CYBER WELFARE

Protect your Digital Privacy

Online Security Basics: The ABC You Actually Need

Additional resource for the lesson “Two-Factor Authentication: Why It Is Now Standard” — Online Security course

Security advice arrives as a long list, and a long list is how people do nothing. Online security basics come down to four things — and knowing which four, in which order, is more useful than knowing forty.

A. Why this comes first

This resource is the entry point to the course. It does not try to cover everything — it tries to identify what matters most, so that everything after it has somewhere to attach.

The problem with security advice is not that it is wrong. It is that there is too much of it, presented flat, with no indication of what to do first. Faced with forty recommendations of apparently equal weight, most people do none.

The key idea: four changes prevent the large majority of what actually happens to individuals. Everything else in this course refines them or handles a specific case.

B. Key concepts

Four changes, then two ideas that explain why these four.

One: a different password everywhere

A password manager, generating a unique credential for each account.

Why it matters to you: This is first because reuse is what turns somebody else’s breach into your problem — and breaches happen to companies, not to you, so you cannot prevent them.

Two: a second factor on your email

Multi-factor authentication, starting with the account that can reset the others.

Why it matters to you: Second because it makes a stolen password insufficient. And email first because it is the account with leverage over everything else.

Three: automatic updates

On the phone, the computer, and the browser.

Why it matters to you: Third because it costs nothing after the first configuration, and because published fixes also publish the flaws they close.

Four: a backup that works

A copy of what matters, with one copy disconnected, tested once.

Why it matters to you: Fourth because it is the only measure that helps after something has already gone wrong.

Why these four

They address the routes by which people actually lose accounts and data: reuse, credential theft, unpatched software, and irreversible loss.

Why it matters to you: They are not the only things that matter. They are the ones with the highest ratio of protection to effort, which is a different and more useful criterion.

Digital identity

The set of accounts and information that represents you online, and what someone could do while holding it.

Why it matters to you: This is the thing all four protect. Naming it is what makes the four feel connected rather than arbitrary.

C. A practical example: how it usually goes wrong

The common sequence, which involves no sophistication at any point:

  • A service you signed up for years ago is breached. Your address and password circulate.
  • The same combination is tried automatically on major services.
  • It works on your email, because the password was reused.
  • From the mailbox, other accounts are reset — the links arrive there.
  • You discover it when something stops working.

Where each of the four would have stopped it

  • A unique password: the breach stays at the breached service.
  • A second factor on email: the correct password is not enough.
  • Updates: relevant to a different route in, but the same principle.
  • A backup: relevant if data is lost rather than an account, and the reason it is on the list.

Notice that nobody targeted anyone. This is the ordinary path, and it is why the first two changes come first.

D. Try it yourself: four things, one week

One per day would finish this in four days. The order matters more than the pace.

Day one — the password manager

  • Choose one, create a strong master passphrase, turn on its own second factor.
  • Move three accounts into it: email, bank, main social.

Day two — the second factor on email

  • An authenticator app rather than SMS where offered.
  • Save the backup codes somewhere you can reach without your phone.

Day three — updates

  • Automatic updates on: phone, computer, browser, app store.
  • Restart everything, so anything pending actually completes.

Day four — the backup

  • Automatic backup for phone and computer.
  • One copy on a drive that stays disconnected.
  • Restore one file, to confirm it works.

After these four, the rest of this course is refinement. Each resource takes one of them further or handles a situation the four do not cover.

E. Videos, articles and further resources

Independent and institutional sources in English, all of which take the same approach of prioritising.

NCSC (UK) — Top tips for staying secure online
The UK authority’s short list for individuals. It overlaps almost exactly with the four above, which is reassuring.
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online

CISA — Secure Our World
The US agency’s public programme, built around four basic actions for the same reason.
https://www.cisa.gov/secure-our-world

NCSC (UK) — Cyber security advice for you and your family
The UK national authority’s advice hub for individuals: short, practical guidance written for people who are not IT professionals.
https://www.ncsc.gov.uk/section/advice-guidance/you-your-family

Electronic Frontier Foundation — Surveillance Self-Defense
For going further: a guide that starts from your situation rather than from a generic list.
https://ssd.eff.org/

National Cybersecurity Alliance — StaySafeOnline resources
Practical material on strong passwords, multi-factor authentication and recognising scams.
https://staysafeonline.org/resources/

FTC — Online privacy and security
Consumer-facing advice on protecting your identity, securing your home network and browsing safely.
https://consumer.ftc.gov/identity-theft-and-online-security/online-privacy-and-security

Links checked in August 2026.

F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior

This lesson sits at level FL1 on the Awareness pillar. Its job is orientation: knowing what matters most, before knowing how anything works.

Skills

  • Setting up a password manager, a second factor, automatic updates and a backup.
  • Knowing which account to protect first and why.

For professionals and organizations

  • Communicating a short, ordered list rather than a comprehensive policy nobody reads.

Awareness

  • Understanding that most incidents follow an ordinary path rather than a sophisticated one.
  • Recognising that breaches happen to companies, which is why reuse is the decisive habit.
  • Knowing that a long list of equal-weight advice produces no action.

For future instructors and ambassadors

  • Resisting the urge to be comprehensive. Four things done beat forty things listed.

Secure Behavior

  • Doing the four, in order.
  • Returning to the rest of the course for refinement afterwards.

For organizations

  • Providing the tools — a password manager, a second factor — rather than recommending them.

G. Questions to sit with

  1. Which of the four have you already done?
  2. If your password from an old, forgotten service appeared online tomorrow, how many accounts would open with it?
  3. Is your primary email protected by a second factor?
  4. Have you ever recovered a file from your backup?

H. What to do now

The recommendations (R) and security measures (MS) from the Cyber Welfare database, ordered as above.

One and two: credentials and the second factor

  • R1 — Do not reuse passwords across accounts.
  • R2 — Use a reliable password manager.
  • R3 — At least 16 characters, generated.
  • R4 — Multi-factor authentication, starting with email.
  • MS1, MS2 — Generate and autofill.

Three and four: updates and backup

  • R6 — Automatic updates on every device.
  • R19 — A periodic backup, with one copy disconnected.

Then, when the four are done

  • R5, R7, MS4 — Device lock and a short timeout.
  • R9, R17 — HTTPS, and caution with unexpected attachments and links.
  • R8 — Login alerts where services offer them.

Minimum commitment: These are the natural next layer, and each has its own resource in this course.

In short

  • Four changes cover most of what actually happens: unique passwords, a second factor on email, automatic updates, a working backup.
  • The order matters, because reuse is the habit that turns someone else’s breach into yours.
  • Nothing in the common sequence requires a sophisticated attacker.
  • Everything else in this course refines these four or handles a specific case.

Where to go next

The four, in order:

Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.

If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.

→ Join the Cyber Welfare Program