CYBER WELFARE

Protect your Digital Privacy

Turn on account login alerts: knowing when it happens

The seven earlier recommendations all serve to prevent something from happening. This one serves something different: noticing if it happens anyway.

It is an important change of logic, and it is worth recognising. No protection is total: a password can end up in a breach, a code can be obtained, a device can be left open. When that happens, the difference between a small problem and a large one is not which protection gave way — it is how much time passes before you notice.

What this recommendation says

Recommendation R8 establishes that security notifications should be turned on for every account that offers them, and configured so that they arrive where you will actually see them.

They are alerts the service sends you when something relevant happens to your account:

  • a sign-in from a new device or an unusual location;
  • a change of password or email address;
  • a recovery method added or removed;
  • the second factor turned on or off;
  • a new application connected;
  • repeated failed sign-in attempts.

What it is not. It is not a protection system: the alert blocks nothing. It is a detection system, and its usefulness depends entirely on what you do when it arrives.

Scope. Main email, bank, payment services, social networks, document storage, password vault. In that order of priority.

Why it matters

The value of this recommendation is easiest to see in one number: the time that typically passes between an unauthorised sign-in and the moment the person notices. Without alerts on, that time is measured in weeks or months. With alerts, in minutes.

In the meantime, whoever has access can do everything described in the earlier units: read, send, configure forwarding, add recovery methods, link devices.

BenefitWhy it counts
It shortens the time to discoveryFrom weeks to minutes: it is the main difference
It lets you react while it still helpsRevoking an active session is only possible if you know it exists
It covers the protections that failNo preventive measure is total
It needs no maintenanceYou turn it on once and it works
It builds a reference pointSeeing normal sign-ins teaches you to recognise unusual ones

There is also a less obvious benefit: alerts make what is normal visible. After a few weeks you know what a sign-in of yours looks like — which devices, which times, which cities. It is that reference point that makes the exception recognisable.

A concrete example

Helen receives a notification: “New sign-in to your account from a Windows device, Milan”. She is in Milan, but she only uses a Mac and a phone.

She opens the account’s security section, finds the active session, disconnects it, changes the password. Time spent: six minutes. Damage: none.

Without that alert, the same situation would have stayed invisible until the first obvious effect — an odd message received by a contact, a service that stops working, a charge. In the meantime the session would have stayed active.

The point is not that Helen was particularly attentive. It is that she had the information at the moment it could still be of use.

When to apply it

  • Right now, on your main email. It is the account that allows every other one to be recovered: if it falls, they all fall.
  • On financial services, where the alerts are typically already on but it is worth checking where they go.
  • When you change phone number or email address. The alerts would keep going to the old contact.
  • After an incident, even a merely suspected one: it is when they are needed most.
  • When you turn on a second factor. The two measures work together: one prevents, the other reports.
  • On social networks, where an unauthorised sign-in causes relational damage before technical damage.
  • When you set up a new account. It costs ten seconds then and a great deal more later.

How to apply it

  1. Start from your main email. In the account’s security section look for “alerts”, “security notifications” or “account activity” and turn on everything available.
  2. Check where the alerts arrive. It is the most important step and the most neglected: if your email’s security notifications arrive at that same email, whoever has access sees them before you — and can delete them.
  3. Set a secondary contact for your main account’s alerts: a second address, or better still your phone number.
  4. Turn on notifications on the phone, not only by email. An alert arriving as a notification gets read in minutes; one arriving in a secondary mailbox can wait days.
  5. Repeat for bank, payments, document storage, password vault.
  6. Look at the “connected devices” section of each service while you are there, and disconnect the ones you no longer use.
  7. Do not filter alerts into a folder. It is the natural reaction when there are many, and it is what makes them useless.

Common mistakes to avoid

  • Sending your email’s alerts to that same email. It is the mistake that undoes everything else.
  • Turning them on and then ignoring them. An alert not read is worth the same as an alert not enabled.
  • Archiving them automatically with a rule. It comes from annoyance, it produces blindness.
  • Turning them on only for the services that seem important. A minor account reused to recover an important one counts as important.
  • Not checking the contact after a change of number. The alerts keep going out, they simply do not reach you.
  • Confusing an alert with a block. The alert does not prevent access: it tells you it happened. The reaction is yours.
  • Reacting on impulse to an emailed alert by clicking the links it contains. That is exactly the pattern phishing imitates: you go to the site by typing the address, not from the message.

The alert that was not an alert

It deserves its own paragraph, because it is the most insidious flip side of this recommendation.

Fake security notifications are among the most widespread phishing messages: “we detected a suspicious sign-in, verify your account now”. They exploit exactly the reflex this recommendation builds.

The practical rule is simple and has no exceptions: a security alert is always checked by going to the service yourself, typing the address or opening the app, never from the link in the message. If the alert is real, the information is there. If it is not there, the message was false.

That also makes the opposite mistake harmless: there is no risk in ignoring an alert and checking later, from the app. There is a concrete risk in clicking.

The periodic check: the part alerts do not cover

Alerts report what the service considers unusual. Two categories of thing stay outside, and it is useful to know that because they call for a complementary habit.

Sign-ins that look normal. An entry from an already recognised device, at a plausible time, from a usual network generates nothing. That is the case of somebody who had physical access to your device or your network.

Configurations. A forwarding rule created during a sign-in produces no later sign-ins: the information leaves on its own. There is nothing to report, so nothing arrives.

Both are covered by the same habit: a five-minute check once a month on your three or four main accounts, looking at two lists.

ListWhat to look forWhere it sits
Recent activity / sign-insDevices and times you do not recogniseSecurity section
Connected devicesActive sessions to closeSecurity section
Recovery methodsNumbers or addresses you did not addRecovery section
Forwarding rulesAny rule you did not createMail settings
Connected appsAuthorised services you do not useSecurity / Apps

The last two rows are the ones no alert will ever show you.

Why a second factor is not enough

A reasonable objection: if I have turned on multi-factor authentication, who gets in without my code?

The second factor is a strong defence, and it remains the most effective measure in this series. But it covers sign-in with credentials, and there are routes that do not pass through there:

  • a session already active on a device left open or stolen;
  • a connected application, which operates with an authorisation of its own and does not ask for the second factor;
  • a recovery procedure completed by whoever controls the email or the number;
  • a code obtained by deception, which is the most widespread phishing pattern today.

In all four cases the second factor worked correctly — it simply was not the point of entry. The alert, on the other hand, sees all of them, because it reports the result, not the method.

That is why prevention and detection are not alternatives: they answer different questions.

How this connects to the Cyber Welfare Framework

PillarHow it contributes
AwarenessUnderstanding that detection is a defence distinct from prevention
SkillsConfiguring where alerts arrive so that it is independent
Secure BehaviourReading alerts and checking them at the service, not from the message

Digital maturity levels.

  • FL1 — Basic. The alerts are whatever the defaults are, or turned off, or landing in an unread folder.
  • FL2 — Beginner. Alerts on for the main email and financial services.
  • FL3 — Autonomous. Alerts on everywhere, arriving somewhere independent of the account they watch.
  • FL4 — Skilled. Every alert gets read and checked at the service; unrecognised sessions get revoked.
  • FL5 — Expert-Guide. You help others set up an independent contact, which is the part almost nobody does alone.

R8 closes the circle opened by R4: the second factor prevents access, the alert tells you when somebody tried.

How to check you are applying it correctly

  1. If somebody signed in to my email account right now, would I get an alert — and where?
  2. Would that alert arrive somewhere whoever has the access does not control?
  3. When did I last look at the list of devices connected to my accounts?

Quick checklist

  • ☐ Alerts on for the main email
  • ☐ Alerts arriving somewhere independent of the account they watch
  • ☐ Notifications on the phone, not only by email
  • ☐ Alerts on for bank, payments and document storage
  • ☐ No rule automatically archiving the alerts
  • ☐ The recovery phone number is up to date
  • ☐ I know an alert is checked from the app, never from the link in the message

For an overall measure of where you stand, you can take the digital resilience self-assessment.

In short

Login alerts do not protect: they inform. It is a different and complementary function, and it covers exactly the space preventive measures leave uncovered — the case where something got through anyway.

The configuration takes a few minutes per account. The part that really counts is a single one: making sure the alert arrives somewhere that does not depend on the account it is watching.

Something to think about. If your email account were open to somebody else right now, how long would it take you to notice?

Explore this recommendation

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.