CYBER WELFARE

Protect your Digital Privacy

Security and Privacy Settings: The Half Hour Worth Spending

Additional resource for the lesson “Security and Privacy Settings: A Half Hour Well Spent” — Online Security course

Every service you use has security and privacy settings you accepted by default and have never opened since. Most of the protection available to you is already there, switched off, waiting in a menu you have not visited.

A. Why this matters

Email, social accounts, cloud storage, the apps you use daily: each of them ships with defaults chosen to get you started quickly, not to protect you particularly well.

The good news is that the protection is already there. Login alerts, session management, recovery options, visibility controls — all built in, all free, and all off or set generously until you change them.

The key idea: this is the highest return available for half an hour, because you are not adding anything. You are turning on what you already have.

B. Key concepts

Six things to look for, in every service that has them.

Recovery options

The email address and phone number a service uses to let you back in.

Why it matters to you: Check these first. People routinely find an address they no longer control, which means the recovery route is either broken or belongs to someone else.

Login alerts and activity

Notifications when a new device signs in, and a list of recent sessions.

Why it matters to you: The alert tells you something happened; the session list lets you end it. Together they turn a silent compromise into something you can act on within minutes.

Active sessions and devices

Everywhere your account is currently signed in.

Why it matters to you: Old phones, work computers, a friend’s laptop. Signing out the ones you do not recognise takes seconds and is worth doing periodically.

Connected applications

Third-party services you granted access to, sometimes years ago through a ‘sign in with’ button.

Why it matters to you: This list is usually longer than expected, and much of it is no longer used. Each entry is standing access to your account.

Privacy and visibility

Who can see what you post, what is public by default, what is used for advertising.

Why it matters to you: Not security in the strict sense, but it is the raw material for the personalised attacks the phishing and password resources describe.

Data retention and download

What a service keeps, for how long, and your right to see or delete it.

Why it matters to you: Downloading your own data once is a genuinely clarifying exercise. It shows what has accumulated more effectively than any policy document.

C. A practical example: thirty minutes on one account

Someone opens the security page of their main email account for the first time in years.

  • The recovery address is an old work email they lost access to when they changed jobs.
  • Three sessions are active: the phone, a laptop, and a device in another city from eighteen months ago.
  • Fourteen applications have standing access, including a photo editor used once in 2019.
  • Login alerts are available and switched off.

Nothing here indicates a compromise. It is simply what accumulates when a settings page is never revisited.

Thirty minutes later

  • Recovery address updated to one they control, and a recovery phone added.
  • The unfamiliar session ended, and the others reviewed.
  • Eleven of the fourteen connected apps revoked.
  • Login alerts on.

No new tools, no subscriptions, nothing installed. Half an hour spent inside settings that were already there.

D. Try it yourself: one account, six checks

Start with your primary email. If you only ever do this once, on one account, that is the right one.

Step 1 — Recovery options

  • Is the recovery email one you still control? Is the recovery phone current?
  • Fix these before anything else: they are how you get back in.

Step 2 — Active sessions

  • Review everywhere the account is signed in.
  • End anything you do not recognise, and anything on a device you no longer own.

Step 3 — Connected applications

  • Revoke everything you do not actively use.
  • If in doubt, revoke it — a service you still need will simply ask again.

Step 4 — Login alerts

  • Turn on notifications for new sign-ins.
  • This is the single most useful setting on the page.

Step 5 — Two-factor authentication

  • If it is not on, this is the moment. The resources on authentication cover the choice of method.

Step 6 — Privacy and visibility

  • Check what is public by default, and what is used for advertising.
  • Adjust to what you would actually choose, rather than what was set for you.

Then repeat on one more account next week. Doing six accounts in one sitting is how this becomes a task nobody finishes.

E. Videos, articles and further resources

Independent and institutional sources in English.

NCSC (UK) — Top tips for staying secure online
The essentials from the UK national authority, most of which are settings rather than tools.
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online

CISA — Secure Our World
The US cyber security agency’s public programme: four basic actions, explained for people who are not IT professionals.
https://www.cisa.gov/secure-our-world

FTC — Online privacy and security
Consumer guidance on privacy and security settings, including what to review and why.
https://consumer.ftc.gov/identity-theft-and-online-security/online-privacy-and-security

Google Safety Center — Security tips
The security checkup for Google accounts, which walks through most of the six checks above. Platform documentation.
https://safety.google/security/security-tips/

Electronic Frontier Foundation — Surveillance Self-Defense
A deeper guide for anyone who wants to go further than the defaults.
https://ssd.eff.org/

National Cybersecurity Alliance — StaySafeOnline resources
Practical material on strong passwords, multi-factor authentication and recognising scams.
https://staysafeonline.org/resources/

Links checked in August 2026. Each service documents its own settings; the pattern above transfers between them.

F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior

This lesson sits on the Skills pillar at level FL2. It is procedural, and the procedure transfers across every service.

Skills

  • Finding the security and privacy pages on any service.
  • Reviewing recovery options, active sessions and connected applications.
  • Turning on login alerts and adjusting visibility deliberately.

For professionals and organizations

  • Making a settings review part of onboarding, rather than something people discover after an incident.

Awareness

  • Understanding that defaults are chosen for ease of setup, not for protection.
  • Recognising that connected applications accumulate silently.
  • Knowing that a broken recovery route is a problem you only discover at the worst moment.

For future instructors and ambassadors

  • Doing this live on one account. Everyone finds something, which is what makes the lesson land.

Secure Behavior

  • Reviewing the settings of critical accounts once or twice a year.
  • Revoking access for applications no longer in use.
  • Keeping recovery options current, especially after changing job or phone number.

For organizations

  • Reviewing third-party access to company accounts on a regular cycle.

G. Questions to sit with

  1. Is the recovery address on your main email one you still control?
  2. How many applications have standing access to your accounts? When did you last look?
  3. Would you know if someone signed into your email right now?
  4. When did you last open the privacy settings of the service you use most?

H. What to do now

The recommendations (R) and security measures (MS) from the Cyber Welfare database that live inside account settings.

The security page

  • R4 — Turn on multi-factor authentication.
  • R8 — Turn on login attempt limits and alerts for new sign-ins.
  • R1 and R2 — Unique credentials, held in a password manager.
  • MS17 — Give the email linked to your bank the strongest settings of all.

The privacy page

  • MS6 — Set social accounts to private.
  • MS7 — Restrict who can see your photos, posts and older content.
  • R31 — Limit the use of ‘sign in with’ across unrelated services, which is what fills the connected apps list.
  • R32 — Turn off location tagging.

Minimum commitment: The connected applications list is the one most people have never opened, and usually the most surprising.

In short

  • Most of the protection you need is already built in and switched off.
  • Check recovery options first: they are how you get back in.
  • Login alerts are the highest-value setting on the page.
  • Connected applications accumulate silently — revoke what you no longer use.

Related resources in this course

The settings this connects to:

Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.

If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.

→ Join the Cyber Welfare Program