Keeping Your Devices Safe
Updates, Malware, Public Wi-Fi and Lost Devices
Most device security comes down to a handful of habits rather than expensive software. This guide explains what actually protects you, and what is mostly marketing.
Technology & Digital Life
↓
Chapter I
How Devices Get Compromised
The Few Ways That Cause Most Problems
Headlines about hacking suggest sophisticated attacks by criminals in hoodies. The reality for most people is far more ordinary. The majority of successful attacks on individuals rely on a small number of simple methods.
The most common is deception. Criminals send emails, texts and messages that look legitimate and persuade people to click a link, open an attachment, enter a password on a fake site or install software. This is known as phishing, and it works because it targets people, not machines. The second is exploiting known flaws in software that has not been updated, which lets malware in without any action from the user. The third is reused or weak passwords, which allow criminals to take over accounts using lists of credentials stolen from other services. A fourth is installing software or apps from unofficial sources, which may carry hidden malware.
Malware is a general term for malicious software. It includes viruses that spread between files, spyware that watches what you do, ransomware that locks your files until you pay and trojans that pretend to be something useful. Modern malware is often designed to be silent, so you may not know that you have it.
The National Cyber Security Centre, part of GCHQ, publishes plain-English advice for individuals, based on the idea that a few basic habits stop the great majority of attacks: keep software updated, use strong, unique passwords and two-step verification, back up your data and be suspicious of unexpected messages.
Most successful attacks do not break into your device. They persuade you to open the door.
· · ·
"Most successful attacks do not break into your device. They persuade you to open the door."
Chapter II
Updates: Your Best Defence
Why They Matter and How to Manage Them
If you do only one thing for your security, install updates. They are the single most effective protection that most people can adopt.
When researchers or criminals find a flaw in software, the maker produces an update to fix it. Once the fix is released, the flaw becomes public knowledge, and criminals use it against people who have not updated. That is why leaving an update for weeks, however inconvenient, leaves you exposed. Switch on automatic updates for your operating system, your browser and your apps, so that you do not have to remember.
Devices also reach the end of their supported life, after which the maker no longer issues security updates. Windows 10, for example, reached the end of its standard support in October 2025. Phones and tablets stop receiving updates after a number of years, which varies by manufacturer. A device that does not receive updates becomes steadily more dangerous to use, especially for banking and email. Check the support dates for your devices, and plan to replace those that are no longer supported, or at least avoid using them for sensitive tasks. Some manufacturers offer extended security updates for a fee.
Do not forget other devices. Routers, smart TVs, printers, cameras and smart home equipment also need updates, and many are neglected. Check them from time to time.
Safe Updating
Only install updates through the device's own settings or the official app store. Never click on a pop-up in a web page that claims that your computer needs an update, or on a link in an unexpected message. These are common ways of delivering malware.
· · ·
Chapter III
Protection Software and Safe Browsing
What You Actually Need
The security software industry sells a great deal of protection, and some of it is useful. But the right choice for most people is simpler than advertising suggests.
Modern operating systems come with built-in protection. Windows includes Microsoft Defender, which is well regarded by independent testers and is adequate for most home users. Macs include several layers of built-in protection, and iPhones and iPads have a tightly controlled app system that makes malware rare. Android phones are protected by Google Play Protect, and most malware reaches Android through apps installed from outside the official store. For many people, built-in protection, kept up to date, together with good habits, is enough. Paid security suites may add features such as password managers, identity monitoring and parental controls, which some people find useful, but are not essential.
Be careful with free security tools offered by pop-ups or adverts, and beware of fake virus warnings that claim your device is infected and tell you to call a number or download a program. These are scams. Close the browser and, if necessary, restart your device. If you have called a number or let someone have remote access, change your passwords from a different device and contact your bank.
Browse sensibly. Keep your browser updated, use an ad blocker if you wish, and be suspicious of sites that offer something too good to be true, such as free films, cracked software or prizes. Download programs only from the maker's website or official stores, and check the address carefully.
· · ·
"The best security software in the world cannot help a device that stopped receiving updates."
Chapter IV
Public Wi-Fi, VPNs and Travelling
Staying Safe Away From Home
Public Wi-Fi in cafés, stations, hotels and airports is convenient, and it carries some risk. The risk is real but often overstated.
Most websites and apps now encrypt their traffic using HTTPS, which means that even on an open network, other users cannot easily read what you send. The padlock symbol in the browser indicates an encrypted connection, although it does not show that the site is trustworthy. The more serious risks on public networks are fake hotspots set up with a name that looks genuine, and the possibility that someone on the same network could attempt to interfere with unprotected traffic. Confirm the exact network name with staff, and avoid doing sensitive tasks, such as banking, on public Wi-Fi if you can. Your phone's mobile data is usually safer.
A virtual private network, or VPN, encrypts your connection to a server run by the VPN provider. It can protect you on untrusted networks, and can hide your internet address from websites. However, it does not make you anonymous, it does not protect you from phishing or malware and it means that you must trust the VPN provider with your traffic. Choose a reputable, independently audited provider, and be wary of free VPNs, some of which make money by selling data. Many people do not need a VPN for everyday use.
Travelling brings additional risks. Keep devices with you and locked, avoid charging from unknown public USB ports, which can be tampered with, in favour of your own charger or a power bank, and be cautious of shoulder surfing when entering passwords.
· · ·
Chapter V
Lost, Stolen and Hacked Devices
What to Do When Something Goes Wrong
Sooner or later, many people lose a device or find that an account has been compromised. Preparation reduces the harm, and prompt action limits the damage.
Prepare in advance. Use a screen lock on every device, switch on device encryption, which is on by default on most modern phones and available on computers through tools such as BitLocker and FileVault, and enable the find-my-device feature. Keep backups. With these steps in place, a lost device is an inconvenience rather than a disaster.
If a device is lost or stolen, use the find-my-device service to locate it, lock it and, if necessary, erase it remotely. Report theft to the police and ask your mobile provider to block the SIM and, for stolen phones, the handset. Change passwords for key accounts, especially email and banking, and review active sessions. Tell your bank if you use banking apps.
If you think an account has been hacked, change the password immediately from a device that you trust, using a unique new password, and switch on two-step verification. Check the account's recovery email, phone number and forwarding rules, which attackers often change. Tell your contacts if someone could be sending messages in your name, and watch your bank statements. If you used the same password elsewhere, change those too. If you have been the victim of fraud, contact your bank at once and report it to the police.
Check for Breaches
The free service Have I Been Pwned lets you check whether your email address has appeared in known data breaches. If it has, change the passwords for the affected services and any others where you used the same one.
· · ·
Chapter VI
Building Good Habits
A Realistic Routine for Everyday Security
Security is a habit, not a product. A small set of routines, practised regularly, provides far more protection than any tool.
Set up a short monthly check. Confirm that automatic updates are on and that no important updates are waiting. Review your apps and delete those you no longer use. Check your backups. Glance at your accounts for anything unfamiliar, such as unknown devices signed in or unexpected transactions. Run a check on your passwords using a password manager if you have one.
Practise safe habits every day. Pause before clicking links, particularly in messages that create urgency. Look at the sender's address and the web address. Do not open unexpected attachments. Use a separate, strong password for your email and your main accounts. Lock your screen when you leave a device, and do not leave devices unattended in public places.
Teach those around you. Families and small businesses are only as secure as their weakest member. Explain the basics to children and older relatives, agree a way to check unusual requests, and share what you learn about new scams. If you run a small business, the National Cyber Security Centre's guidance and the Cyber Essentials scheme offer a practical framework.
The Five Habits
Update everything. Use strong, unique passwords and two-step verification. Back up what matters. Think before you click. Know what to do if something goes wrong.
· · ·
We try to respond to all messages within 48 working hours, please be patient, we will get back to you.
Your cookie preferences
We use cookies to keep the site working, to understand how it is used and, with your permission, to show embedded video. Accept all, reject everything that is not strictly necessary, or choose your own settings. Read our policies for more detail.
Cookie preferences
Choose which cookies you are happy for us to use. Strictly necessary cookies are always active because the site cannot work without them. Your choices are stored for 30 days and you can change them at any time using the cookie settings link in the footer. See our policies for more detail.
Always on
Strictly necessary cookies allow core website functionality such as user login and account management. The website cannot be used properly without strictly necessary cookies.
Name
Provider / domain
Expiry
Purpose
PHPSESSID
PHP.netjwbiz.co.uk
Session
General purpose identifier used to maintain user session variables. Normally a randomly generated number.
mf_has_cookie
jwbiz.co.uk
1 day
Used to indicate whether the user's browser supports cookies.
mc_cookie_consent
jwbiz.co.uk
30 days
Stores your cookie consent preferences. Required for the cookie banner to work correctly.
browserupdateorg
jwbiz.co.uk
7 days
Used to track if a user has been shown a message suggesting they update their web browser.
Performance cookies are used to see how visitors use the website, e.g. analytics cookies. Those cookies cannot be used to directly identify a certain visitor.
Name
Provider / domain
Expiry
Purpose
is_unique
StatCounter Ltd.statcounter.com
1 year 1 month
Determines whether you are a first-time or returning visitor.
is_visitor_unique
StatCounter.statcounter.com
1 year 1 month
Assigns a unique visitor ID to track navigation and interaction for statistical purposes.
Targeting cookies are used to identify visitors between different websites, e.g. content partners, banner networks. Those cookies may be used by companies to build a profile of visitor interests or show relevant ads on other websites.
Name
Provider / domain
Expiry
Purpose
VISITOR_INFO1_LIVE
Google LLC.youtube.com
6 months
Set by YouTube to keep track of user preferences for embedded videos and to determine whether the visitor is using the new or old YouTube interface.
YSC
Google LLC.youtube.com
Session
Set by YouTube to track views of embedded videos.
Functionality cookies are used to remember visitor information on the website, e.g. language, timezone, enhanced content.
Name
Provider / domain
Expiry
Purpose
sc_is_visitor_unique
StatCounter Ltd.jwbiz.co.uk
1 year 1 month
Used to store number of visits.
Unclassified cookies are cookies that do not belong to any other category or are in the process of categorisation.