10 Things You Should Actually Be Doing to Stay Safe Online (In Plain English)
Look, I spend most of my working life building websites. And after years of watching how the internet actually works behind the scenes, I feel like it’s my responsibility to be straight with you about online safety — not in a scary, corporate-jargon way, but in a “mate, seriously, do these things” kind of way.
The stats from 2026 are properly eye-opening. Cybercrime cost Americans alone $20.9 billion last year. A data breach caused by a stolen password now costs businesses an average of $4.67 million to clean up. And here’s the kicker — 62% of all breaches involve a human doing something they shouldn’t. That’s us. That’s the problem.
The good news? Most of this is fixable with a few simple habits. Here are ten of them.
1. Stop Using Passwords. Start Using Passphrases.
The old advice — uppercase, lowercase, number, special character — has been thoroughly debunked. Why? Because we all end up doing the same predictable things: Password1!, Fluffy2024!, qwerty@99. Hackers know this. Their software knows this.
The new gold standard, recommended by the UK’s own National Cyber Security Centre (NCSC), is the three random words approach. Something like vanilla-reopen-splashy or octopusboxcarhat. Long, random, but actually memorable. Length gives you far more protection than complexity ever did.
Just make sure the words are actually random — not your dog’s name, your favourite team, or your mum’s maiden name. All of that is probably sitting on your Facebook profile waiting to be harvested.
2. Use a Password Manager (Seriously, This One’s Non-Negotiable)
Even the best passphrase is useless if you’re using the same one on every site. One breach somewhere obscure, and suddenly your email, your bank, your everything is wide open. That’s called credential stuffing, and it’s rampant.
The fix is a password manager. It generates a unique, random, nearly-impossible-to-crack password for every single site you use, stores them all safely, and fills them in automatically. You only ever need to remember one master passphrase.
What to use:
- Bitwarden — Open source, free, and trusted. This is the one I’d point most people to.
- 1Password — Slick, polished, great for families. £35/year.
- Dashlane — User-friendly with a decent free tier.
A note on Apple Passwords: If you’re on an iPhone or Mac, you’ve probably noticed Apple has its own built-in password manager. It’s not bad — but it has some real limitations worth knowing about. First, it’s tied entirely to your iCloud account, which means if your Apple ID gets compromised, so does every password you own. Second, it’s awkward to use on anything outside the Apple ecosystem — the Windows app exists but it’s pretty basic, and Android support is essentially non-existent. If you live exclusively in Apple-land and never touch a Windows or Android device, it’s a reasonable option. For everyone else, a dedicated manager like Bitwarden keeps your passwords in a separate, independently encrypted vault that works everywhere.
Avoid storing passwords in your browser alone — it’s convenient, but it’s the first thing targeted if your device is compromised.
3. Turn On Two-Factor Authentication — But Not the Rubbish Kind
Multi-Factor Authentication (MFA) means even if someone has your correct password, they still can’t get in without a second thing — usually your phone. Microsoft’s own data says phishing-resistant MFA blocks over 99% of identity-based attacks. That number should be enough on its own.
But not all MFA is equal. Here’s the honest breakdown:
- SMS codes (texts) — Better than nothing, but they can be intercepted via SIM-swapping. Still, 41% of people rely on these. Don’t make it your only method.
- TOTP (Time-Based One-Time Passwords) — This is what authenticator apps like Aegis (Android), Raivo OTP (iPhone), or Authy generate: a six-digit code that refreshes every 30 seconds. Rated as high security and a big step up from SMS. The one weakness is that a very fast, live attacker can technically intercept that code in real time and use it in the same 30-second window — but in practice this is a sophisticated, targeted attack, not something most people need to lose sleep over. For most accounts, a TOTP app is absolutely good enough.
- Passkeys / FIDO2 hardware keys — The best. A physical key like a YubiKey (from around £25) is practically unphishable. There are now 5 billion passkeys in use worldwide. Google, Apple, Microsoft all support them. If you want the gold standard, this is it.
If you do nothing else from this list, enable MFA on your email. Your email is the master key to everything else.
4. Modern Phishing Is Frighteningly Good. Know What to Look For.
Phishing used to be easy to spot — dodgy spelling, generic greetings, obvious fakes. That era is over. As of 2025, 82.6% of phishing emails are AI-generated. They’re grammatically perfect, personally targeted, and written in your own language.
The numbers are wild: 3.4 billion phishing emails are sent globally every single day. According to Verizon’s own data, the median time for someone to click a malicious link is just 21 seconds after opening the email.
New threats to watch out for:
- Quishing — QR codes in emails that bypass your spam filter and redirect you to a dodgy site when scanned on your phone. Up 400% in two years.
- Vishing — Fake phone calls. Attackers can now clone someone’s voice from a short clip of audio pulled from a YouTube video, conference recording, or voicemail. A finance worker in Hong Kong was convinced to transfer $25.6 million this way.
Rule of thumb: If something creates urgency — “Act now”, “Your account will be suspended”, “Urgent transfer required” — slow down. Verify via a different channel before doing anything.
5. What You Post Online Can Be Used Against You
Every seemingly harmless post on social media is a potential data point for someone building a profile on you. Criminals use a technique called the Mosaic Effect — piecing together little fragments of public information to build something far more dangerous.
Your boarding pass photo reveals your frequent flyer number and travel dates. Your pet’s name answers a security question. Your check-in at a restaurant tells someone your house is empty.
Quick wins:
- Set your social profiles to private
- Turn off live location sharing on posts
- Remove your date of birth from public view
- Be wary of “fun” quizzes asking for your first pet’s name, first car, etc. — those are literally the answers to your security questions.
6. Update Your Stuff. Immediately. Always.
Boring advice, I know. But in 2026, vulnerability exploitation overtook stolen passwords as the number one way hackers break in — accounting for nearly a third of all breaches.
Here’s the thing: most of these attacks don’t rely on secret, cutting-edge exploits. They target known vulnerabilities that have had patches available for months or years. The median time for organisations to patch a critical flaw? 43 days. That’s a 43-day open window that attackers actively exploit.
The fix couldn’t be simpler: turn on automatic updates for your phone, laptop, apps, and router. Take the decision out of your hands entirely.
7. Public Wi-Fi Is a Trap. Use a VPN.
That free Wi-Fi at the coffee shop, airport, or hotel? Totally unencrypted in many cases. Anyone with basic tools can sit nearby and intercept everything you’re sending — login details, emails, messages.
Worse, attackers set up fake hotspots (“Evil Twins”) that look identical to the real one. You connect thinking you’re on the café network; you’re actually handing your data directly to them.
The solution is a VPN (Virtual Private Network), which creates an encrypted tunnel so even if someone intercepts your traffic, it’s completely unreadable.
What to use:
- ProtonVPN — Swiss-based, privacy-first, open source, has a genuinely usable free tier. My top recommendation.
- Mullvad — Ultra-private, doesn’t even require an email address to sign up. €5/month flat.
- NordVPN — The most mainstream option. User-friendly, fast, well-reviewed.
What to avoid: Any VPN you’ve never heard of offering “free unlimited” access. Free VPNs often make money by selling your browsing data to the very people you’re trying to avoid.
And while we’re here — don’t do online banking or enter important passwords over public Wi-Fi, even with a VPN. Just wait until you’re somewhere you trust.
8. Back Up Your Data Offline — Ransomware Is Everywhere
Ransomware is exactly what it sounds like: malicious software that locks all your files and demands payment to unlock them. It’s in 48% of all data breaches now. Even if you never pay (and 69% of victims now refuse to), you still lose your data if you haven’t backed it up properly.
Here’s the critical bit most people miss: modern ransomware actively hunts for your backups. It’ll encrypt your external hard drive if it’s plugged in. It’ll encrypt your synced cloud folder (Dropbox, Google Drive, OneDrive) if it’s connected.
The only truly safe backup is one that’s physically disconnected when you’re not actively using it:
- An external hard drive that you plug in, back up, and unplug
- A cloud backup service with versioning and immutable storage (so old versions of files can’t be overwritten or deleted by ransomware)
Back up regularly. Test that your backups actually restore. If ransomware hits, you wipe the device and restore — and the attacker gets nothing.
9. Some “Security” Software Is Actually Spying on You
This one stings a bit. The very tools sold to protect your privacy can be the ones violating it.
Avast — yes, the free antivirus millions of people use — was taken to court by the US Federal Trade Commission (FTC) for covertly collecting and selling users’ detailed browsing histories to marketing companies. Despite promising to block trackers, they were the trackers. The FTC fined them $16.5 million and banned them from selling browsing data.
They’re not alone. X-Mode, Kochava, InMarket, and Mobilewalla were all investigated for selling precise location data — sometimes revealing where people lived, worshipped, or sought medical care.
Better alternatives:
- Windows Defender (built-in on Windows) — independent testing labs consistently rate it at 99%+ effectiveness. It’s free, it’s already there, and it doesn’t sell your data.
- Malwarebytes — Excellent as a secondary scanner. Free version available.
- Bitdefender — Strong protection, good privacy reputation.
More broadly: reject non-essential cookies, restrict app location permissions to “while in use” only, and use browser extensions like uBlock Origin to block trackers.
10. Always Check You’re on HTTPS
Any website that handles your information — login, payment, contact form — should be running on HTTPS (the padlock in your browser). This encrypts the connection between you and the site, so no one in the middle can read or tamper with it.
The good news: around 90% of websites now use HTTPS by default, and modern browsers like Chrome will prominently warn you if a site is “Not Secure.” 97% of users now actively avoid sites with that warning — and rightly so.
As a web developer I’d add: if you’re visiting a site that doesn’t have HTTPS in 2026, that’s a red flag about how seriously they take security full stop.
You can go one step further and enable HTTPS-Only Mode in your browser settings (available in Firefox and Chrome). It blocks any accidental connections to unencrypted sites automatically.
The Short Version
None of this needs to be overwhelming. If you start with just three things today, make it these:
- Set up Bitwarden and start saving unique passwords for every site.
- Enable MFA on your email and most-used accounts.
- Turn on automatic updates on every device you own.
The rest can follow. The internet isn’t going anywhere, and neither are the people trying to exploit it — so a little bit of hygiene goes a very long way.
If you’ve got questions about any of this, feel free to get in touch. This is exactly the kind of thing I care about — not just building good websites, but making sure people can use the internet safely.
This kind of thing takes time to research and write properly, and it’s free to read — if it’s saved you a headache, you can buy me a coffee. Never expected, always appreciated.