Step 2 · At your own pace

Level Up

Fourteen more protections for your devices, family, home network and privacy. If you haven't done Step 1 on the home page yet, start there.

Step 1 · Start here

The Essentials

The 10 protections everyone needs: passwords, 2FA, scams and what to do if you get hacked.

Go to Step 1 →
Step 2 · At your own pace

Level Up

14 more protections for your phone, your family, your home network and your privacy.

✓ You are here
On this page
11 Your Phone 12 Encryption 13 Backups 14 Browser Security 15 Online Shopping 16 AI Chatbots 17 Kids & Family 18 Digital Legacy 19 Custom DNS 20 Router & Wi-Fi 21 Smart Home 22 Social Media 23 Privacy Audit 24 Email Aliases

Protect your devices

Your phone and laptop hold your whole life. Make them useless to a thief.

11. Securing Your Phone

Your phone is the key to everything. Lock it well, find it when lost and guard your SIM.

Your phone holds your email, banking, photos and 2FA codes. It's the single most valuable thing a thief can grab. A few settings make it dramatically safer.

1. The essentials

  • Strong screen lock: use Face ID / fingerprint plus a 6-digit (or longer) passcode, not 4 digits, not a simple pattern.
  • Find My / Find My Device: turn it on now so you can locate, lock, or erase a lost phone.
    Settings → your name → Find My
    Settings → Google → Find My Device
  • Auto-updates on: phone updates patch security holes (see card 4 (Software Updates)).
  • Official app stores only: never install apps from links, QR codes, or "sideloading". That's how phone malware spreads.

2. Protect your SIM (stops "SIM swapping")

In a SIM-swap attack, a scammer convinces your carrier to move your number to their SIM and then receives your 2FA codes. Call your mobile carrier and ask to add a PIN or password to your account so nobody can transfer your number without it.

3. App hygiene

  • Review permissions. Does that game really need your location and microphone?
    Settings → Privacy & Security
    Settings → Privacy
  • Delete apps you no longer use. Every app is a door into your phone.
📱 iPhone walkthrough
Set up Find My and check your privacy settings Coming soon
Settings → your name → Find My → enable Find My iPhone & Send Last Location
❌ Don't
  • ❌ Use a 4-digit PIN like 1234 or your birth year
  • ❌ Install apps from outside the official store
  • ❌ Leave Find My turned off "for privacy"
✅ Do
  • ✅ Use biometrics + a 6-digit or longer passcode
  • ✅ Add a PIN to your mobile carrier account
  • ✅ Review app permissions twice a year

12. Device Encryption

Scrambles your data so thieves can't read it. Already on by default on iPhone.

1. How to enable it

  • iPhone/iPad: Already encrypted by default with a passcode.
  • Mac: System Settings → Privacy & Security → FileVault → Turn On.
  • Windows: Settings → Privacy & Security → Device Encryption (or BitLocker).

2. Encrypted messaging

Signal iMessage WhatsApp

Regular SMS is not encrypted and can be intercepted. Use these apps for private conversations.

❌ Don't
  • ❌ Leave FileVault / BitLocker off
  • ❌ Use SMS for sensitive conversations
  • ❌ Forget to save your recovery key
✅ Do
  • ✅ Enable FileVault (Mac) or BitLocker (Windows)
  • ✅ Save recovery key in your password manager
  • ✅ Use Signal, iMessage, or WhatsApp

13. Backups

The 3-2-1 rule: 3 copies, 2 storage types, 1 offsite.

Ransomware encrypts your files and demands payment. A good backup means you can wipe and restore without paying a cent.

The 3-2-1 rule

  • 3 copies of your data
  • 2 different types of storage
  • 1 copy offsite (iCloud, Backblaze)
❌ Don't
  • ❌ Keep files on only one device
  • ❌ Assume cloud sync = backup
  • ❌ Pay ransomware, just restore
✅ Do
  • ✅ Follow 3-2-1: 3 copies, 2 types, 1 offsite
  • ✅ Use Time Machine (Mac) or File History (Win)
  • ✅ Add cloud backup (iCloud, Backblaze)

Browse and shop safely

Everyday habits for the open web, online stores and AI tools.

14. Browser Security

Check for the padlock, block trackers and don't trust "private mode" too much.

Your browser is the door to almost everything you do online, so a few small habits go a long way.

Quick habits

  • Check for the padlock / https:// before entering any password or payment info.
  • Keep your browser itself updated: Chrome, Firefox, Safari and Edge all patch security holes quickly.
  • Turn on your browser's built-in tracking protection (Firefox, Safari and Edge include one in their privacy settings).
MythReality
"Private/Incognito mode keeps me anonymous"It only stops your browser saving history locally. Your network, employer, or the websites you visit can still see you.
❌ Don't
  • ❌ Enter passwords on a page without https://
  • ❌ Rely on incognito mode for privacy
  • ❌ Ignore "Not Secure" browser warnings
✅ Do
  • ✅ Look for the padlock before logging in
  • ✅ Turn on built-in tracking protection
  • ✅ Keep your browser auto-updating

15. Safe Online Shopping

Spot fake shops before you pay and use payment methods you can dispute.

Fake online shops are designed to look real long enough to take your money and your card details.

1. Red flags

  • Prices far too good to be true, with countdown timers pushing you to "buy now"
  • Only a contact form, no real phone number or address
  • A domain that was registered very recently

2. Pay safely

Prefer Apple Pay, Google Pay, PayPal, or a credit card over a debit card. These make disputing fraudulent charges much easier.

Check before you buy: search the shop's name plus "reviews" or "scam," and look up how old the domain is with a free WHOIS lookup. Brand-new domains running "huge sales" are a classic red flag.
❌ Don't
  • ❌ Pay by bank transfer to an unfamiliar shop
  • ❌ Ignore a missing phone number or address
  • ❌ Rush because of a countdown timer
✅ Do
  • ✅ Pay with a credit card or Apple/Google Pay
  • ✅ Search "[shop name] scam" before buying
  • ✅ Check how old the website's domain is

16. Safe AI Chatbot Use

Chatbots are useful, but treat everything you type as potentially stored. Never paste secrets.

AI chatbots (ChatGPT, Claude, Gemini and the assistants built into apps) are genuinely helpful, but many people paste things into them they'd never post online. Treat a chatbot like a very smart stranger: great for advice, wrong place for secrets.

1. Never paste these into a chatbot

  • ❌ Passwords, recovery codes, or 2FA codes
  • ❌ Credit card or bank account numbers
  • ❌ Photos of your ID, passport, or medical documents
  • ❌ Confidential work documents or client data

2. Good habits

  • Assume it may be stored. Conversations can be kept and, on some free services, used to train future models or reviewed by staff.
  • Check the data settings. Most chatbots let you turn off "use my chats for training" and delete your history. Do both if you're unsure.
  • Remove details before asking. "Review this contract" works just as well with names, addresses and amounts blanked out.
  • Use official apps only. Fake "AI" apps in search results are a common way to steal data and money.
  • Double-check important answers. Chatbots sound confident even when wrong. Verify medical, legal, or financial advice with a real source.

3. Be careful what you connect AI to

Newer AI assistants ask to connect to your email, calendar, files, or even to browse and click for you. That can be genuinely useful, but a connected AI can read everything in that account and act on your behalf. Treat every connection like handing over a key.

  • Understand before you connect. Only link an AI to your email, files, or other accounts when you know exactly what it can see and do there.
  • Stick to well-known providers for anything connected. A random "AI email assistant" from an ad is a data grab waiting to happen.
  • Keep banking out of it. Never give an AI tool your banking login or let it make payments for you.
  • Review and revoke. Check the connected apps page of your Google or Microsoft account twice a year and remove AI tools you no longer use.
  • Know that connected AI can be tricked. A malicious email or website can contain hidden instructions for your AI assistant. If an AI acts on what it reads, it can be fooled by what it reads.
Scammers use AI too. Voice cloning and AI-written messages make scams more convincing. Another reason to verify unexpected calls and texts the way cards 5 and 6 (Phishing, Scam Calls) describe.

Protect your family

Kids and grandparents are scammers' favorite targets. Set them up safely.

17. Kids & Family Online Safety

Kids and grandparents are scammers' favorite targets. A few conversations protect them more than any app.

The two most-targeted groups online are kids (games, social media, "free" offers) and older family members (phone scams, phishing). Technology helps, but talking about it openly helps more.

1. For kids

  • Use the built-in parental controls. Set app-purchase approval so "free" games can't charge your card.
    Settings → Screen Time
    the Google Family Link app
  • Keep gaming chat with strangers off for younger kids and teach older ones never to share their name, school, or photos with people they only know online.
  • Agree they can always tell you if something online went wrong, with no punishment for coming to you. Scared kids hide problems; that's when small issues become big ones.

2. For parents & grandparents

  • Walk them through the scam cards on this site (cards 5 to 8, the scam section), especially fake bank calls and the "grandchild in trouble" voice scam (card 7 (Voice Cloning)).
  • Set up their family code word together and save the bank's real fraud number in their contacts.
  • Make yourself their "ask first" person: any unexpected payment request, they call you before doing anything. One phone call stops almost every scam.
The best family security tool is a rule: "We never send money or codes to anyone based on a call or message. We always verify first, together."

18. Your Digital Legacy

What happens to your accounts and photos if something happens to you? Ten minutes of setup spares your family months of stress.

If you were suddenly unable to use your accounts, could your family get into your photos, pay the bills, or close things down? Without preparation, they'd face months of support tickets and legal paperwork, locked out of everything by the very security you set up.

1. Three settings that solve most of it

  • Apple Legacy Contact: Settings → your name → Sign-In & Security → Legacy Contact. Lets someone you choose access your photos and data.
  • Google Inactive Account Manager: myaccount.google.com → Data & privacy → "Make a plan for your digital legacy". Shares chosen data with a trusted person after a period of inactivity.
  • Password manager emergency access: Bitwarden and 1Password can grant a trusted person access after a waiting period you define, covering everything else.

2. Also worth doing

  • Write down where things are. A simple note ("passwords are in Bitwarden, emergency access goes to...") kept with your important documents.
  • Tell the person you chose. A legacy plan nobody knows about helps nobody.
This is also a security feature for the living: emergency access gets you back in if you're ever locked out of your own password manager.

Secure your home network

Your router and every smart gadget connected to it.

19. Custom DNS

Block malicious websites and keep your lookups out of your internet provider's logs.

Recommended DNS providers

ProviderAddressBonus
Cloudflare1.1.1.1Fastest, privacy-focused
Quad99.9.9.9Blocks malware domains
NextDNSCustomConfigurable ad/tracker blocking
📱 iPhone walkthrough
How to set up Cloudflare DNS on iPhone Coming soon
Download the free 1.1.1.1 app → tap to enable → done
❌ Don't
  • ❌ Use your provider's default DNS
  • ❌ Use random "free DNS" services
✅ Do
  • ✅ Switch to Cloudflare, Quad9, or NextDNS
  • ✅ Install the 1.1.1.1 app for easy setup

20. Router & Home Wi-Fi

Change the default password, use WPA2/WPA3 and put smart devices on a guest network.

Your router is the front door to every device in your home: phones, laptops, smart TVs, cameras and any "wifi button" style smart-home gadgets that connect to it.

Lock it down

  • Change the default admin password. Many routers ship with a password that's publicly known for that model.
  • Use WPA2 or WPA3 encryption for your Wi-Fi network and avoid the old, broken WEP standard.
  • Put smart-home devices on a guest network so a compromised camera or plug can't reach your laptop or phone.
  • Install firmware updates a few times a year. Check your router app or admin page.
❌ Don't
  • ❌ Leave the router's default admin password
  • ❌ Mix smart-home gadgets onto your main network
  • ❌ Skip firmware updates for years
✅ Do
  • ✅ Set a unique admin password
  • ✅ Use WPA2/WPA3 with a strong Wi-Fi password
  • ✅ Create a separate guest network for IoT devices

21. Smart Home & Connected Devices

Cameras, doorbells, speakers, TVs: every smart device is a small computer on your network. Treat it like one.

Smart devices are the weakest computers in most homes: rarely updated, often left on default passwords and always online. A compromised camera or doorbell is about as personal as a breach gets.

1. Buying & setup

  • Stick to known brands that publish security updates. A €15 no-name camera is cheap because the software (and its security) is an afterthought.
  • Change any default password immediately and put MFA on the device's account (especially cameras and doorbells).
  • Put smart devices on your guest network so a hacked gadget can't reach your laptop or phone. Card 20 (Router & Wi-Fi) shows how.

2. Ongoing habits

  • Turn on auto-updates in each device's app and once a year check that older devices still receive updates at all.
  • Disable features you don't use: remote access, microphones on TVs, cameras in kids' rooms.
  • When you retire or sell a device, factory-reset it and delete its account. Old accounts keep working (and watching) after the device leaves your house.
❌ Don't
  • ❌ Keep default passwords on cameras or doorbells
  • ❌ Put smart gadgets on the same Wi-Fi as your laptop
  • ❌ Sell a device without a factory reset
✅ Do
  • ✅ Use the guest network for all smart devices
  • ✅ Enable MFA on camera & doorbell accounts
  • ✅ Turn on auto-updates in every device app

Guard your online identity

Control what the internet knows and shares about you.

22. Social Media Privacy

Scammers build their attacks from what you post. Share less and share it with fewer people.

Almost every scam gets easier with information from your profiles: your voice for cloning (card 7 (Voice Cloning)), your dog's name for password guesses, your vacation dates for burglars, your friend list for "it's me" scams. Privacy settings are security settings.

1. Lock down the audience

  • Set accounts to private / friends-only where you can and review your follower list occasionally and remove accounts you don't recognize.
  • Check what strangers see: most platforms have a "view as public" option. You may be surprised.
  • Watch for cloned friends: a second friend request from someone you're already connected to is almost always a scammer copying their profile.

2. Think before posting

  • Those fun quizzes are harvesting security answers. "Your first pet + your childhood street" is literally how password-recovery questions work.
  • Post vacations after you're back. Real-time location tags tell everyone your home is empty.
  • Keep identifiers out of photos: house numbers, license plates, school logos on kids' uniforms, boarding passes (the barcode contains your booking details).
Rule of thumb: assume everything you post will eventually be seen by the one person you'd least want to see it, then decide whether to post.

23. Privacy Audit

Review app permissions, check for data leaks, clean up old accounts.

Checklist

  • Review app permissions. Does that flashlight app really need your contacts?
  • Run Google's privacy checkup at myaccount.google.com/privacycheckup
  • Set social profiles to private and remove your phone number
  • Delete old accounts you no longer use
  • Use a privacy browser: Firefox, Brave, or Safari
Check if your data has been leaked: Visit haveibeenpwned.com and enter your email address.
❌ Don't
  • ❌ Give apps unnecessary permissions
  • ❌ Keep old unused accounts around
  • ❌ Leave social profiles fully public
✅ Do
  • ✅ Revoke unneeded app permissions
  • ✅ Run Google's privacy checkup
  • ✅ Check haveibeenpwned.com for leaks

24. Email Aliases

Use fake forwarding addresses so your real email stays private.

Aliases are unique forwarding addresses that all deliver to your main inbox. If one gets spam, disable it.

Options

Hide My Email iCloud+ SimpleLogin Free Firefox Relay
❌ Don't
  • ❌ Give every site your real email
  • ❌ Use one email for everything
✅ Do
  • ✅ Use Hide My Email or SimpleLogin
  • ✅ Create a unique alias per service
Back to Step 1: The Essentials →