The Online Safety Basics I Can Actually Explain to Someone in Ten Minutes

Sep 02, 2026By Jay Kells
Jay Kells

I've had this conversation more times than I can count, a friend, a neighbour, someone at a dinner party who finds out what I do for a living and asks the same question: where do I even start? I used to try to answer that properly, walking through passwords, two-factor authentication, backups, phishing, and VPNs, the lot. By the time I'd finished, most people had glazed over, and worse, they hadn't actually changed anything. So I stopped trying to cover everything, and now I keep it to what I can genuinely explain in about ten minutes, standing in a kitchen, without a single slide or link.

Why I Stopped Trying to Cover Everything at Once

The problem with a comprehensive answer is that it sounds like homework, and homework gets postponed indefinitely. If I list ten things someone should do, they leave with a vague sense of guilt and do none of them. If I give them two things, they can actually go home and do those two things that evening. I'd rather someone properly finish two changes than half-remember eight. So the first thing I do now, before I say anything technical, is pick the two most consequential things instead of trying to be thorough.

The Two Things I Always Explain First

The two things are a password manager and turning on two-factor authentication for email, in that order, because email is the account that can reset almost everything else if it's compromised. I don't get into the technical detail of how a password manager works or which one to choose in that first conversation, I just tell them it exists, that it takes about five minutes to install, and that it will fix the reused-password problem almost every person I've ever talked to has without realising how much risk it creates. Once that's installed, turning on two-factor for email is usually a two-minute job inside the account's own security settings, and I stay on the phone or in the room while they do it, because a task that gets left for later usually stays left.

The One Habit That Matters More Than Any Setting

If there's a third thing I make time for, it's not a setting at all, it's a habit: treating any message that creates pressure to act immediately as suspicious by default, regardless of who it claims to be from. I've written elsewhere about why that particular pressure is the thread running under almost every scam format, but in a ten-minute conversation I keep it simple: if something wants an answer right now, wait five minutes and check it a different way before doing anything. That one habit catches more than any piece of software does, and unlike a setting, it doesn't need updating or renewing.

What I Deliberately Leave Out of That First Conversation

I don't mention VPNs, antivirus software, router settings, or backup strategy in that first ten minutes, not because they don't matter, but because introducing five more things guarantees none of them get done either. Those are things I'll happily go into if someone's genuinely interested or comes back with a specific worry, but they're not where the risk actually concentrates for most people. A reused password and a slow reaction to a fake emergency cause far more real damage, in my experience, than a missing VPN ever does. Being selective isn't the same as being incomplete, it's recognising that ten minutes spent on the two highest-impact changes beats an hour spent on everything at once.

Where I Send Someone Once They Want to Go Further

For the people who do want more once the basics are in place, I point them toward a proper priority order to work through themselves, rather than trying to cram it into the same conversation. The NCSC also has solid general guidance if someone wants a source that isn't just my opinion. And I always mention my free Safety Toolkit at the end, mostly because it means the conversation doesn't have to end when I leave the room, they've got something to come back to if a question occurs to them later that evening.