The Cybersecurity Trends I'm Actually Seeing Right Now
I read a lot of cybersecurity coverage that makes everything sound apocalyptic. Most of it isn't. What I'm actually seeing, working with people day to day, is a shift in who gets targeted and how. It used to be mostly big companies. Now it's just as often an ordinary person checking their phone on the bus between stops. The tools scammers use have got cheaper and easier to access, so the volume of low effort attacks has gone up sharply even where the sophisticated ones haven't changed all that much. That distinction matters more than most coverage lets on, because it changes what you should actually be worried about day to day.
The businesses and families who come to me worried about the wrong things usually got that worry from a headline, not from anything specific happening to them. I'd rather talk about what I'm genuinely seeing repeat itself across real conversations, because that's a far better guide to where your attention should go than whatever's trending in the news that week.
AI Is Changing Both Sides
Scammers are using AI to write more convincing messages and clone voices, and I've covered some of the cybersecurity myths I keep hearing about that shift. But the same technology is helping the good side too. Spam filters and fraud detection have got noticeably better at catching things before they reach you, often flagging patterns a human reviewer would never spot at that scale. It's an arms race, and right now neither side is winning outright. What that means practically is that the messages getting through the filters are, on average, the more convincing ones, so the old advice to "just look for the obvious signs" matters less than it used to.
Phishing Emails Are Getting Harder to Spot
The obvious spelling mistakes and dodgy logos are mostly gone. Today's phishing emails often look identical to the real thing, right down to the footer and the unsubscribe link. If you want the full detail on what to look for, I've written a guide on how to identify email phishing that goes through it step by step. The short version is to check the sender's actual email address, not just the display name, before you click anything, because the display name is trivial to fake and tells you nothing.
The Trend I Didn't Expect
The one shift that's genuinely surprised me is how much scam activity now starts on platforms that used to feel relatively safe, group chats, marketplace apps, and messaging platforms rather than email. People have spent years training themselves to be suspicious of their inbox, and that caution simply hasn't transferred to a message from someone claiming to be a buyer on a marketplace listing or a new contact in a group chat. Scammers go where the guard is down, and right now that's increasingly not email at all.
Why I'm Wary of Fear-Based Marketing
There's a growth industry in security products sold purely on fear, and I think it's doing almost as much damage as the scams themselves. I regularly hear from people who've bought an expensive suite of software after a panicked late-night purchase, without ever working out whether it actually addresses the risk that worried them in the first place. Fear makes for a great sales pitch and a genuinely poor buying decision, because it skips the one step that actually matters, working out what you're protecting and from whom. I'd always rather someone spent ten minutes thinking about their own setup than ten seconds panic-buying whatever's been marketed hardest that month.
This matters more now than it used to, because the marketing has got as sophisticated as the scams it claims to protect you from. Countdown timers, "your device is at risk" pop-ups, and inflated statistics are all designed to short-circuit the same careful thinking that protects you from an actual scam. If a security product is selling itself the way a scammer would, that's worth noticing rather than ignoring.
The Basics Still Work
With all this change, it's easy to think you need something complicated to stay safe. You mostly don't. Turning on two factor authentication is still one of the single best things you can do, and a password manager like NordPass takes away the temptation to reuse the same password everywhere, generating a unique one for every account instead. Neither takes more than a few minutes to set up, and both keep working regardless of how convincing the next wave of scams gets, because they don't rely on you spotting anything in the moment.
What I'd Focus On If I Were You
If you only do three things this year, make it these. Turn on two factor authentication everywhere it's offered, get a password manager, and use a VPN like NordVPN whenever you're on public wifi or a network you don't fully trust. None of it is exciting, but it's the difference between being an easy target and not being worth a scammer's time, and that's really the whole game. Scammers are running a numbers business, and the goal isn't to be unhackable, it's to be enough friction that they move on to someone easier.
Have a browse of my Safety Toolkit for the full list of what I actually use myself, and if anything here raises a question specific to your own setup, drop me a message and I'll give you a straight answer.
