Helping an Older Parent Stay Safe Online, Without Taking Over
My mum is seventy-three and she is not daft. She reads more than I do, she manages her own money, and she has been running a household since before I was born. So when I started helping her with online safety, the worst thing I could have done was talk to her like she was a child who had wandered into traffic. I did it anyway at first, and it went about as well as you would expect.
What follows is what I actually do now, after getting it wrong for a good while. It works because it treats the person as capable, which they are, and because it puts the boring protective stuff in place quietly in the background rather than turning every phone call into a lecture.
Why the big scary talk never works
The instinct is to sit someone down and list everything that could go wrong. Fake bank texts. Cloned voices. Romance scams. Dodgy links. By the end of it they feel got at, slightly stupid, and no safer than when you started, because nothing has actually changed on their devices.
Worse than that, it makes them less likely to tell you when something does happen. Nobody wants to ring the person who warned them and admit they clicked the thing. That silence is the real danger. Most of the damage in a scam happens in the hours after the click, not the click itself, and those are exactly the hours when someone is sat there feeling too embarrassed to say anything.
So I stopped doing the talk. I do the setup instead, and I keep the conversation short and specific.
The three things I set up before anything else
First, two-factor authentication on email. Not on everything, just email to begin with. Email is the master key, because it is where every password reset lands, and if someone else has it they can walk into everything else. It takes about five minutes and it is the single biggest jump in safety you can give anyone. I have written out the exact steps I use in my guide to setting up two-factor authentication if you want to follow along.
Second, a password manager. This is the one that gets the most resistance, because it sounds technical and it sounds like one more thing to remember. It is genuinely the opposite. It means they remember one password instead of forty, and it means the same password stops being reused across the bank, the supermarket and some forum they joined in 2011. I use NordPass myself and I set it up on my mum's phone in an afternoon.
Third, and this one costs nothing, I made myself the safe person to ring. I said, out loud and more than once, that if anything ever looks off she should ring me and I will never make her feel silly about it. That sentence has been worth more than every other bit of setup combined.
The scams I see catching that generation most
It is rarely the exotic stuff. Three formats do most of the damage.
Delivery texts, because everyone is expecting a parcel and the message arrives with a plausible tracking number and a link that wants a small redelivery fee. The fee is not the point. The card details are.
Bank impersonation calls, where someone rings claiming to be from the fraud team and creates just enough panic that thinking straight becomes difficult. The tell is always the same: a real bank will never ask you to move money to a safe account, because no such thing exists.
And the slow ones. Someone friendly turns up in a comment section or a messaging app, builds a rapport over weeks, and only asks for anything much later. These are the ones that hurt the most, because by the time it goes wrong there is real affection involved.
I go through the scams people ask me about most often in more detail elsewhere, but those three cover the bulk of it.
How I explain things without the jargon
I have one rule. If I cannot explain it using something from ordinary life, I have not understood it well enough myself to be teaching it.
Two-factor authentication is not two-factor authentication. It is the chain on the front door. The key gets you to the door, the chain means someone still has to prove who they are before you let them all the way in.
A password manager is not a vault with encryption. It is the drawer where you keep all your keys, and only you have the drawer key.
Phishing is not phishing. It is somebody in a high-vis jacket walking into a building like they belong there, because nobody questions a man with a clipboard.
Nobody needs the technical word. They need the picture. Once the picture is in their head, the behaviour follows on its own and you never have to nag about it again.
What to do when it has already happened
Sometimes you are not preventing anything, you are cleaning up. The order matters more than the speed.
Ring the bank first, on the number printed on the back of the card, never a number from the message that started all this. Then change the email password, then the passwords for anything that used the same one. Then report it, which in the UK means Action Fraud, and which matters even when nothing was lost, because the reporting is how the patterns get spotted.
And then, and I mean this, do not do the post-mortem. Do not talk them through everything they should have spotted. They know. What they need is to come out of it still willing to tell you next time.
Everything I have mentioned here, the password manager, the two-factor setup, the lot, is in my safety toolkit if you would rather see the tools in one place than piece it together yourself.
