What I Used to Tell People About Staying Safe Online

Jay Kells
Sep 07, 2025By Jay Kells

What I Used to Tell People About Staying Safe Online, and What I Say Now

For years I gave more or less the same advice to anyone who asked how to stay safe online. Use a strong password, look for the padlock icon in the browser bar, don't click links from people you don't know, keep your software updated. It was solid advice, it was easy to remember, and I genuinely believed it covered most of what mattered. I've since changed almost all of it, not because it was wrong exactly, but because the threats it was built to answer have mostly moved on.


I still get asked the same question constantly, usually some version of "what's the one thing I should actually do." I used to have a tidy answer. I don't anymore, and I think that's worth explaining rather than pretending I still have a neat list.


What I Used to Tell People


The old advice was built around spotting things. Spot the fake email by its bad spelling. Spot the fake website by the missing padlock. Spot the scam call by the pushy tone. It worked because for a long time, scams genuinely did look different from the real thing if you knew where to look. A phishing email in 2015 was often clumsy enough that a careful reader had a real chance of catching it on sight.


That advice made people feel capable. You didn't need to understand how any of it worked technically, you just needed to notice a few tells, and I could teach those tells in five minutes. It was good advice for the threats of its time, and I don't think it was wrong to give it then.


Why That Advice Stopped Being Enough


The tells mostly aren't there anymore. Scam messages are now written using the same AI tools everyone else uses, which means the spelling is fine, the tone is professional, and the branding is often lifted directly from the real company's own emails. A fake banking site can be an almost perfect copy of the real one, padlock icon included, because getting a padlock is just a matter of installing a free certificate, not a mark of legitimacy anymore.


Voice cloning has done something similar to phone scams. The tell used to be that the voice sounded slightly off, or the story didn't quite add up. Now a scammer can clone a few seconds of someone's voice from a video posted online and use it to fake a distressed phone call, which removes the one signal a lot of people were leaning on without realising it.


None of this means the old advice is actively harmful. Strong passwords still matter. Updated software still matters. But treating those as the finish line rather than the starting point leaves a gap that's much bigger than it used to be, and I was underselling that gap for longer than I'd like to admit.


What Changed My Approach


The shift for me happened gradually, through writing about specific incidents rather than through any single moment. I've covered a voice clone call that nearly caught me out, and it's a strange thing to sit with the fact that a technique like that is no longer rare or expensive to pull off. I've also written about why bad grammar doesn't give scam messages away anymore, which is really the same underlying shift applied to text instead of speech.

Layered translucent glass with geometric patterns, golden light rays, warm glowing bokeh effect.


What connects all of it is that the old checklist assumed a scammer's effort was the limiting factor. Bad actors used to be constrained by time, language skill, or technical knowledge, and the tells were really just symptoms of those constraints. AI tools removed most of those constraints, so the tells disappeared along with them. That's the part I had to rebuild my thinking around, not just the specific list of do's and don'ts.


What I Actually Tell People Now


These days my advice is less about spotting fakes and more about verifying independently. If a message or call asks you to act, urgently or otherwise, the useful question isn't whether it looks convincing. It's whether you can confirm the claim through a channel you chose yourself, rather than one the message handed you. Open the banking app directly instead of clicking the link. Call the number on the back of your card instead of the one in the text. Ring the family member back on their usual number instead of trusting the voice on an unexpected call.


I also tell people to put a small number of things on autopilot rather than relying on vigilance for everything, because vigilance runs out by the end of a long day and scammers know that. A password manager removes the temptation to reuse passwords without you having to think about it each time. I run a VPN on every device I own by default, not because I'm doing anything sensitive most of the time, but because it means I don't have to judge every network I connect to. Decisions you've already made ahead of time hold up better than judgement calls made in the moment a message arrives.


The One Thing That Hasn't Changed


If there's a piece of the old advice that's held up completely, it's this: nobody legitimate needs you to do something urgent right now through a channel they chose for you. That was true when the tell was bad spelling, and it's still true now that the spelling is perfect. Everything else I tell people has had to evolve as the threats got more convincing, but that one instinct, slow down and verify independently, has done more work for me than any specific checklist ever did.


I'd still rather someone walked away from this with one good instinct than a list of ten rules they'll half remember. If you want the fuller version of what I actually put in place day to day, I've pulled it together in a free Safety Toolkit. And if something does slip through, Action Fraud is the right place to report it in the UK.