Resource Library

Practical help for safer digital life.

Straightforward guidance for families, individuals, and small organizations—written to be used, shared, and revisited.

Browse the library

Guidance, tools, and reference material, grouped by what you are trying to do.

Checklists

Four checklists worth an afternoon.

Most everyday digital safety comes down to a short list of things done once and reviewed occasionally. These are written to be worked through in order.

1. Account security starter checklist

If you only do one section on this page, do this one. Account takeover is a serious online risk. These steps can reduce the chance of it happening and help limit the damage.

  • Use a password manager. The goal is not memorable passwords — it is a different password everywhere, so one breach stays contained.
  • Turn on two-factor authentication on email, banking, and any account tied to money. Prefer a passkey or an authenticator app over SMS codes, which can be intercepted through SIM swapping.
  • Secure your email first. Email is the master key: whoever controls it can reset most of your other accounts. It deserves your strongest password and strongest second factor.
  • Check your recovery options. Old phone numbers and dead backup addresses are a common way people get locked out permanently — or a way an attacker gets in.
  • Review active sessions and connected apps. Most major services list every signed-in device and every third-party app with access. Remove what you no longer recognize or use.
  • Check whether your address has appeared in a breach. If it has, change that password and anywhere you reused it.

2. How to recognize phishing

Phishing does not usually look like a scam. It looks like a normal message that wants you to hurry. These are the signals worth training yourself to notice:

  • Manufactured urgency. Account suspended, payment failed, package held, unusual sign-in, respond within 24 hours. Urgency exists to stop you from checking.
  • A sender domain that is close but not right. Look at the full address, not the display name, which anyone can set to anything.
  • A link whose destination does not match its text. Hover on desktop, long-press on mobile, and read the actual domain.
  • A request to move to another channel — text me here, call this number, continue on WhatsApp. Legitimate support rarely needs this.
  • Unexpected payment demands, especially gift cards, wire transfers, or crypto. Treat urgency, secrecy, or an unusual payment method as a warning. Legitimate businesses sometimes use wire transfers; verify payment instructions through an independently confirmed contact before sending money.
  • Pressure to keep it private. Isolation is a tactic, especially in scams targeting older adults and teenagers.
The reliable habit: never act from the message. Open the app or type the address yourself and check from there. If it is real, it will still be there.

3. Family device setup

Controls are a floor, not a ceiling. They buy time and reduce accidents; the conversations are what actually work.

  • Give each child their own profile or account with an age set honestly. Content and privacy defaults follow that age on most platforms.
  • Require approval for installs and purchases. This single setting prevents most surprise charges and most unwanted apps.
  • Set content and contact limits in the platform's own family settings, then check them again after major OS updates, which sometimes reset preferences.
  • Decide location sharing deliberately — who sees it, on which app, and for how long. Revisit it as kids get older rather than leaving it permanent.
  • Turn off or restrict direct messages from strangers in games and social apps. In practice this is where most unwanted contact begins.
  • Agree on what happens when something goes wrong. A child who expects to lose the device will not tell you. Say plainly that reporting something never costs them the device.

4. If an account has already been compromised

Order matters here. Doing these out of sequence lets an attacker undo your work.

  • Work from a device you trust. If malware is a possibility, do not reset passwords from the affected machine.
  • Change the password, then sign out all other sessions. Changing the password alone does not always end sessions already open.
  • Check recovery settings and email rules. Attackers commonly add a recovery address or a forwarding or auto-delete rule so they keep access and you stop seeing the alerts.
  • Turn on two-factor authentication if it was not already on.
  • Work outward to reused passwords. Anywhere you used that password is now also exposed.
  • Watch anything financial for a few statement cycles, and consider a credit freeze if identity data was involved.
  • Tell the people in your contacts if messages went out in your name, so the next person does not get caught.

A note on what this is

This is general guidance for households and individuals, not a compliance framework and not legal advice. Situations involving harassment, extortion, a compromised business, or a threat to someone's safety warrant contacting law enforcement and, where relevant, a professional responder rather than working from a checklist.

Recommended tools

Two tools worth paying for.

Everything above this line is free and stays free. These two are not. A password manager can help with everyday account security. A VPN serves a narrower network-privacy purpose; whether it is useful depends on your needs.

Disclosure: the ExpressVPN link below is a referral link — subscribe through it and you get 30 days free, and JesterMedia gets a free month as well. The 1Password link is an ordinary link that earns JesterMedia nothing; it is listed because it is what the studio actually uses. Neither company paid for placement, saw this page before it went up, or had any say in what it says.

Something here out of date?

Security guidance ages badly. If a step no longer matches what an app actually does, tell the studio and it gets corrected.

Send a correction