The Five Security Fixes I'd Make First in Your Position
Why These Five Come First
If you sat down with me for a coffee and asked where to even start with all this online safety stuff, I wouldn't hand you a fifty point checklist. I'd give you five things. In fifteen-odd years of watching people get caught out (and getting caught out myself once, years before I knew any better), it's always the same five gaps that let the scammers and the hackers in. Sort these five and you've shut the door on most of what's out there. Leave them and you're propping that door open with a brick.
I work with people right across Liverpool, from Aigburth to Anfield, Woolton to Walton, and the story is nearly always the same. Nobody thinks it'll happen to them until it does. So let's get ahead of it, properly, starting today. If you want the full story of how I ended up doing this work, you'll find it on my About page.
Fix One: Get a Password Manager Sorted
This is the one people roll their eyes at most, and it's the one that stops the most damage. If you're using the same two or three passwords for everything, your email, your bank, your Tesco Clubcard, one leaked password from some website you've long forgotten about becomes a master key to your entire life.
A password manager does the remembering for you. You set one strong master password, and it generates and stores a completely different, properly complicated password for every account you own. I use NordPass myself and I point nearly every client toward it, mainly because it's simple enough that even my least tech-confident clients actually stick with it once it's set up. There's a free trial if you want to see whether it suits you before you commit to anything.
Ten minutes of setup. Then you never have to remember a password again, and neither does a scammer.
Fix Two: Switch On Two-Factor Authentication
Two-factor authentication is the second lock on your front door. Even if someone gets hold of your password, they still can't get in without the code that lands on your phone at the same moment they try. It's the single biggest thing I tell every client to switch on, no exceptions, and I'd start with your email and your banking app before anything else.
Most banks and email providers have this built in already and just need you to turn it on in your account settings. It adds about four seconds to your morning login routine. Compare that to the months of hassle a compromised bank account causes, and it's not really a decision.
If you want a full walkthrough on spotting the phishing messages that try to trick you into handing over these codes in the first place, I've written a separate piece on the phishing scams I see catching Liverpool people out that's worth a read alongside this one.

Fix Three: Stop Ignoring Your Updates
That little red notification badge on your phone or laptop telling you an update is available isn't nagging you for no reason. Most updates exist specifically to patch security holes that hackers already know about and are actively using. Every time you tap remind me tomorrow, you're leaving that hole open for one more day.
I know updates feel like they always arrive at the worst possible moment, usually right as you're trying to leave the house. Set your phone and computer to update overnight instead, and you'll barely notice it happening. It's one of the quietest, easiest fixes on this whole list, and one of the most skipped.
Fix Four: Tighten Up Your Social Media Privacy
Scammers don't need to hack you if you've already told them everything on Facebook. Your pet's name, your mum's maiden name, your kids' school, your holiday dates, all of it sits there in plain view for anyone doing their homework before a targeted scam or a bit of old-fashioned burglary planning.
Go into your privacy settings on whichever platforms you use and lock your profile down to friends only. Turn off public location tagging. And have a proper think about whether that quiz asking for your first pet's name is really just for fun, because that's a classic security question in disguise.
Fix Five: Secure Your Wi-Fi and Any Public Connections You Use
Your home Wi-Fi should have a strong password and the default router login changed from admin. If you've never touched your router settings since your provider installed it, that's worth an afternoon sorting. Which? has a solid step-by-step guide if you're not sure how.
Public Wi-Fi in Liverpool ONE, your local café, or the train down to Lime Street is a different matter entirely. Anyone on that same network can, with the right tools, see what you're doing. A VPN encrypts your connection so what you're browsing stays private even on networks you don't control. I use NordVPN when I'm out and about and recommend it to clients who travel a lot or work from cafés regularly.
None of This Has to Happen Overnight
Pick one fix this week. Then another next week. Within five weeks you'll have closed every major gap I see catching people out across this city, and you'll sleep a lot easier for it.
If you'd rather not do it alone, that's exactly what I'm here for. Have a browse through my Safety Toolkit for the tools I recommend, or get in touch and I'll walk through your specific situation with you, no jargon, no judgement, just straight answers from someone who's seen it all before.
And if you ever do get caught out despite everything, report it to Action Fraud straight away. The sooner it's reported, the better the chance of stopping it happening to someone else too.
