Additional resource for the lesson “The Final Step: Why Logging Out Matters” — Online Security course
Signing in carefully and then walking away leaves the session open behind you. Knowing how to log out of your accounts — and, more usefully, how to end sessions you left open somewhere else — is the step almost everyone skips.
A. Why this matters
Signing in is only half of it. A session stays open until it is closed — by you, or eventually by the service, sometimes months later.
That matters most in two situations: on a device you do not control, and on devices you used once and forgot. Both are more common than they sound. A library computer, a hotel business centre, a work laptop you returned, a friend’s tablet.
The key idea: closing the browser is not logging out. The session usually survives it, and reopening the browser resumes exactly where you were.
B. Key concepts
Six ideas, including the one that solves the problem retroactively.
Logging out
Ending the session deliberately, using the service’s sign-out option.
Why it matters to you: It closes the door behind you. Closing a tab or shutting the laptop lid does not.
Computers in libraries, schools, hotels, internet points, coworking spaces, and any borrowed device.
Why it matters to you: Here logging out is not a precaution but a requirement. The next person to sit down inherits whatever you left open.
Sessions on your own devices
Every device where you are currently signed in: phone, laptop, tablet, an old phone in a drawer.
Why it matters to you: These accumulate silently. Most people are signed in on at least one device they no longer use.
Sign out everywhere
A setting on most major services that ends every active session at once, everywhere.
Why it matters to you: This is the useful discovery in this lesson. It fixes retroactively every session you forgot to close, and it takes seconds.
History, cookies and anything the browser offered to remember.
Why it matters to you: On a public computer, private or incognito mode is what prevents this accumulating in the first place — worth using before, rather than clearing after.
Where logging out is not the answer
On your own phone, permanently signing out of everything is impractical and pushes people towards weaker passwords.
Why it matters to you: The proportionate version: stay signed in on your own protected devices, sign out everywhere else, and review the session list occasionally.
C. A practical example: the session list
Someone opens the security settings of their email account and looks at active sessions for the first time.
- The current phone and laptop, as expected.
- A tablet sold two years ago.
- A work laptop returned when they changed jobs.
- A browser session in a city they visited once, from a hotel computer.
None of these indicates anything went wrong. They are simply sessions nobody closed, and services keep them alive for a long time.
The fix, in ten seconds
One button — usually called sign out of all devices or sign out everywhere — ends all of them. The current device asks you to sign in again, and everything else is closed.
This is one of the rare cases where a single action resolves years of accumulated exposure. It is worth doing today and then once or twice a year.
D. Try it yourself: close what is open
Fifteen minutes, and the last step is a habit rather than a task.
Step 1 — Look at your session lists
- Primary email, main social account, cloud storage.
- The setting is usually under Security, called active sessions, devices, or where you are signed in.
Step 2 — Sign out everywhere
- Use the option that ends all sessions at once.
- Have your password manager ready: you will sign back in on the devices you actually use.
- Private or incognito window before you start.
- Sign out explicitly before you stand up.
- Close the window rather than leaving it open.
Step 4 — Decide what stays signed in
- Your own phone and computer, protected by a strong code and a short lock timeout: staying signed in is reasonable.
- Anything else: sign out.
Step 2 is the one with the most immediate effect, and almost nobody has done it. Step 4 keeps the advice realistic — permanent signing out on your own phone is not sustainable and does not need to be.
E. Videos, articles and further resources
Independent and institutional sources in English.
NCSC (UK) — Top tips for staying secure online
Six short pieces of advice from the UK’s national cyber security authority. A good starting point if you want the essentials without the jargon.
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online
FTC — Protect your personal information from hackers and scammers
What to lock down first, including sessions and shared devices.
https://consumer.ftc.gov/articles/protect-your-personal-information-hackers-and-scammers
NCSC (UK) — What to do if your account is hacked
Signing out everywhere is also the first step if you suspect an account is compromised.
https://www.ncsc.gov.uk/section/respond-recover/hacked-accounts
CISA — Secure Our World
The US cyber security agency’s public programme: four basic actions, explained for people who are not IT professionals.
https://www.cisa.gov/secure-our-world
Google Safety Center — Security tips
Where the session list and the sign-out-everywhere option live in a Google account. Platform documentation.
https://safety.google/security/security-tips/
FTC — Online privacy and security
Consumer-facing advice on protecting your identity, securing your home network and browsing safely.
https://consumer.ftc.gov/identity-theft-and-online-security/online-privacy-and-security
Links checked in August 2026. Each service names this setting slightly differently; the pattern is the same everywhere.
F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior
This lesson sits on the Secure Behavior pillar at level FL1: small, concrete, and immediately actionable.
Skills
- Finding the active sessions list on a service.
- Using sign out everywhere and knowing when it is appropriate.
- Using private browsing on a device that is not yours.
For professionals and organizations
- Ending sessions as part of offboarding, rather than relying on people to have signed out.
Awareness
- Understanding that closing a browser does not end a session.
- Recognising that sessions accumulate on devices you no longer own.
- Knowing that sign out everywhere resolves this retroactively.
For future instructors and ambassadors
- Having people open their session list live. The forgotten devices make the point instantly.
Secure Behavior
- Signing out explicitly on any device that is not yours.
- Reviewing session lists once or twice a year.
- Using private browsing on shared computers as a matter of course.
For organizations
- Setting session timeouts on internal systems rather than leaving them indefinite.
G. Questions to sit with
- When did you last look at where your accounts are currently signed in?
- Is there a device you no longer own that might still have an open session?
- On a shared computer, do you sign out, or close the window?
- Would you know where to find sign out everywhere on your main email account?
H. What to do now
The recommendations (R) and security measures (MS) from the Cyber Welfare database that apply to sessions.
Sessions
- R8 — Turn on login alerts, so a new session tells you about itself.
- R7 — Keep the screen lock timeout short on devices where you stay signed in.
- R5, MS4 — A strong device code, which is what makes staying signed in reasonable.
Minimum commitment: Sign out everywhere on your critical accounts today. Then once or twice a year.
Around it
- R2, MS2 — A password manager, so signing back in after ending sessions is trivial.
- R4 — Multi-factor authentication, so a session opened by someone else needs more than a password.
In short
- Closing the browser does not end the session.
- Sessions accumulate on devices you no longer own.
- Sign out everywhere resolves years of this in ten seconds.
- Staying signed in on your own protected phone is reasonable — everywhere else, sign out.
Related resources in this course
Where sessions fit:
- Security and Privacy Settings: The Half Hour Worth Spending
- Device Lock: The Barrier Everything Else Sits Behind
- Map Your Digital Life: Where Your Protection Really Starts
Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.
If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.




Leave a Reply