centre (published 17 December 2018, reviewed 21 December 2021; accessed 28 September 2026)
  2. How To Recognize and Avoid Phishing Scams. US Federal Trade Commission, Consumer Advice (accessed 28 September 2026)
  3. Easy steps to secure yourself online. Australian Signals Directorate's Australian Cyber Security Centre (first published 29 April 2019, last updated 7 April 2021; accessed 28 September 2026)
  4. Cyber Hygiene. European Union Agency for Cybersecurity, ENISA (accessed 28 September 2026)
  5. Top tips for staying secure online: Turn on 2-step verification (2SV). UK National Cyber Security Centre (collection reviewed 21 December 2021; accessed 28 September 2026)
  6. ENISA Threat Landscape 2025. European Union Agency for Cybersecurity, ENISA (October 2025; version 1.3, September 2026)
  7. Top tips for staying secure online: Use a strong and separate password for your email. UK National Cyber Security Centre (collection reviewed 21 December 2021; accessed 28 September 2026)
  8. Recovering a hacked account. UK National Cyber Security Centre (published 17 December 2018, modified 8 December 2025; accessed 28 September 2026)
  9. Evaluating Login Challenges as a Defense Against Account Takeover. Doerfler, P., Marincenko, M., Ranieri, J., Jiang, Y., Moscicki, A., McCoy, D. & Thomas, K. (2019). Proceedings of The World Wide Web Conference (WWW '19), ACM
  10. NCSC: Leave passwords in the past - passkeys are the future. UK National Cyber Security Centre, news release (23 April 2026; accessed 28 September 2026)
  11. Top tips for staying secure online: Install the latest software and app updates. UK National Cyber Security Centre (collection reviewed 21 December 2021; accessed 28 September 2026)
  12. Phishing scams: Spotting scams. UK National Cyber Security Centre (accessed 28 September 2026)
  13. How to Recognize and Report Spam Text Messages. US Federal Trade Commission, Consumer Advice (accessed 28 September 2026)
  14. Top tips for staying secure online: Always back up your most important data. UK National Cyber Security Centre (collection reviewed 21 December 2021; accessed 28 September 2026)
  15. How to find your lost iPhone or iPad. Apple Support (accessed 28 September 2026)
  16. Find, secure, or erase a lost Android device. Google, Android Help (accessed 28 September 2026)
  17. Report fraud and cybercrime. Canadian Anti-Fraud Centre (accessed 28 September 2026)

How we researched this

In September 2026 we read, in full, consumer guidance from the UK's NCSC, the US FTC, Australia's ACSC, the EU's ENISA and the Canadian Anti-Fraud Centre, ENISA's 2025 threat report, Apple and Google help pages, and a 2019 peer-reviewed study of Google sign-in data. Main limitation: we found no trial measuring whether people who follow these habits lose fewer accounts; the evidence is agency guidance plus one company's observational data.

Last updated . Read our editorial policy.

Cite this article: WiserHours. (2026). Digital Safety for Beginners: The Habits That Protect You Most. WiserHours. https://wiserhours.com/digital-safety/digital-safety-basics/. Tables and charts may be reused with a link back to this page.