The Online Safety Tips I Actually Think Matter, and the Ones I Don't
The Online Safety Tips I Actually Think Matter, and the Ones I Don't
Every few weeks someone sends me one of those lists, forty tips for staying safe online, and asks what I think of it. My honest answer is always some version of the same thing. A handful of the items genuinely matter. Most of it is filler added to hit a word count. And a few items are advice I actively disagree with, the kind that sounds responsible but doesn't actually protect anyone in practice. I've written enough of these posts myself and heard from enough people who tried to follow lists like that to have a fairly settled view on which tips earn their place and which ones I've quietly stopped repeating.
Why I Stopped Treating Every Tip the Same
The problem with most safety lists is that every item gets presented with equal weight. Use a strong password sits next to clear your browser history weekly as if the two carry the same importance, when one of those genuinely determines whether your accounts get compromised and the other does almost nothing measurable. When everything looks equally urgent, people either try to do all of it and burn out, or they read the whole list and do none of it because it feels like too much. I'd rather tell someone three things that actually matter than forty things where thirty-seven of them are noise dressed up as diligence. That's not the same argument as which order to do things in, it's a separate question: which of these are actually worth your time at all.
The Few I Think Genuinely Matter
If I'm being honest about what actually moves the needle, it's a short list. A password manager sits at the top, not close to anything else. I've written before about why I finally switched to a password manager, and the short version is that it's the one change that fixes the single biggest weakness most people have without them ever noticing, reused or weak passwords sitting across dozens of accounts. I use NordPass specifically because it removes every excuse people have for putting it off. Two-factor authentication comes right after it, because a strong password still fails if it ever leaks somewhere you didn't expect, and 2FA is what catches that. Keeping your software updated rounds out the list, mostly because it closes doors that are already publicly known to be open. Everything else I'd call genuinely important is really just a variation on these three: they're the tips that survive contact with real accounts and real attackers, not just contact with a checklist.
The Ones I've Quietly Stopped Recommending
There's a second category I used to repeat and don't anymore, because I never saw it change an outcome for anyone. Changing your passwords every ninety days on a fixed schedule is one of them. It sounds disciplined, but in practice it just pushes people toward small predictable variations of the same password, which is worse than leaving a genuinely strong one alone once it's actually strong. Treating incognito or private browsing mode as a meaningful safety measure is another. It hides your history from the next person using your device, that's genuinely useful for that one purpose, but it does nothing against the actual threats people usually mean when they ask about staying safe, phishing, scams, account compromise. I've also gone quiet on blanket advice to avoid all public wifi entirely, memorising which networks are supposedly safe and which aren't. If you're already covering that risk properly elsewhere, treating every coffee shop network as a crisis is energy spent on a problem you've already solved, and it tends to make people paranoid about the wrong layer of the picture. None of these are dangerous pieces of advice exactly, they're just advice that costs someone's attention without buying them much in return, and attention is the one resource every list like this quietly assumes is unlimited. I'd rather someone spent that attention on the three things that actually work.
Where I Think the Real Risk Actually Sits
If I'm ranking what actually causes people harm, it's rarely a technical gap. It's a moment of being rushed, distracted, or caught off guard by something that looks convincing enough not to question. That's true of most scams I hear about, and it's exactly why I put more weight on the checks I use to catch AI-driven scams than on most of the technical tips people ask me about. A voice that sounds right, a message that references something real, a sense of urgency, that's what actually gets people, far more often than a weak password or an unpatched app. The technical tips matter, I'm not walking that back, but they protect you from a different category of problem than the one that catches most people off guard.

What I'd Actually Tell Someone Starting Today
If someone asked me right now, today, for the version of this that actually matters, I'd give them three things and stop there. Get a password manager and let it generate and store everything properly. Turn on two-factor authentication, starting with email. And slow down for ten seconds before clicking anything that's trying to make you feel rushed, because that pause is worth more than most of the tips further down any list you'll find. Everything else on the usual lists is worth doing eventually, in its own time, but it's not what determines whether you're actually protected, and I'd rather be honest about that than hand someone forty items and let them assume each one carries equal weight. I've put the fuller version of what I think is worth prioritising into a free Safety Toolkit, and the NCSC has its own guidance on the basics if you want to weigh my list against theirs.
