The Safety Habits I Tell Every New Client to Start With
The First Thing I Ask Every New Client
When someone gets in touch with me for the first time, before we talk about anything fancy, I ask one simple question: what would happen if your phone got stolen right now. Most people go quiet for a second, and that pause tells me everything I need to know. It's not because people are careless, it's because nobody ever sits them down and walks through the basics properly. That's what this piece is for, the exact habits I ask every new client to put in place first, in the order I ask them to do it. None of it is complicated on its own, the problem is that nobody ever explains it in order, so people end up doing three unrelated things and missing the two that actually matter most.
Passwords and Two Factor Authentication, Sorted Once
The single biggest change I see in someone's security, and it usually takes under an hour, is moving to a proper password manager like NordPass. If you're reusing the same three passwords across your email, your bank, and your Tesco Clubcard account, one leaked password is all it takes for a criminal to try it everywhere else. A password manager fixes that in one go, and once it's set up you genuinely stop thinking about it. Right behind that comes two factor authentication on your email account specifically, because your email is the recovery route into almost everything else you own online. If a criminal gets into your inbox, they can reset the rest. I always ask which email address a client's other logins are tied to, because that one account is usually worth more to a criminal than the bank login itself.
Slowing Down Before You Click
Most scams rely on speed. A text that says your parcel couldn't be delivered, an email that says your account's been suspended, a WhatsApp message from a family member needing money fast. They all want you to act before you think. The habit I try to build in every new client is a five second pause before clicking anything that creates urgency. That pause is where most scams fall apart, because the moment you actually look at the sender's address or the link underneath the button, the cracks show. I've written more on spotting this properly if you want to go deeper. The five second pause costs nothing, and I've never once had a client tell me it made them miss something that turned out to be genuine.
Checking Whether Anything Has Already Been Exposed
The first thing I do with a new client is check whether their email address has already turned up in a data breach, because that tells me a lot about how urgent the rest of the conversation needs to be. I use Have I Been Pwned for this, it's free and it takes about ten seconds to search an email address against thousands of known breaches. If something comes back, it doesn't mean panic, it means we go through exactly which passwords need changing first and whether that old, breached password is still being reused anywhere else.
Locking Down the Home Network
Your router is the front door to everything else in your house that connects to the internet, and most people have never once changed its default settings. Renaming it, setting a proper password, and turning on the built in firewall takes about fifteen minutes and closes off a route into your home network that most people don't even know exists. I've put together a full walkthrough of the process if you want to follow along step by step, and more habits like it are sitting in my Safety Toolkit. It's one of the few security jobs you genuinely only have to do once, which makes it a strange thing for so many people to still be putting off.
Keeping Your Software and Backups Actually Up to Date
The second thing I check is whether automatic updates are actually switched on, not just installed once and forgotten. Phones, laptops, and routers all patch known security holes through updates, and most of the serious break-ins I hear about started with a device that was months behind on patches everyone else had already applied. The other habit that goes with this is a proper backup, something offsite or cloud based that keeps working even if a laptop gets lost, stolen, or hit with ransomware. I'd rather a client spend twenty minutes setting up automatic backups once than lose years of photos and documents because a hard drive failed on an ordinary Tuesday.
What I Tell People to Do This Week
If you take nothing else from this, do these three things this week: get a password manager sorted, turn on two factor authentication on your email, and check your router's default settings haven't been left switched on since the day it arrived. None of it is complicated, and none of it needs a technical background, it just needs doing. If a company you've used ever has a data breach, the Information Commissioner's Office keeps a public register of enforcement action, which is worth a look if you're ever unsure whether a company handled your data properly. And if you'd rather I just walk you through your own setup directly, get in touch and we'll sort it together. Most of the clients I see six months later aren't the ones who did everything perfectly on day one, they're the ones who actually kept these habits going instead of letting them slide the moment life got busy.

