What's Actually Working to Keep People Safe Online
For years I watched people write off scams and hacking as something that happens to someone else, somewhere else. Not any more. I hear from more people every month who've had a scam text, a dodgy email, or a mate who's lost money to a fake delivery link. The good news is that awareness is finally catching up with the threat, and that's half the battle won. What I want to cover here isn't the doom and gloom version of this story, it's the parts that are actually working, the things I see making a real difference when I talk to people about staying safe online.
Community Sessions Are Making a Real Difference
Libraries, community centres and local groups everywhere are running free sessions on staying safe online, and I love seeing it. These aren't dry lectures either. They're practical, hands on, and aimed at real problems: spotting a phishing email, setting a password you'll actually remember, and understanding what your social media privacy settings are quietly sharing with the world. If you've never been to one, it's worth a look. And if you can't make it, that's exactly why I write this blog, so you get the same advice without leaving the sofa. I've sat in on a few of these sessions myself over the years, partly out of curiosity and partly to see what questions people are actually asking rather than the ones I assume they're asking, and the gap between the two is bigger than you'd think.
Schools Are Teaching the Next Generation
I'm genuinely encouraged by how many schools now build online safety into the curriculum rather than treating it as an afterthought. Kids are growing up online from primary school onwards, so teaching them to spot a scam or think before they click matters just as much as teaching them to cross the road safely. It sets habits that last a lifetime, and honestly, some of what they're learning would do half the adults I know some good too. I've had conversations with parents who tell me their kids come home and correct them on password habits, which is exactly the kind of role reversal I'm happy to see. A habit taught at eight years old tends to stick in a way that advice given to a busy adult at thirty five often doesn't.
Small Businesses Are Stepping Up Too
It's not just individuals either. More small businesses are taking cybersecurity seriously, and not before time, because a single phishing email can cost a small firm thousands and take months to recover from. I've written a full guide on protecting small businesses if that's you, covering the basics you need without the jargon or the eye watering price tag. What I notice most with small business owners is that they usually know they should be doing more, they just don't know where to start or what actually matters versus what's being sold to them as essential. That gap between knowing and doing is where most of the damage happens.
The Advice That's Finally Landing
A few years ago, telling someone to use a password manager got a shrug or a "that sounds like a hassle." I'm hearing that a lot less now. Something has shifted, whether it's a friend who got caught out, a news story that hit closer to home, or simply enough repetition that the message has finally sunk in. The same goes for two-factor authentication, which used to feel like an extra step nobody wanted to bother with and now gets treated as basic common sense by a growing number of people I talk to. I think part of what's changed is that the advice itself has gotten simpler. Fewer people are being told to memorise sixteen random characters, and more are being pointed towards tools that do the remembering for them.
Where I Still See Gaps
I don't want to make this sound like the job is done, because it isn't. The people who are engaging with this advice tend to be the ones who were already halfway there, reasonably tech confident, already a bit cautious. The people I worry about most are the ones who don't see themselves as a target at all, who assume scammers only go after people with obvious wealth or people who are careless. That assumption is exactly what makes them a target. Scammers don't care how careful you think you are, they care whether a message catches you at a distracted moment, and that can happen to anyone regardless of how switched on they normally are. I've spoken to retired professionals who ran entire departments in their careers and still got caught out by a fake courier text, simply because it landed on a busy Tuesday morning between two other things demanding their attention. Confidence in your own judgement is not the same thing as protection, and the sooner people separate those two ideas the better.
How You Can Be Part of It
You don't need to run a workshop or rewrite your company's IT policy to make a difference. Start small. Use a proper password manager instead of reusing the same password everywhere, I use NordPass myself and it's removed the guesswork entirely, learn to spot the signs of a phishing email, and report scams when you see them rather than just deleting and moving on, Action Fraud makes it painless. Have a browse of my Safety Toolkit for the tools I actually use myself, or get in touch if you'd like some straight talking advice tailored to you or your business.
