How I Stay Ahead of Cybercriminals

May 10, 2026By Jay Kells
Jay Kells

Where I See Cybercriminals Getting In

Cybercrime doesn't discriminate by postcode, and it hasn't slowed down. I hear from people every week who assumed they were too careful, too switched on, or too small to be a target. None of that matters to a scammer running the same script against thousands of people at once. Cybercriminals aren't picking locks anymore, they're walking through doors people left open without realising it. It's rarely one dramatic breach that catches people out, more often it's a handful of small oversights quietly stacking up.


The threats I see most often aren't complicated. They're phishing emails dressed up as delivery notices, fake invoices sent to small business owners, and password reuse that turns one leaked account into five. Understanding where the real risk sits is the first step, and it's usually much closer to home than people expect. None of this requires special expertise to fix, just a bit of attention paid where it usually isn't.

Hooded figure walking through a dark alley at night, representing the opportunistic cybercriminals targeting Liverpool residents and small businesses online


Strong, Unique Passwords Are My Starting Point


Every proper conversation about online safety starts here, because a weak or reused password is still the easiest way in. I've written before about the debate between using a password manager and just memorising a few passwords, and my answer hasn't changed: use a password manager. I rely on NordPass to generate and store mine, so I never have to reuse a password I can't quite remember across three different accounts. It also flags any password that's been caught up in a known breach, which is worth acting on the moment it happens rather than waiting to find out the hard way.


Two-Factor Authentication Isn't Optional Anymore


A strong password is a good lock, but two factor authentication is the deadbolt behind it. I turn it on for every account that offers it, especially email and banking, because it's the one habit that stops a stolen password from actually being useful to whoever's holding it. It adds ten seconds to my login. That's a fair trade for not having my accounts drained while I'm asleep. I use an authenticator app rather than text-message codes wherever it's offered, since a code sent by SMS can be intercepted in ways an app-generated one can't.


Checking Whether My Data's Already Been Exposed

Passwords and two factor authentication only help with accounts you know about. Every few months I run my own email address through a breach-checking site to see whether it's turned up in a leak I hadn't heard about, and I'd recommend anyone do the same. If something does show up, it's usually an old account you'd forgotten existed, and it's worth changing that password and checking whether you reused it anywhere else before moving on.

Watching Out for Phishing Scams


I've covered the phishing defences I actually rely on in detail elsewhere, but the short version is this: I check the sender address before I click anything, I never trust urgency, and I go directly to a company's website rather than clicking a link in an email claiming to be from them. If something ever does slip through, Action Fraud is where I'd report it. Voice calls and texts get the same treatment, since the pressure tactics are identical even when there's no email involved.


Keeping Software Updated Without Thinking About It


Software updates feel like an interruption, which is exactly why so many people put them off. Most of them exist to patch a security hole that's already being exploited somewhere. I keep automatic updates switched on across my phone, laptop and router, so I'm not the one deciding whether today's a good day to leave a known vulnerability open. Browser extensions are the thing most people forget are software too, and an old, unmaintained one is as good an entry point as an outdated operating system.


Locking Down My Home Network


I've written a full walkthrough on securing a home network step by step, but the essentials are worth repeating here: change the router's default login, use a strong separate wifi password, and set up a guest network for visitors and smart devices. When I'm working from a cafe or anywhere with public wifi, I run NordVPN so my traffic isn't sat there in plain sight for anyone else on the same network. Routers get firmware updates too, and I check mine every so often rather than assuming it updates itself the way my phone does.


Educating Myself and Everyone Around Me


The tools only get you so far. The habits are what actually keep you safe, and habits spread faster when you talk about them. I make a point of walking family, friends and clients through the basics rather than assuming they'll pick it up on their own, and I keep my own Safety Toolkit updated with the tools and checklists I actually use. It doesn't take a lecture to make it land, most people are receptive once they realise it's about protecting them rather than catching them out.


Final Thoughts


Staying ahead of cybercriminals isn't about becoming paranoid or living without technology. It's a handful of habits, repeated consistently: a password manager, two factor authentication, a healthy suspicion of anything urgent in your inbox, and updates you don't put off. If you'd like a hand putting any of this in place, get in touch and I'll talk you through it. None of this is about becoming an expert, it's simply about not being the easiest target in the room.