Additional resource for the lesson “Navigating the Digital World: An Introduction to Online Security” — Online Security course
Before you change a single password, it is worth taking a calm look at how much of your life already happens online. This resource helps you map your digital life — the accounts, devices and habits you actually rely on — so that the protection you put in place goes where it matters most.
A. Why this comes first
This lesson asks you to pause and look closely at your digital life before touching any settings. Four questions are enough to start:
- How much time do you spend online on a normal day?
- How many services and accounts do you actually use?
- How much do you depend on email, chat, social media and cloud storage?
- How would you feel if you lost access to one of them?
The key idea: before advanced security techniques come into play, it helps to understand how closely the digital world is woven into your personal and working life.
That understanding is what lets you decide where to concentrate your protection, which accounts are genuinely critical, and which habits are worth changing. Without it, security advice stays abstract — a list of things you should do, with no way to tell which one to do first.
B. Key concepts
Eight ideas that come back throughout the course. Each one is followed by what it changes for you in practice.
Digital presence
Everything you do and leave online: accounts, posts, photos, comments, purchases, searches.
Why it matters to you: It shows you there is no such thing as “just one account”. Every digital trace contributes to how you are seen and to your level of exposure.
Digital identity
The set of data that identifies you online: email address, name, username, phone number, uploaded documents, bank details, national digital identity schemes (SPID or CIE in Italy, comparable systems elsewhere).
Why it matters to you: Whoever controls your digital identity can act as you: open accounts, make purchases, or approach other people in your name.
Personal attack surface
The full set of points through which your digital life could be reached: accounts, apps, devices, connected services.
Why it matters to you: The more unused or forgotten accounts you keep, the larger that surface. Seeing it clearly is what makes closing old accounts feel worth the effort.
Critical accounts
The accounts that would have a real impact on you if someone else controlled them: your primary email, online banking, national digital identity, cloud storage holding your documents, work accounts.
Why it matters to you: They let you set priorities. Not every account deserves the same attention — but a few of them deserve considerably more.
Digital habits
The things you repeat without thinking: tapping links, signing in on public Wi-Fi, reusing a password, accepting contact requests.
Why it matters to you: Many threats work precisely because these actions are automatic. Noticing them is the first step to changing them, and noticing costs nothing.
Digital resilience
Your ability to withstand a digital problem and recover from it: a stolen account, lost data, malware.
Why it matters to you: The goal is not only to avoid incidents but to get back on your feet quickly — backups, a recovery route for your accounts, someone you can contact.
Privacy by default
Setting up an account so that it shares the minimum necessary from the start, rather than opening up and tightening later.
Why it matters to you: It limits how much of your information is exposed even on the days you forget to check every single setting.
Multi-factor authentication (MFA)
A sign-in method that asks for two or more proofs of identity — typically your password plus a code from an app, or a hardware security key. Passkeys, now supported by most phones and computers, are a newer form of the same idea: the proof stays on your device, and there is no password to steal.
Why it matters to you: Even if someone works out your password, they still cannot get in without the second factor.
C. A practical example: a day in Anna’s digital life
Anna is 34 and works remotely in marketing.
- She wakes up and checks WhatsApp, Instagram and her personal email.
- She opens her laptop and signs in to her work email, Teams, an HR platform for payslips and several cloud tools.
- Through the day she also uses three online shops, a banking app, two expense apps and three cloud services for sharing documents.
On an ordinary day, Anna signs in to more than twenty accounts. She has never counted them.
The afternoon it stops working
One afternoon Anna can no longer get into her personal email.
- The password no longer works.
- The recovery address is an old account she has not opened in years.
- That same email address is the one linked to her social media, her cloud storage and several shops.
What follows is not dramatic, but it is genuinely difficult:
- She cannot reset the passwords on other services, because every reset link arrives in the mailbox she has lost.
- Someone starts messaging her contacts in her name.
- She feels anxious about the photos and documents she may not get back, and awkward about explaining it to colleagues and friends.
What would have changed the outcome
- Knowing in advance which accounts were critical — primary email, bank, cloud.
- Having multi-factor authentication switched on for those accounts (R4, MS17).
- Using a password manager, with a different password for each account (R1, R2, R3, MS1, MS2).
- Keeping a periodic backup of the data that mattered (R19).
None of these is a technical feat. What makes the difference is simply having thought about it once, before the afternoon it stops working.
D. Try it yourself: map your digital life (10–15 minutes)
Four short steps. You can do them on paper, in a note on your phone, or in the fields provided on the lesson page.
Step 1 — Count your daily sign-ins
- How many devices do you use on a normal day? (phone, computer, tablet, other)
- Roughly how often do you pick up your phone to check notifications, messages or social media?
- On how many sites or apps do you type a password on a normal day?
Step 2 — List your main accounts
- Fill in the table below, adding the accounts that come to mind.
- Mark “High” next to any account that would cause real problems if you lost it — access to work, to money, or to personal documents.
- There is no right number. Most people find more than they expected.
| Category | Your accounts | Criticality (High / Medium / Low) |
|---|---|---|
| Social media | ||
| Bank and payments | ||
| Cloud and documents | ||
| Work | ||
| Shopping | ||
| Other |
Step 3 — Impact and emotions
- If you lost access to your primary email, how much harder would your week become?
- If a stranger got into the social account you use most, what would concern you first?
- If someone could see the photos in your private cloud, how would that feel?
Step 4 — One concrete decision
- Turn on multi-factor authentication for at least one critical account.
- Change the password of one important account to something long and unique.
- Close one account you no longer use.
Pick one of the three actions in Step 4 and save it as your commitment for today. One is enough — a decision you actually carry out is worth more than a list you never start.
E. Videos, articles and further resources
Independent, non-commercial sources, all available in English. They cover the same ground as this lesson in more depth.
Electronic Frontier Foundation — Surveillance Self-Defense
A well-organised guide to protecting your data and communications, starting from your own situation rather than from a generic checklist.
https://ssd.eff.org/
NCSC (UK) — Top tips for staying secure online
Six short pieces of advice for individuals from the UK’s national cyber security authority. A good starting point if you want the essentials without the jargon.
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online
CISA — Secure Our World
The US cyber security agency’s public awareness programme: four basic actions, explained for people who are not IT professionals.
https://www.cisa.gov/secure-our-world
National Cybersecurity Alliance — StaySafeOnline resources
Practical material on strong passwords, multi-factor authentication and recognising scams.
https://staysafeonline.org/resources/
Federal Trade Commission — Online privacy and security
Consumer-facing advice on protecting your identity, securing your home Wi-Fi and browsing safely.
https://consumer.ftc.gov/identity-theft-and-online-security/online-privacy-and-security
Google Safety Center — Security tips
Tools and short videos on privacy settings and account management. Useful if most of your digital life runs through a Google account.
https://safety.google/security/security-tips/
ConnectSafely — Parent and educator guides
Clear guides on social media privacy and digital citizenship, helpful if you are also supporting children or students.
https://www.connectsafely.org/guides-2/
Links checked in August 2026. If one of them has moved, searching the title on the organisation’s own site will usually find it.
F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior
This lesson supports growth across the three pillars of the Cyber Welfare Framework. It sits mainly at level FL1, where the work is orientation rather than technique.
Skills
- Mapping your own accounts and telling the critical ones from the rest.
- Understanding what digital identity and personal attack surface mean in your own case.
- Estimating, in simple terms, what losing an account would cost you: data, reputation, work.
For professionals and organizations
- Connecting personal habits to the organization’s own security and privacy policies.
- Identifying the critical business accounts — ERP, CRM, HR systems — that need stronger protection than the rest.
Awareness
- Recognising that your digital life is wider than it feels: more accounts, more apps, more devices than you would have guessed.
- Noticing the attachment you have to some accounts — photos, memories, contacts — and what a loss would actually mean.
For institutions and future instructors
- Recognising that human error usually grows out of unexamined personal habits, not carelessness.
- Learning to guide someone else through this kind of self-assessment with fair questions, without judgement, and with improvement as the goal.
Secure Behavior
- Deciding to reduce your attack surface: closing unused accounts, simplifying where you can.
- Setting priorities out loud: “these three accounts are critical — they get MFA, stronger passwords and a periodic check.”
- Building small daily habits: checking your devices, applying updates, pausing before you tap.
For organizations
- Making room for guided reflection in internal training, not only technical checklists.
- Building a culture where talking about mistakes and near misses is normal, because that is how everyone improves.
G. Questions to sit with
No right answers. They are here to help you decide what to do first.
- Which account, if you lost it today, would cause you the most real trouble? What could you do about it before tonight?
- How many of your passwords are reused or near-identical? Would you change one of them now?
- Have you ever thought about a plan B if you lose access to your primary email? Who could help? How would you recover the services that depend on it?
- Which of your digital habits feels riskiest to you — tapping links quickly, signing in on public Wi-Fi, accepting requests from people you do not know? What could you change starting tomorrow?
- If you had to explain to a friend in one sentence why this matters, what would you say?
H. What to do now
The recommendations (R) and security measures (MS) from the Cyber Welfare database that apply most directly to this lesson. Each group ends with a minimum commitment: the smallest useful step, not the complete one.
1. Accounts and passwords
- R1 — Do not use the same, or nearly the same, password across your accounts.
- R2 — Use a reliable password manager to store your credentials, protected by a strong and unique master password.
- R3 — Make your passwords at least 16 characters long, combining numbers, upper and lower case letters and symbols.
- R4 — Turn on multi-factor authentication, ideally with an authenticator app or a hardware security key rather than SMS.
- MS1 — Let the password manager generate your passwords rather than inventing them yourself.
- MS2 — Let the manager fill them in automatically: fewer typing errors, and less exposure to fake sign-in pages.
- MS17 — Give the email address linked to your bank account a unique, strong, randomly generated password and mandatory MFA.
Minimum commitment: Choose one critical account — primary email, bank or work — and apply R1, R3, R4 and MS1/MS2 to it today. Just one.
2. Devices and access
- R5 — Set a six-digit PIN on your mobile devices.
- R6 — Keep your software up to date, with automatic updates on wherever possible.
- R7 — Set your screen to lock after the shortest interval you can live with.
- MS3 — Prefer a passcode over pattern unlock, and consider how you use biometrics on shared or high-risk devices.
- MS4 — Use an alphanumeric passcode of 8 characters or more on the phone you rely on most.
Minimum commitment: Today, check the lock screen, PIN and update settings on the phone you use most. It takes about two minutes.
3. Browsing and connections
- R9 — Make sure you are connecting to sites over HTTPS.
- R10 — Avoid reaching sensitive services, such as your bank, over public Wi-Fi.
- R11 — Use a VPN when you need to handle confidential information away from a network you trust.
- MS5 — Use a browser that treats privacy as a default rather than an option.
- MS10 — For a more advanced home setup, configure a VPN at router level.
Minimum commitment: Get into the habit of glancing at the padlock before you type credentials — and keep online banking off public Wi-Fi.
4. Social media and online identity
- R23 — Add and follow people you actually know.
- R24 — Avoid posting photos that contain QR codes.
- R31 — Limit the use of “sign in with Facebook / Google” across unrelated services.
- R32 — Turn off location tagging on your phone’s camera.
- MS6 — Set your social accounts to private.
- MS7 — Review who can see your photos, posts and older content.
- MS12 — Search for your own phone number online and request removal where it has been published.
- MS13 — Register with the national do-not-call list where one exists (in Italy, the Registro delle Opposizioni).
Minimum commitment: Spend ten minutes today on three things: make one social account private, turn off location tagging, and remove contacts you do not recognise.
In short
- Awareness — you now have a rough picture of how wide your digital life is: how many accounts, how much time, how much dependency.
- Assessment — you have asked what losing a critical account would actually cost, which is what makes security concrete rather than theoretical.
- Action — you start with a few specific steps: MFA, stronger passwords, a locked device, tighter social settings.
The point of this lesson is not to worry you. It is to give you a way of looking at your own digital habits, so that you can turn them into something steadier, one step at a time.
Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.
If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.




Leave a Reply