Why Online Safety Matters for Everyday Users

Online threats are not reserved for large corporations or high-profile individuals. Everyday users — people managing bank accounts, medical appointments, and family photos online — are targeted routinely because they often represent easier opportunities than well-defended organisations.

Understanding a few core principles can significantly reduce the risk of unauthorised access to your accounts and personal data. This guide covers those principles in plain language, without assuming a technical background. For a focused look at your digital footprint specifically, see our plain-language privacy guide.

81%

Data breaches involving weak or stolen passwords

According to Verizon's Data Breach Investigations Report, the majority of hacking-related breaches leverage compromised credentials.

3.4 billion

Phishing emails sent daily worldwide

Estimates from cybersecurity researchers suggest phishing remains one of the most prevalent forms of online attack by volume.

50%+

Users who reuse the same password across accounts

Studies by security researchers consistently find that password reuse is widespread among everyday internet users.

Creating and Managing Strong Passwords

A strong password is long (at least 12 characters), uses a mix of letters, numbers, and symbols, and is unique to each account. Reusing passwords across sites is one of the most common ways accounts get compromised — when one service has a data breach, attackers test those credentials everywhere else.

A password manager — an app that generates and stores complex passwords securely — removes the burden of memorising dozens of unique passwords. You only need to remember one strong master password to unlock the vault.

  • Never use obvious information such as birthdays, names, or common words.
  • Enable two-factor authentication (2FA) wherever it is offered. This means even if your password is stolen, a second step — usually a code sent to your phone — is still required to log in.
  • Check whether your email address has appeared in known data breaches using publicly available tools such as Have I Been Pwned.

Use a passphrase — four or more random words strung together — as your password manager's master password. It is easier to remember than a string of symbols and statistically very difficult to crack.

Length is a more significant factor in password strength than complexity alone; a long, memorable passphrase outperforms a short, complex password.

When setting up 2FA, prefer an authenticator app over SMS codes wherever the service allows it. Authenticator apps are not vulnerable to SIM-swapping attacks, which can intercept text messages.

SIM-swapping — where an attacker convinces a mobile carrier to transfer your number — is a known method for bypassing SMS-based two-factor authentication.

Recognising and Avoiding Phishing

Phishing is when an attacker impersonates a trusted entity — a bank, parcel courier, or government agency — to trick you into handing over login credentials, payment details, or personal information. It arrives most often by email, but also by SMS (sometimes called smishing) and phone call.

Key warning signs include: unexpected urgency, mismatched sender addresses, links that don't match the supposed organisation's domain, and requests for sensitive information that a legitimate organisation would never make via email.

Urgency Is a Red Flag

Phishing messages are designed to make you act before you think. Phrases like 'Your account will be suspended in 24 hours' or 'Immediate action required' are deliberate pressure tactics. Legitimate organisations rarely demand instant responses to sensitive requests via email. Pause, verify the sender independently, and contact the organisation directly if you are unsure.

When in doubt, go directly to the organisation's official website by typing the address yourself, rather than clicking any link in a message. A few seconds of caution prevents most phishing attempts from succeeding.

Securing Your Devices

Your smartphone, tablet, and computer are gateways to virtually every account and service you use. Keeping them secure is therefore foundational to your broader online safety.

  • Install updates promptly. Software updates frequently patch security vulnerabilities that attackers exploit. Enabling automatic updates removes the risk of forgetting.
  • Use a strong screen lock. A PIN, password, or biometric lock on your devices prevents physical access by others.
  • Only install apps from official sources such as your device's manufacturer app store. Third-party app stores carry a higher risk of malicious software.
  • Review app permissions. An app that requests access to your microphone, location, or contacts without a clear reason is worth questioning.

For a thorough walkthrough of smartphone-specific settings, our smartphone security guide covers these steps in detail.

Protecting Your Privacy Online

Privacy and security are related but distinct. Security is about preventing unauthorised access; privacy is about controlling what information you share and with whom — even with services you have legitimately signed up to.

Review the privacy settings on social media platforms, browsers, and frequently used apps. Ask yourself:

  1. Which apps have access to my location, and is that access necessary?
  2. Are my social media posts visible to the public or only to people I know?
  3. Does my browser save passwords and browsing history in a way I am comfortable with?

Many platforms default to the broadest data sharing settings because it benefits their advertising models. Adjusting these defaults takes only a few minutes but can meaningfully limit how much personal data is collected and shared. You can also run a structured check using the personal data security audit checklist.

“Privacy is not about hiding something. It is about being able to control your own narrative and protect your personal information from those who would use it without your knowledge or consent.”

— Ann Cavoukian, Former Information and Privacy Commissioner of Ontario; creator of the Privacy by Design framework

Safe Browsing and Network Habits

Not all online environments carry the same risk. Public Wi-Fi networks — in cafés, airports, or hotels — are convenient but potentially unsecured, meaning others on the same network could intercept unencrypted traffic.

Practical habits for safer browsing include:

  • Look for HTTPS (the padlock icon) in your browser's address bar before entering any personal or payment information. HTTPS means the connection between your browser and the site is encrypted.
  • Avoid logging into sensitive accounts such as online banking over public Wi-Fi. If you must, consider using a VPN (Virtual Private Network), which encrypts your connection — though be aware that not all VPN services are equally trustworthy.
  • Clear cookies and browsing history periodically, particularly on shared computers.
  • Use a browser that receives regular security updates.

Check for HTTPS Before Entering Any Data

Before typing a password, payment detail, or personal information into any website, confirm the address bar shows a padlock icon and begins with 'https://'. If the padlock is missing or shows a warning, leave the site. This simple check takes under a second and prevents a wide range of interception risks.

Building a Lasting Security Routine

Online safety is not a one-time setup — it requires occasional attention to remain effective. The good news is that a small number of consistent habits covers the majority of everyday risk.

Consider scheduling a simple quarterly review covering: password health, software update status, app permissions, and account recovery information (backup email, phone number). This takes less time than most people expect and catches problems before they become serious.

For families with younger users at home, our guide to children and online safety offers age-appropriate starting points. And if you want to embed better habits gradually rather than overhauling everything at once, everyday habits that strengthen security is a practical next step.

Act Quickly If You Suspect a Breach

If you believe an account has been compromised, change the password immediately and log out of all active sessions if the platform allows it. Then check whether the same password was used elsewhere and change it on those accounts too. Enable two-factor authentication if it was not already active. Contact your bank if any financial account may be involved.

No single measure makes you completely immune to online threats, but a layered approach — strong passwords, two-factor authentication, updated software, and a cautious eye for suspicious messages — makes you a far less convenient target.