What I've Actually Changed About How I Protect Myself Online This Year

Sep 02, 2026By Jay Kells
Jay Kells

What I've Actually Changed About How I Protect Myself Online This Year


I used to think of my online security setup the way I think of a smoke alarm: install it once, forget it exists, and assume it'll still work whenever it matters. That assumption held up fine for years, right up until I noticed how much of what actually threatens people now barely existed in the same form eighteen months ago. This isn't a roundup of predictions. It's a plain account of what I've actually changed about my own habits over the past year, and what's pushed me to change them.


Why I Stopped Treating My Security Setup as "Done"


The moment that actually shifted my thinking wasn't a headline, it was realising that half the advice I'd been repeating to people was written for a threat landscape that had already moved on. Passwords alone stopped being the main battleground years ago, but I was still talking and acting like they were the whole story. Once I started paying closer attention to what was actually catching people out, I found myself quietly updating one habit after another, not because a single event forced my hand but because the old defaults had quietly stopped being enough.


Passkeys Replaced More of My Passwords Than I Expected


I was sceptical about passkeys when they first started appearing as an option on major accounts, mostly because "sign in without a password" sounded like exactly the kind of convenience feature that trades security for ease. I was wrong about that. A passkey is tied to your device and can't be phished the way a typed password can, since there's no shared secret for a fake login page to steal in the first place. I've switched over on every account that offers it, which is now a meaningful chunk of the logins I use daily, and I still keep a password manager running everything else that hasn't caught up yet.


I Now Assume Any Voice or Video Call Could Be Faked


A year ago I would have said a phone call was one of the more trustworthy ways someone could reach me, precisely because you could hear it was really them. That assumption doesn't hold anymore. AI voice cloning has gotten cheap and convincing enough that a short clip of someone's voice, the kind anyone posts on social media without thinking twice, is enough to fake a call that sounds exactly like a family member in distress. My actual behaviour change is small but consistent: any unexpected call asking for money or sensitive information gets a callback on a number I already trust, not the number that just rang me, no matter how convincing the voice sounded.


QR Codes Get the Same Suspicion I Used to Reserve for Links


I used to scan QR codes without a second thought, mostly because they felt like a neutral piece of infrastructure rather than something that could be tampered with. That's changed since I started seeing reports of scammers physically sticking fake QR code stickers over legitimate ones on parking meters and restaurant tables. A QR code hides the actual destination until after you've already tapped it, which is exactly the kind of blind trust I'd never extend to a random text link. I still use them, but I check the URL that loads before entering anything, the same habit I already had for links, just extended to a format I'd been treating as exempt.


Minimalist smart home device held in hand against white background, showcasing sleek industrial design and LED indicators

I Pay More Attention to What My Smart Devices Are Doing


My smart home setup has grown steadily over the past few years without me ever really auditing it as a whole, and that's the habit I've most deliberately corrected recently. Every smart device on my network is a small computer with its own firmware, its own update schedule, and its own potential vulnerabilities, and I'd been treating most of them as appliances rather than as what they actually are. I now check my router's connected-device list every few months and actually recognise what's supposed to be there, rather than assuming everything on it belongs. A device I don't recognise gets investigated before it gets ignored.


The One Habit That Hasn't Changed at All


For everything I've adjusted this year, the most valuable habit I have is one that hasn't changed at all: treating urgency as a warning sign rather than a reason to act fast. Every new format the scams take, cloned voices, spoofed QR codes, convincing fake emails, relies on the same underlying pressure to skip the pause where you'd normally think something through. The specific technology keeps shifting and I expect it'll keep shifting again next year, but the instinct to slow down when something feels urgent has outlasted every individual trend so far, and the NCSC's own guidance leans on exactly that same principle.


None of these changes came from a single dramatic event. They came from paying closer attention to what was actually working against people and being honest with myself about which of my own habits were built for a threat landscape that had already moved on. My free Safety Toolkit covers the fundamentals that make it easier to keep adjusting as things keep changing, and I'd rather update a habit a little too early than find out I needed to a little too late.