In-depth Technology guide

The complete guide to staying safe online at home

A whole-household plan for online safety: accounts, passwords, 2-step verification, scams, devices, backups, children and what to do after a breach.

Reading time: 15–20 minutesUpdated: 28 September 2026

Most online harm at home does not come from clever hacking but from reused passwords, rushed clicks, forgotten updates and accounts nobody remembers opening. The good news is that a handful of well-chosen habits protects almost everything. This guide walks through the whole household, one layer at a time, so you can build protection that lasts rather than reacting to each new scare. Work through it over a few evenings and keep the notes you make somewhere safe.

Start with your most important accounts

Not every account matters equally, so begin by listing the few that would hurt most if someone else got in. For nearly everyone this means the main email account, online banking, the mobile phone account and the accounts that store photos and documents. Your email is the master key: password resets for almost every other service are sent there, so whoever controls it can usually take over the rest. Write the list down on paper or in a password manager and put a star next to each account that controls others.

For each starred account, check three things: that the recovery phone number and recovery email are current, that you know which devices are signed in, and that there are no forwarding rules or connected apps you do not recognise. Old recovery details are one of the most common reasons people get locked out permanently. It is also worth closing or deleting accounts you no longer use, because a forgotten account with an old password is an easy target. Aim to review this list once or twice a year and after any major life change such as a new phone number.

  • Main email account (the master key)
  • Online banking and payment apps
  • Mobile phone network account
  • Cloud storage for photos and documents
  • Social media accounts that others could impersonate you with
  • Any account holding saved card details

Passwords that actually protect you

The single biggest improvement most households can make is to stop reusing passwords. When one website is breached, criminals try the same email and password combination on hundreds of other sites automatically, so one leak can open many doors. The National Cyber Security Centre recommends using three random words to create passwords that are long, memorable and hard to guess. The words should be genuinely unrelated to you, so avoid pets, children, football teams and places.

A password manager removes the need to remember dozens of different passwords. It creates a strong, unique password for each site, fills it in for you and warns you about reused or weak ones. You then only need to remember one strong master password, which should be used nowhere else and protected with 2-step verification. Many browsers and phones include a built-in password manager, and standalone ones are also available; choose one that works across all the devices you use and keep a recovery method written down securely at home.

Moving everything into a password manager does not have to happen in one sitting. Start with the starred accounts, then change other passwords as you next sign in to each site, letting the manager generate and save a new one each time. Most managers include a health check that lists reused, weak or leaked passwords, which gives you a simple to-do list. Within a few weeks, most of your regularly used accounts will have unique passwords without much extra effort.

  • Never reuse your email password anywhere else
  • Use three random words for passwords you must remember
  • Let the password manager create all the others
  • Work through the manager's reused-password list over a few weeks

Two-step verification and passkeys

Two-step verification, often shortened to 2SV or called two-factor authentication, adds a second check after your password. Even if someone has your password, they also need your phone, an authenticator app code or a security key. Turn it on for every starred account first, then for anything else that offers it. An authenticator app or security key is generally stronger than a text message code, but a text code is far better than nothing.

Passkeys are a newer way to sign in that replace passwords with your device's fingerprint, face or PIN unlock. They are designed so they cannot be phished, because they only work on the genuine website they were created for. Where a service offers passkeys, they are worth setting up, but keep at least one backup sign-in route. Whichever method you use, save any backup or recovery codes the service gives you and store them somewhere safe away from your phone, because losing your only second factor can lock you out.

  • Authenticator app: strong, works offline
  • Security key: very strong, needs a spare
  • Text message code: better than nothing
  • Passkey: phishing-resistant, tied to your devices
  • Backup codes: print or write down and store safely
Which sign-in protection to choose
MethodStrength against phishingBest used for
Unique strong password aloneLow – can be tricked out of youLow-value accounts, alongside a password manager
Password plus text message codeModerate – codes can be phished or interceptedAccounts where nothing stronger is offered
Password plus authenticator appGood – codes still phishable but harder to interceptEmail, social media and most important accounts
PasskeyVery strong – only works on the genuine siteAny service that offers it, with a backup route kept
Physical security keyVery strong – needs the key in handMain email and high-value accounts, with a spare key registered
Backup or recovery codesDepends on safe storageRegaining access if your usual second step is lost

Recognising and handling scams

Scams reach households by email, text, phone call, social media and messaging apps, and they increasingly look professional. The warning signs are usually about pressure rather than spelling: urgency, secrecy, a request to move money, a surprise problem with a delivery or account, or a message from a family member on a new number asking for help. Criminals may also know some real details about you from previous data leaks, so a message that mentions your name or address is not proof it is genuine.

The safest rule is to never act on the contact itself. Close the message and reach the organisation using a number or app you already trust, such as the number on the back of your bank card. Many UK banks can be reached by calling 159 if you think a call claiming to be from your bank is a scam. Forward suspicious emails to the Suspicious Email Reporting Service run by the National Cyber Security Centre, and forward scam texts to 7726, a free service that works on most UK networks. If you have lost money, contact your bank immediately and report it to Report Fraud, the national fraud reporting service for England, Wales and Northern Ireland; in Scotland, report to Police Scotland on 101.

  • Stop: take a breath before clicking, paying or sharing
  • Check: contact the organisation through a route you already trust
  • Never share one-time codes, even with someone claiming to be your bank
  • Agree a family code word for urgent money requests

Keeping devices and home networks secure

Updates fix security weaknesses that criminals actively look for, so switching on automatic updates for phones, tablets, computers and apps is one of the easiest protections you can apply. Devices eventually stop receiving updates, and at that point they become steadily riskier to use for banking or email. Check whether older phones, laptops and smart devices in the house are still supported by their maker, and plan replacements for any that are not.

Every device should have a screen lock, such as a PIN, password, fingerprint or face unlock. Use the built-in find-my-device feature so you can locate, lock or erase a lost phone or laptop. At home, make sure your broadband router's admin password has been changed from the default and that its software is up to date, and treat smart devices such as cameras, doorbells and speakers as small computers that also need strong passwords and updates. If you are unsure whether a smart product is secure, check whether the maker says how long it will receive security updates before you buy.

Backups: your safety net

Backups turn a disaster such as ransomware, theft, a dropped phone or a failed hard drive into an inconvenience. A good home approach keeps at least one copy of important files somewhere other than the device itself, such as a cloud storage service or an external drive, and ideally both. Photos, scanned documents, work files and anything you could not recreate are the priority. Automatic backups are far more reliable than remembering to copy things manually.

A backup you have never tested may not work when you need it. Every few months, try restoring a single file or photo to check that it opens properly. If you use an external drive, disconnect it when it is not backing up, so that ransomware on the computer cannot reach it. Also check that you could still get into your cloud backup if your phone were lost, which means knowing your password and having a second-factor backup method available.

Shared family devices deserve particular attention. A tablet used by several people often holds photos from everyone, yet may be backed up to only one person's account, or to none. Check which account each device backs up to, and make sure photos from children's and older relatives' phones are included somewhere. When a device is replaced, confirm the backup is complete and restored on the new device before wiping or selling the old one.

  • Keep at least two copies of important files, one away from the device
  • Switch on automatic backup for phones and computers
  • Test a restore every few months
  • Disconnect external backup drives between uses

Children and young people online

Technical controls help, but conversations matter more. Parental controls are available at several levels: on your broadband router or provider's network filter, on each device's operating system, in app stores and inside individual apps and games. Use them to match content and time limits to age, and review them as children grow, because settings that suit an eight-year-old will frustrate a teenager and may push them to work around them.

Talk regularly and calmly about what children enjoy online, who they talk to and what they would do if something upset them. Make it clear they will not lose their device for telling you about a problem, because fear of punishment is a common reason children stay silent. Explain that people online are not always who they say, that private images should never be shared, and that they should come to you if anyone asks for secrecy. If you are worried a child is at risk of sexual abuse or grooming online, report it to CEOP, the child protection command of the National Crime Agency, and contact the police on 999 if a child is in immediate danger.

  • Set age-appropriate controls at network, device and app level
  • Keep devices out of bedrooms overnight for younger children
  • Agree family rules together and write them down
  • Review settings at each birthday or new device

What to do after a data breach or account compromise

If a company tells you your data has been involved in a breach, or you notice signs that an account has been taken over, act quickly but methodically. First, change the password for the affected account and for any other account where you used the same or a similar password, starting with email. Then turn on 2-step verification if it was not already on, sign out of all other sessions and check recovery details, forwarding rules and connected apps for anything unfamiliar.

Next, think about what was exposed. If bank or card details were involved, contact your bank using the number on your card. If identity details such as date of birth, address or passport information were leaked, watch your credit file with the main credit reference agencies for applications you did not make, and be extra wary of convincing follow-up scams that use the leaked details. Keep a dated note of what happened and what you did. If you believe an organisation has handled your personal data poorly, the Information Commissioner's Office explains how to raise a concern, and if you lost money, report it to Report Fraud or Police Scotland.

  • Change passwords, email first
  • Turn on 2-step verification and sign out everywhere
  • Check recovery details, forwarding rules and connected apps
  • Contact your bank if financial details were exposed
  • Monitor your credit file for unexpected applications
  • Keep a dated log of events and actions

Making it a household routine

Online safety works best when it is shared and regular rather than a one-off panic. Choose one person to coordinate, but make sure at least two adults know where recovery codes and important account information are kept. A short check every three months keeps things under control: look for pending updates, review the starred account list, test one backup restore and ask everyone whether anything odd has happened online.

It is also worth planning for the long term. Many major services let you nominate a legacy contact or set up inactive account settings so that someone you trust can access or close accounts if you die or become unable to manage them. Record which accounts exist, without writing passwords in plain view, and let the relevant people know where the information is kept. Treat older relatives kindly and patiently, because scam victims often feel embarrassed, and the quicker someone tells you something has gone wrong, the easier it is to fix.

Key terms explained

Two-step verification (2SV)
A second check after your password, such as a code or approval on your phone. It stops most account takeovers even when a password has leaked.
Passkey
A way of signing in that uses your device's unlock method instead of a password. It is tied to the genuine website, so it resists phishing.
Password manager
An app or browser feature that creates, stores and fills in unique passwords for each account. You protect it with one strong master password.
Phishing
Messages or websites that pretend to be from a trusted organisation to trick you into giving away details or money.
Smishing
Phishing sent by text message, often about parcels, bank problems or unpaid bills.
Credential stuffing
Criminals automatically trying leaked email and password pairs on many other websites. It is why reusing passwords is risky.
Ransomware
Malicious software that locks or encrypts your files and demands payment. Offline backups are the best protection.
Data breach
An incident where personal information held by an organisation is lost, stolen or exposed to people who should not see it.
Recovery codes
One-time backup codes a service gives you to regain access if you lose your usual second step. Store them offline and safely.
Legacy contact
A person you nominate to access or manage certain accounts after your death, offered by some major providers.
Software update
A new version of software from its maker, often fixing security weaknesses. Automatic updates keep devices protected with little effort.

Common mistakes to avoid

  • Reusing one password across several sites – use a password manager so every account has its own password.
  • Leaving an old phone number as the account recovery route – check recovery details on key accounts at least once a year.
  • Acting on a link or phone number in an urgent message – always contact the organisation through a route you already trust.
  • Keeping the only backup on a drive permanently plugged into the computer – disconnect it between backups or use a second copy elsewhere.
  • Setting strict parental controls and never talking about them – combine controls with regular, calm conversations and review settings as children grow.

Frequently asked questions

Is it safe to let my browser save my passwords?

Built-in browser and phone password managers are a reasonable choice for many households, especially compared with reusing passwords. Protect the account they are linked to with a strong password and 2-step verification. If you use several different makes of device, a standalone password manager may work more smoothly across them.

Should I write passwords down?

Writing down a small number of critical items, such as a master password or recovery codes, and keeping them securely at home is generally safer than reusing weak passwords. Keep the note away from the devices themselves and out of sight of visitors. Never keep a list of passwords in an unprotected file or in your phone's notes app.

How do I know if my details have been in a data breach?

Organisations are often required to tell affected people when a breach is likely to put them at high risk, so read any such notices carefully. Reputable breach-checking services also let you search by email address. Either way, the fix is the same: change affected and reused passwords, turn on 2-step verification and stay alert for follow-up scams.

What should I do if I clicked a phishing link?

Do not panic. If you entered a password, change it straight away along with any account that shares it, and turn on 2-step verification. If you entered bank details, call your bank on the number from your card. If you downloaded something, run your security software's scan and consider getting the device checked.

At what age should my child have their own phone?

There is no single correct age, and it depends on your child's maturity and your family's needs. Many families start with a basic or heavily restricted phone and relax settings gradually. Charities such as the NSPCC and Internet Matters publish balanced guidance to help you decide.

Who should I report online fraud to?

In England, Wales and Northern Ireland, report fraud and cyber crime to Report Fraud, the national reporting service. In Scotland, report to Police Scotland on 101. If money has left your account, contact your bank first, as speed matters, and call 999 if anyone is in immediate danger.

Where to get official help

Trusted UK services

  • National Cyber Security Centre – practical advice on passwords, 2-step verification, updates and backups, and the Suspicious Email Reporting Service
  • Report Fraud – the national service for reporting fraud and cyber crime in England, Wales and Northern Ireland
  • Police Scotland – reporting fraud and cyber crime in Scotland on 101
  • Information Commissioner's Office – your data protection rights and how to raise concerns about how an organisation handled your data
  • CEOP (National Crime Agency) – reporting concerns about online sexual abuse or grooming of children
  • Citizens Advice – help if you have been scammed and need to know your next steps

This guide gives general information, not personal legal, financial or medical advice. Rules can change, so check the current position with the official service before acting.