The Order I'd Tackle Your Online Security In If You're Starting From Scratch

Sep 02, 2026By Jay Kells
Jay Kells

People ask me where to start more than almost anything else, and the honest answer is that most advice out there is either too vague to act on or too long to actually finish. So here's the order I'd genuinely work through myself if I was starting from nothing, based on what stops the most damage for the least effort, not what makes the longest checklist.

Start With a Password Manager, Before Anything Else

If you only do one thing this week, make it this. Password reuse is still the single biggest reason accounts get taken over, because one leaked password from an old, forgotten site gets tried against everything else you own. A password manager fixes that in one sitting. It generates a unique, complicated password for every account and remembers it for you, so you never have to. I moved everything into one years ago and it's still the change that's done the most for my own security, by a wide margin.

Turn On Two-Factor Authentication Next, Even If It Feels Like a Hassle

Once your passwords are unique, two-factor authentication is what stops a leaked or guessed password from being enough on its own. I used to find the extra step annoying, and I'll admit I put it off longer than I should have. I've written before about the excuses I used to make about this myself and looking back, none of them held up once I actually tried it for a week. Start with email and banking, since those two accounts can be used to reset almost everything else if someone gets into them.

Update Everything and Then Leave Auto-Updates On

Most of the exploits that actually get used against ordinary people target known, already-patched vulnerabilities that people just haven't updated yet. It's not usually some clever new attack, it's an old door someone forgot to lock. Go through your phone, laptop, and router once, update everything that's behind, then turn on automatic updates so you're not relying on remembering to do this again. This is part of the same routine I run through every time I set up a new device, and it takes far less time than people expect.

Back Up What You'd Actually Miss

Backups don't stop an attack, but they take away most of the reason to panic if one succeeds. If ransomware locks your files or your phone ends up at the bottom of a river, a recent backup means you've lost time, not everything. This doesn't need to be complicated. Turning on the automatic cloud backup that's already built into your phone or laptop covers most people's needs without any extra decisions to make.

Neatly labeled storage bins and boxes organized on metal shelving inside climate-controlled storage unit

Learn to Pause Before You Click, Not Just What to Click

Every list of scam warning signs eventually goes out of date, because scammers update their scripts faster than anyone can update the lists. What doesn't go out of date is a habit of pausing before you act on anything urgent, whether that's a text, an email, or a phone call. If something is pushing you to act immediately, that urgency is usually the tell, not the request itself. The NCSC has some good general guidance on this if you want to read more, and it's held up well against everything I've seen change since.

Everything After This Is Optimisation, Not Essentials

Once those five things are in place, you've covered the overwhelming majority of how people actually get compromised. Everything past this point, from VPNs to antivirus software to more advanced privacy settings, is worth doing eventually, but it's optimisation on top of a foundation rather than the foundation itself. If you want a simple place to keep track of all of this as you work through it, my free Safety Toolkit walks through the same order I've laid out here.