Preloader spinner
Older couple carefully reviewing information on a laptop at home

Staying safe online does not require you to become a cyber security expert. A small number of habits can make a major difference: protect your email account, use strong unique logins, turn on two-step verification, keep devices updated, slow down when a message creates pressure and independently check unexpected requests before paying money or sharing information.

That last point is becoming increasingly important. Scam emails and messages are no longer always full of obvious spelling mistakes. Criminals can create polished websites, realistic messages and convincing impersonations, so the safest approach is to judge the behaviour of the request, not just how professional it looks.

10 things everyone can do to improve their online security

  1. Protect your email account particularly carefully.
  2. Use a different strong password for every important account, or use passkeys where available.
  3. Turn on two-step verification.
  4. Use a reputable password manager rather than reusing memorable passwords.
  5. Install software and device updates promptly.
  6. Use screen locks and device security features.
  7. Back up important photos and files.
  8. Be cautious with unexpected links, QR codes and attachments.
  9. Verify unusual requests through a separate trusted channel.
  10. Know what to do if an account, card or device is compromised.

Why your email account matters so much

Your email account is often the key to many other online services. Password-reset links, invoices, purchase confirmations and security alerts all arrive there.

If somebody gains control of your email, they may be able to reset passwords for other accounts or impersonate you convincingly.

Use a strong unique login for email and enable two-step verification. If your provider offers a passkey, that can also provide a strong modern sign-in option.

Should you use a password manager?

For most people, yes. A password manager makes it practical to have a different strong password for every service without remembering them all.

The risky alternative is password reuse. If the same password protects your email, shopping and social-media accounts, one compromised service can give a criminal a route into several others.

You should still protect the password manager itself carefully, normally with a strong master password and two-step verification or a passkey.

What is a passkey?

A passkey is a newer way to sign in without relying on a traditional password. It normally uses a trusted device together with a PIN, fingerprint, face recognition or another secure device-authentication method.

Passkeys are designed to be resistant to common phishing attacks because there is no reusable password for you to accidentally type into a fake website.

Where a reputable service offers passkeys, they are worth considering. Where it does not, use a strong unique password and two-step verification.

What is two-step verification?

Two-step verification, also called 2SV or multi-factor authentication, asks for an additional proof of identity as well as your password.

That extra step can stop an attacker from signing in even if they have discovered your password.

Turn it on particularly for:

  • email
  • banking and finance
  • social media
  • cloud storage
  • shopping accounts that store payment information
  • Apple, Google or Microsoft accounts

Keep phones and computers updated

Updates do more than add features. They frequently fix security weaknesses that attackers could exploit.

Enable automatic updates where practical for your phone, computer, browser and important applications. Older devices that no longer receive security updates deserve particular caution.

Only install applications from trusted sources and official app stores wherever possible.

Why scams are becoming harder to spot

Traditional advice often told people to look for spelling mistakes and poor grammar. Those clues can still appear, but they are no longer enough.

Modern criminals can produce well-written messages and copy the design of banks, delivery companies, government departments and well-known websites. AI tools can also make impersonation, translation and content creation easier.

A convincing appearance does not prove that a message is genuine.

The five warning signs of a scam message

The UK's National Cyber Security Centre highlights several psychological techniques that scammers commonly use.

1. Authority

The message claims to come from somebody you are expected to obey or trust, such as your bank, HMRC, the police, a solicitor, your employer or a senior manager.

2. Urgency

You are told that you must act immediately or within a very short deadline.

3. Emotion

The message tries to create fear, excitement, sympathy, curiosity or panic so you react before thinking.

4. Scarcity

You are offered something limited or exclusive and told you will miss out if you do not act now.

5. Current events

The scam uses something topical such as tax deadlines, major news, popular events or delivery periods to make the contact feel plausible.

If one of these techniques appears in an unexpected contact, slow down.

How to check whether a message is genuine

Do not use the contact details supplied in the suspicious message.

If a bank appears to contact you, use the number on your bank card, banking app or official website. If a retailer mentions an order, open the retailer's app or type its normal website address yourself rather than following the link.

If a family member asks for money from a new phone number, contact them using a number or method you already trust.

This independent check is one of the strongest defences against impersonation scams.

Common online scams to watch for

Phishing emails

A phishing email tries to make you click a malicious link, open an attachment, reveal information or make a payment. It may imitate a bank, Microsoft, a delivery company, streaming service, retailer or government organisation.

Smishing or scam text messages

Texts may claim you have missed a parcel, owe a small fee, need to verify a bank transaction or have an unpaid charge. A small believable payment can be used to capture card details or direct you into a wider scam.

Bank impersonation scams

A caller or message claims that suspicious activity has been detected and pressures you to move money to a “safe account”, reveal security codes or approve a payment.

Do not transfer money because somebody claiming to be from a bank tells you to. End the contact and speak to your bank independently.

Fake purchase and marketplace scams

Criminals advertise goods that do not exist, pressure buyers to pay outside the normal marketplace or send fake payment confirmations to sellers.

Stay within the platform's normal payment and messaging system where possible.

Investment and cryptocurrency scams

These can begin with social-media adverts, unexpected messages or apparently professional websites. Victims may initially see convincing dashboards showing profits before being pressured to deposit more money or pay fees to withdraw funds.

Be extremely cautious of guaranteed returns, time-limited opportunities and unsolicited investment approaches.

Romance scams

A criminal creates an emotional relationship online and eventually asks for money, often using an emergency, travel problem, medical issue or investment opportunity as the reason.

The relationship may be developed over weeks or months, which makes the later request feel more credible.

Remote-access scams

Some scammers claim to be from Microsoft, your broadband provider, a bank or another support service and ask you to install software that lets them control your computer.

Do not install remote-access software because of an unsolicited call.

QR-code scams

QR codes can hide the destination until you scan them. Be particularly cautious of codes in unexpected emails, messages, parking notices or stickers placed over legitimate public QR codes.

Invoice and payment-detail scams

Individuals can encounter these when buying property, arranging building work or paying other large invoices. A criminal may compromise or imitate an email conversation and provide replacement bank details.

Verify any unexpected change of payment details directly with the person or organisation using a trusted telephone number.

What about AI voice cloning and deepfakes?

Images, video and voices can all be manipulated. A message that appears to include the voice or face of somebody you know should therefore not override normal checks when the request is unusual.

If someone appears to urgently request money or sensitive information, verify the request separately. For families or close teams, an agreed phrase or question that would not be public can sometimes provide an additional check, although it should not replace other security measures.

Can you trust the caller ID on your phone?

Not always. A displayed telephone number or sender name can be manipulated or spoofed.

Never treat the number appearing on the screen as proof of identity. If the call concerns money, passwords or a security problem, ending the call and contacting the organisation through a trusted number is safer.

Be careful what you share on social media

Public information can help criminals create personalised scams. Birthdays, employers, family relationships, holidays, hobbies and photographs can all make an impersonation more believable.

Review your privacy settings and consider how much personal information needs to be public.

How to shop more safely online

  • Use retailers you know or investigate unfamiliar sellers before paying.
  • Be suspicious of prices that are dramatically lower than everywhere else.
  • Do not assume a professional-looking website is genuine.
  • Type the retailer's known address yourself rather than following an unexpected advertising link.
  • Use payment methods that provide appropriate consumer protection.
  • Check the exact web address, particularly before entering payment details.

What should you do if you clicked a suspicious link?

Do not panic, but act promptly.

If you only opened a page and entered nothing, close it. Make sure your browser and device are up to date and follow any relevant device-security guidance.

If you entered a password, change that password immediately on the genuine website. If the same password is used anywhere else, change it there too. Turn on two-step verification if it is not already enabled.

If you entered bank or card information or lost money, contact your bank or payment provider immediately.

What should you do if an account has been hacked?

  1. Try to regain control using the provider's official account-recovery process.
  2. Change the password to a new unique one.
  3. Sign out of other devices or sessions if the service provides that option.
  4. Enable or reset two-step verification.
  5. Check recovery email addresses and phone numbers have not been changed.
  6. Review recent messages, purchases and account activity.
  7. Warn contacts if the attacker may have sent messages pretending to be you.

How to report suspicious emails and texts in the UK

You can forward suspicious emails to the National Cyber Security Centre's Suspicious Email Reporting Service at report@phishing.gov.uk.

Most UK mobile providers also allow suspicious text messages to be forwarded free to 7726.

If you have lost money or experienced cyber crime or fraud in England, Wales or Northern Ireland, the national police reporting service is now Report Fraud, which replaced Action Fraud in December 2025. People in Scotland should report fraud to Police Scotland on 101.

If money has been taken or banking information has been compromised, contact your bank first as well as making the appropriate fraud report.

A simple rule when something feels wrong

Stop. Break the contact. Check independently.

You do not need to decide instantly whether a message is definitely a scam. You only need to refuse to be rushed into an action you cannot undo.

A genuine bank, retailer, family member or supplier will still be genuine after you have taken a few minutes to verify them through another route.

Frequently asked questions

Are scam emails easy to spot?

Not always. Some are obvious, but modern scam messages can be polished and convincing. Look at the behaviour of the request, particularly urgency, unusual payments, requests for credentials and pressure to bypass normal procedures.

Can scammers fake a bank telephone number?

Caller information can be spoofed, so a familiar displayed number is not proof. End the contact and call your bank using a trusted number.

Is it safe to click a link in a text from a delivery company?

If you are unsure, do not use the link. Open the delivery company's official app or website independently and enter your tracking details there.

Should I use the same strong password on several websites?

No. A strong password that is reused can still create risk if one service is compromised. Use unique passwords or passkeys.

What is the most important account to protect?

Email is one of the most important because other accounts often use it for password resets and security notifications. Banking, cloud-storage and main Apple, Google or Microsoft accounts are also high priority.

What if I am not sure whether something is a scam?

Do not respond through the suspicious contact. Use the organisation's official website, app or a known telephone number to check independently.

Learn more about cyber security

ExperTrain's Cyber Security Glossary explains common terminology including phishing, ransomware, malware, multi-factor authentication and social engineering.

For professionals who want to develop technical cyber security skills, ExperTrain also provides instructor-led training across CompTIA, ISC2, ISACA, Microsoft, Cisco, EC-Council and cloud security technologies.

Further reading

Keep ExperTrain in your Google results

Found this article useful? Add ExperTrain as a Preferred Source on Google to help surface more of our training guides, articles and learning resources.

Join our mailing list

Receive details on our new courses and special offers

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.