
Four Skills, One Safer Internet
The habits that actually protect you, explained in plain language
October is Cybersecurity Awareness Month. Instead of a long list of rules, we’re focusing on four skills that protect people the most: spotting scams, keeping devices updated, using two-step login, and browsing safely. These are the topics that come up again and again in our workshops, our Digital Navigator training, and conversations with the organizations we serve.
No jargon, and no technical background needed. If you work with clients, each section ends with a Navigator Tip: a short session you can run one-on-one.
Skill 1: Spot Scams Before They Spot You
The call, text, or email that isn’t what it seems
Phishing is when a scammer pretends to be someone you trust, like your bank, Medicare, Amazon, or even a family member, to get your money, passwords, or personal information.
It’s the most common way online fraud starts. It works not because people are careless, but because today’s scams are designed to look and sound real.
What scams look like now
For most of the people we work with, scams don’t arrive by email. They arrive as a phone call or a text message. Common ones we hear about from our partners:
- A caller says they’re from Medicare, Social Security, or the IRS and there’s a problem with your account.
- A text says your package couldn’t be delivered, or your bank account has been locked, with a link to “fix it.”
- A pop-up on your computer says you have a virus and gives you a number to call for “tech support.”
- Someone on Facebook Marketplace or another selling site asks you to pay in advance or send a code.
- A caller sounds exactly like your grandchild or another relative, says they’re in trouble, and asks for money right away. Scammers can now use AI to copy a person’s voice from a short video clip.
The Warning Signs
They rush you. “Act now.” “Your account will be closed today.” “Don’t hang up.” Real banks, government agencies, and doctors’ offices don’t demand action within minutes. If you feel rushed, that feeling is the warning.
They ask you to pay in an unusual way. Gift cards, wire transfers, cryptocurrency, or a payment app to someone you don’t know. No real agency or company asks for payment in gift cards. Ever.
They ask for information they should already have. Your bank won’t call or text to ask for your PIN, your full password, or your Social Security number.
They ask you to keep it secret. “Don’t tell your family” or “don’t talk to the bank” is a red flag.
Something is slightly off. A sender address with a misspelling, a phone number you don’t recognize, or a greeting like “Dear Customer.”
What to do
Hang up and call back. If someone says they’re from your bank or Medicare, hang up and call the number on the back of your card or on an official letter. Don’t use the number they gave you.
Don’t tap the link. Open the app or type the website address yourself.
Check with family directly. If a relative calls asking for money, hang up and call them back on the number you already have. Some families agree on a code word for emergencies.
Ask someone. Show the message to a friend, family member, or Digital Navigator before you do anything. A second person breaks the spell of urgency.
Report it. Use the “report spam” or “report junk” option on your phone or email, and report scams at ReportFraud.ftc.gov.
It happens to more people than you’d think
A man came into the rural office of one of our partners, Family Services Association of San Antonio, for help getting his driver’s license. While helping him, staff noticed more than $3,000 was missing from his bank account. He had no idea he’d been scammed. Staff worked with him until he got his money back. He was lucky he came in when he did, and the team’s question stuck with us: how many others haven’t noticed yet?
Navigator Tip: 10 minutes
Ask your client to show you the last few texts or calls they weren’t sure about. Go through them together using the warning signs above. Then help them turn on spam filtering on their phone and save their bank’s real phone number in their contacts.
Teach this skill
Common Scams workshop, which teaches learners to recognize red flags in email, text, and phone scams (part of the Staying Safe Online bundle): https://lift.thinkific.com/bundles/staying-safe-workshops
Teaching Internet Safety & Responsibility (free course for instructors), which includes personal data security and phishing prevention: https://lift.thinkific.com/courses/internet-safety-responsibility
Skill 2: Keep Your Devices Updated
The protection most people skip
Software updates are the least exciting part of staying safe online. They’re also one of the most important.
When someone finds a weak spot in a phone, computer, or app, the company races to fix it. That fix arrives as an update. Until you install it, the weak spot stays open, and scammers know exactly where to look.
Many successful attacks target problems that already have a fix available, on devices where the update was never installed. That’s entirely preventable.
Let your device do it for you
The easiest way to stay updated takes no effort at all: turn on automatic updates.
On an iPhone or iPad: Settings > General > Software Update > Automatic Updates.
On most Android phones: Settings > System > Software update. The exact wording varies by brand.
On a computer: look for “Windows Update” or “Software Update” in your settings.
Don’t forget your apps
Apps update separately from your phone itself. Your banking app, email, and WhatsApp all need updates too. Turn on automatic app updates in the App Store or Google Play Store.
Is your device too old to get updates?
This is the part most guides skip. Phones, tablets, and computers stop getting security updates after a few years. Many people use hand-me-down, refurbished, or donated devices, which may already be past that point.
To check, go to the software update screen. If it has said “up to date” for a long time and your device is several years old, search online for your device’s model name and “security updates end” to find out whether it’s still supported.
If it isn’t, the device still has value: it’s fine for video calls, photos, and the news. Just avoid using it for banking, health portals, or anything with personal information.
Navigator Tip: 5 minutes
Sit with your client and turn on automatic updates for their device and their apps. Then check together whether the device still receives security updates. It’s one of the quickest sessions you can run, with protection that lasts for years.
Teach this skill
Digital Navigator Overview (free course), which prepares staff and volunteers for patient, one-on-one device help: https://lift.thinkific.com/courses/navigators-overview
Device curriculum for Android, iPhone, iPad, Chromebook, and Windows, available in English, Spanish, Chinese, and Tagalog: https://digitallift.org/curriculum/
Skill 3: Turn On Two-Step Login
The deadbolt for your accounts
Imagine your front door only had one lock, and copies of keys like yours were regularly stolen and sold to strangers. That’s what an account protected only by a password looks like today.
Two-step login, also called two-factor authentication, 2FA, or multi-factor authentication (MFA), adds a second lock. After you type your password, you also confirm it’s you, usually with a code sent to your phone, a fingerprint, or your face.
Even if someone steals your password, they can’t get in without that second step. It stops most account takeovers, and it takes about three minutes to set up.
Where to turn it on first
Start with the accounts that matter most: your email (because it can reset every other password), your bank, your health portal, and your social media. Look for “Security,” “Login,” or “Two-step verification” in each account’s settings.
The most important rule
Never share a login code with anyone who calls, texts, or messages you. Not your bank, not Medicare, not “tech support,” not someone who says they sent it by mistake.
Your bank will never ask you to read them a code. If someone asks for one, it’s a scam, every time. This is how scammers get past two-step login, so this rule matters more than any setting.
If your phone number changes, or you share a phone
Text-message codes go to your phone number. If you use a prepaid phone, switch plans often, or share a phone with family, you can get locked out of your own accounts.
Protect yourself:
- When you set up two-step login, save the backup codes most accounts offer. Write them on paper and keep them somewhere safe at home.
- If your number changes, update it in your important accounts right away, starting with email.
- If your phone allows it, consider an authenticator app, which creates codes on your phone without depending on your phone number.
“It’s a hassle”
It does add a step. But for accounts that hold your money, your health information, and your messages, that extra step is worth it.
Navigator Tip: 15 minutes
Help your client turn on two-step login for their email account. Write the backup codes on paper together. Then practice saying out loud: “I never share my codes with anyone who contacts me.” People remember a rule better when they’ve said it themselves.
Teach this skill
Password Management workshop, which helps learners create and manage strong passwords: https://digitallift.org/workshops/
Teaching Internet Safety & Responsibility (free course for instructors), which includes account and password security: https://lift.thinkific.com/courses/internet-safety-responsibility
Skill 4: Browse Safely
Using the internet without leaving the door open
Most of the internet is safe. Some of it is built to trick you. Browsing safely isn’t about avoiding the internet. It’s about a few habits that keep you on the right side of that line.
Check the website name, not just the lock
You may have heard that a lock icon or “https” means a site is safe. It means your connection is private, but scam sites use it too. What matters more is the website’s name.
Before you sign in or pay, look at the address bar. Is it really your bank’s name, spelled correctly? A scam site might use something close, like “yourbank-account-help.com” instead of “yourbank.com.”
Even better: save your bank’s and health portal’s real addresses as bookmarks, or use their official apps, and always go in that way.
Look before you tap a link
Links in texts, emails, and social media can say one thing and go somewhere else. On a computer, hover your mouse over a link to see where it really goes. On a phone, press and hold the link to preview it. If it doesn’t match, don’t tap it.
Public Wi-Fi: use it wisely, not fearfully
For many people, Wi-Fi at the library, a community center, or a coffee shop is their main way to get online. That’s fine. Reading the news, watching videos, searching for jobs, and checking email are generally low risk.
For banking, health portals, or anything with personal information, a few simple steps help:
- Use the official app instead of a web browser.
- Make sure you’re connected to the right network. Ask staff for the exact network name, since scammers sometimes set up look-alike networks.
- If you have a phone data plan, switch off Wi-Fi for sensitive tasks.
- Be careful with free VPN apps. Some of them collect and sell your information. If you’re not sure, skip them.
Download with care
Only download apps from the App Store or Google Play Store. Don’t open attachments from people you don’t know. If a website says you “must” download something to continue, close it.
Don’t take the bait: misinformation and clickbait
Not everything unsafe online is trying to steal your password. Some of it is trying to fool you, or just to get your click.
Misinformation is false or misleading information. It matters because it spreads fast, and it can lead people to make real decisions about their health, their money, or their vote based on things that aren’t true.
Why we fall for it. False stories are often built to make us feel something strongly: fear, anger, or excitement. They often confirm what we already believe, and they usually reach us through friends and family we trust. None of that makes someone gullible. It makes them human.
Clickbait. Headlines like “You won’t believe what happened next” or “Doctors hate this one trick” are designed to make you curious enough to click. Often the page behind them is full of ads, has little real information, or leads somewhere unsafe.
Not all fake news is the same. Some stories are completely made up. Some take a real photo or quote and put it in the wrong context. Some are jokes or satire that get shared as if they were true. And some have a misleading headline over an otherwise accurate story.
How to spot it:
- Notice your reaction. If a post makes you instantly angry or afraid, slow down before you share it.
- Read past the headline. The article may not say what the headline claims.
- Check who’s behind it. Is it a source you recognize? Does the website name look right?
- Look for it elsewhere. If something big really happened, other trusted news sources will be reporting it too.
- Check the date. Old stories often get recirculated as if they were new.
When in doubt, don’t share it.
Navigator Tip: 10 minutes
Help your client bookmark the real websites for their bank, health portal, and email, or install the official apps. Show them how to press and hold a link to preview it. Then pick one post from their social media feed and walk through the “How to spot it” questions together.
Teach this skill
Misinformation & Clickbait workshop, with hands-on practice, group discussion, a slide deck, lesson plan, and printable handouts: https://lift.thinkific.com/courses/misinformation
Staying Safe Online bundle, which adds Online Shopping (safe shopping and best practices) and Common Scams: https://lift.thinkific.com/bundles/staying-safe-workshop
Teaching Internet Safety & Responsibility (free course for instructors), which includes media literacy: https://lift.thinkific.com/courses/internet-safety-responsibility
Four Skills, No Technical Background Required
This is what cybersecurity looks like when it’s built for everyone: not a list of complicated rules, but a few specific habits that protect real people’s money, health information, and peace of mind. 88% of digitalLIFT learners we surveyed say they navigate the internet more safely.
Our device curriculum is available in Spanish, Chinese, and Tagalog as well as English.
For organizations: teach these skills yourself
If you work with people who need this, as a Digital Navigator, librarian, health worker, case manager, or volunteer, start with our two free courses:
Teaching Internet Safety & Responsibility, covering account and password security, phishing, and media literacy: https://lift.thinkific.com/courses/internet-safety-responsibility
Digital Navigator Overview, to prepare your staff and volunteers for patient, one-on-one help: https://lift.thinkific.com/courses/navigators-overview
When you’re ready to bring workshops to your community, each one is ready for your team to run as many times as you need:
Common Scams: recognizing red flags in email, text, and phone scams
Misinformation & Clickbait: spotting deceptive content through hands-on practice and discussion, with a slide deck, lesson plan, and printable handouts: https://lift.thinkific.com/courses/misinformation
Staying Safe Online bundle, which includes Common Scams, Misinformation & Clickbait, and Online Shopping: https://lift.thinkific.com/bundles/staying-safe-workshops
Password Management and the full workshop catalog: https://digitallift.org/workshops/
To build a full program:
Digital Navigators: Advanced: https://lift.thinkific.com/courses/advanced-navigators
Aging Services, Healthcare, and Libraries packages: https://digitallift.org/packages/
If you or someone you know has been scammed
It’s not your fault, and acting fast helps.
Call your bank right away.
Report it: ReportFraud.ftc.gov
Recover from identity theft: IdentityTheft.gov
Free, confidential support for people of any age: AARP Fraud Watch Network Helpline, 877-908-3360
— digitalLIFT | digitalLIFT.org

Comments are closed.