
A short welcome and what this course sets out to do: turn online security into something you practise, not something you worry about.
A map of the eleven sections and how they build on each other, so you know where you are going and why the order matters.
The concrete skills you will have when you finish, stated as things you can do rather than topics you will have heard about.
How videos, practical activities and complementary resources fit together, and how to get the most out of three minutes a day.
Every lesson has a complementary resource on the Cyber Welfare portal, with verified sources, step-by-step checks and further reading. Here is how to use them.
What the essentials are and why they come first. An outline of the foundations covered in this section and what you will be able to do with them.
A set of questions rather than instructions: how often you go online, how many accounts you manage, how you would feel if you lost access to one. Your answers are where protection starts.
What makes a password hold: length first, then variety. Practical rules for building one, and why using the same key on every door is the real risk.
Four unrelated words beat a short password full of symbols, and you will still remember them next month. How to build a passphrase, and when it actually needs changing.
Why a second factor matters even when your password is good, and a first look at the methods available: authenticator apps, SMS codes, hardware keys and biometrics.
Logging out is not just closing a tab: it ends the session and removes the authentication that would otherwise let the next person in. Why it matters most on shared and public devices.
Recovery options, reviewing what is enabled, reacting to unusual activity, and deciding who sees what on social platforms. Most of it is already in your accounts, waiting to be opened.
A short recap of the essentials covered here, and the two or three changes worth making before moving on to the next section.
An outline of the practical habits covered here, across mobile devices, downloads, updates and Wi-Fi, and what you will be able to do with them.
How many times a day you pick up your phone, what you use it for, and what would be exposed if it ended up in someone else's hands. A reflection before the practical steps.
Why the lock screen is the barrier everything else sits behind: loss and theft, banking apps, work documents, and the ordinary privacy of messages and photos.
Almost nothing installs itself. The decision that matters is the one about the source, taken in the half-second before the download starts.
Updates close published vulnerabilities, and they also bring bug fixes, drivers and performance improvements. Why postponing them leaves a known door open.
The risks of public networks, what network encryption actually covers, and the practical rules for using Wi-Fi outside your home without exposing your data.
A recap of the habits covered in this section, and which ones to put in place first if you only have time for a few.
An outline of the warning signs covered here and how to read them calmly, without mistaking ordinary device wear for an infection.
A slow phone is usually just a tired phone. How to tell the ordinary causes from the ones worth investigating, without jumping to conclusions.
Unusual data use or charges you cannot place are among the few malware signals that arrive with a number attached. Where to look and what to do about them.
Advertising inside a free app is the deal you accepted. Advertising on your home screen is something else entirely. How to tell them apart and remove the second.
Updates are the base but not the whole job: caution with attachments and links, apps only from official stores, and a look at your privacy and security settings.
A recap of the signals covered here and the practical measures that reduce the risk of an infection in the first place.
An outline of how passwords are actually attacked, what makes one hold, and how to manage them without relying on memory.
A brute force attack is arithmetic, not cleverness. Understanding the arithmetic is what tells you how many characters are genuinely enough.
Attackers do not start from random combinations: they start from words, names and the patterns people actually use. Why meaning is the weakness.
What entropy means in practice, why length matters more than symbols, and why a password that looks complicated to you is not the same as one that is unpredictable.
You are not bad at inventing passwords: you are a person, and people have patterns. A generator produces the kind of randomness a person cannot.
Length over complexity, unrelated words, and honest guidance on when a passphrase actually needs changing, which is less often than you may have been told.
An encrypted vault, one master password, and the honest downside: a single point of failure. What to set up so that point holds.
A recap of what makes credentials strong, and the practical setup worth putting in place: a manager, unique passwords, and a second factor on the vault.
An outline of what the authentication factors are, how a second factor works, and how to choose between the available methods.
Once reserved for bank accounts, a second factor is now expected on email, cloud storage and work platforms. What it is, how the login actually goes, and where it matters most.
Something you know, something you have, something you are. Once you can name the three, every security setting you meet starts to make sense.
How the factors combine into layers, and how the common methods compare: authenticator apps, one-time codes by SMS or email, and hardware tokens.
Step by step, from entering your username to proving the second factor, including why the code on your phone was never actually sent to you.
Any second factor is better than none, but they are not equal. What separates an SMS code from an authenticator app, and both from a physical key.
A recap of the factors and methods covered here, and the order worth following when enabling them across your accounts.
An outline of what runs through your home connection, from the router to the browser, and what is worth configuring once.
The device every other device connects through, usually left exactly as it arrived. Wi-Fi password, guest network, and the settings worth opening once.
Trackers and cookies follow browsing habits across sites. What a privacy-focused browser blocks by default, and what changes when you switch.
A VPN on the router encrypts traffic for every device on the network. It changes who can see that traffic, and it does nothing against phishing or malware.
Every connected device adds a way in, and smart appliances are rarely updated. Opening the router's device list is usually the surprising part.
A recap of the settings covered here, and which of them give the most protection for the least effort.
An outline of what actually gets attacked around a bank account, and the measures that address it: access points, second factor and phishing.
Nobody attacks the bank's security directly: they attack the email address and phone number the bank uses to reach you. Why a dedicated address changes the picture.
Choosing the right second factor for money: why SMS is the weakest link, how SIM swap fraud works, and what a hardware key does that an app cannot.
Modern phishing does not look like phishing. Which is why the reliable defence is not sharp eyes, but never arriving from a link in the first place.
A password manager will not autofill on a lookalike domain, and a security key refuses to sign you in there at all. The pair that phishing does not get past.
A recap of the measures covered here, and the order worth following to protect the accounts your money depends on.
An outline of what protects the device that holds most of your life, from the unlock code to backups, encryption and photo privacy.
Pattern or numeric code, and why a pattern is easier for someone nearby to reproduce. How to choose without making the phone impractical to use.
Nobody needs to break into a phone they watched you unlock. The habit worth changing is about where and how you type the code.
How long the phone stays open after you stop using it, and why the long gaps are almost always ones people created themselves.
Apps you last opened years ago still hold their permissions and stop receiving fixes. A periodic clear-out is one of the cheapest things you can do.
Everything else prevents. A backup is what helps once something has already happened, provided you have tried restoring from it at least once.
Your phone has been encrypting everything for years, and the key is the code you type to unlock it. Which is why a four-digit PIN is a weaker choice than it looks.
What the hidden album and the secure folder actually do, what they do not do, and why third-party vault apps deserve caution.
A recap of the measures covered here, and the two or three that make the largest difference on a device you carry everywhere.
An outline of how deceptive apps work, the main models they use, and how to decide before installing rather than after.
Deceptive apps copy the look of well-known ones to get installed. What gives the copy away, and why security apps are a favourite disguise.
Nothing is stolen and no rule is broken: a trivial app charges a great deal through a trial that is easy to start and easy to forget. Where the subscription actually lives.
A page tells you your device is infected and gives you a number to call. Recognising the pattern resolves the whole category in one sentence.
The rating is the field most people trust and the cheapest to buy. Reading a handful of recent low reviews takes the same thirty seconds and says more.
If every message gets an instant, enthusiastic reply, that is not popularity. The signals that separate a platform from a business model.
Requiring authentication for every purchase and removing the stored payment method prevent almost all of it. Ten minutes, once.
Four things on the store page tell you almost everything: developer, description, screenshots, and the link from the official website. Most people read none of them.
Permissions are granted in the moment you want the app to work and reviewed almost never. The review is where the interesting findings are.
A recap of the checks covered here, and the routine worth adopting whenever you install something new.
This course contains the use of artificial intelligence. AI tools were thoughtfully integrated into the development of this course to make the learning experience clearer, more accessible, and more practical. The instructor remained an essential part of the entire process, guiding, reviewing, and supervising the content to ensure its quality and educational value.
Have you ever wondered whether a message was genuine, or whether your password was good enough?
This course is for people who use the internet every day and were never taught how to keep it safe. You don't need a technical background: every term that matters is explained the first time it appears, in plain, everyday language.
The method is simple. Each lesson takes a few minutes, holds a single idea, and ends with one small action you can take straight away on your own phone, computer, or account. One lesson, one action, and then you can stop until next time.
What you'll learn
Protect the accounts that matter most, starting with the one that can reset all the others
Create strong passwords and passphrases you can actually remember, and use a password manager
Turn on two-factor authentication (2FA/MFA) and understand passkeys
Keep your smartphone and computer in order: updates, screen lock, backups, and only the apps you use
Recognise the signs of malware, phishing, fake apps, and apps that ask for too much
Make your home Wi-Fi, router, and smart devices harder to reach
Use online banking with more confidence
Know the first steps to take, in the right order, if an account is taken over
Who this course is for
Anyone who uses the internet for work, study, shopping, or banking
Beginners who want clear guidance without technical jargon
Parents, professionals, retirees, and students looking for practical, everyday habits
Anyone who wants to feel calmer and more in control online
Why this course?
Short and practical: a few minutes per lesson, one clear action each time
Beginner-friendly: no technical background needed
Complete: accounts, passwords, devices, home network, banking, and apps
Honest: no course can make anyone completely safe, and this one doesn't claim to. What it can do is give you better odds on ordinary days, and a plan for the bad one.
By the end, the small decisions you make every day, about a link, an app, or a password, will be made deliberately, and the accounts and devices that matter most to you will be harder for anyone else to reach.
Watch the free preview lessons and see whether the approach suits you.