Start with a password manager
Reusing passwords across sites is one of the most common ways accounts get taken over — if one service you use is breached, attackers try the same password everywhere else. The UK NCSC recommends password managers for exactly this reason: they generate and store a unique, strong password for every account, so a breach at one site doesn’t compromise the rest of your accounts. NCSC guidance on choosing one recommends protecting the password manager account itself with multi-factor authentication and a strong master password, and keeping the software updated.
Turn on 2-Step Verification everywhere it’s offered
2-Step Verification (2SV, also called two-factor authentication or 2FA) asks for a second proof of identity beyond your password — typically a code from an app or a physical security key. The NCSC recommends turning this on for every account that offers it, describing it as something that “instantly makes it much harder for an attacker to access an account, even if they know the password”. Its Cyber Aware pages carry up-to-date setup instructions for major services including Gmail, Outlook, Facebook and LinkedIn. This one habit blocks a large share of account takeovers even when a password has already leaked.
Keep software and devices updated
Security updates exist because vulnerabilities are found on an ongoing basis, and attackers specifically target devices running outdated software. NCSC guidance consistently recommends applying updates promptly, ideally automatically, across phones, computers, browsers and apps. This is genuinely one of the highest-value, lowest-effort things you can do — turn on automatic updates and leave them on.
Check what you’re actually agreeing to
The UK’s data protection regulator, the Information Commissioner’s Office (ICO), suggests treating a request for personal information online the same way you would in person: check a site or app’s privacy notice to see who’s collecting your information, what it will be used for, and whether it’s shared with anyone else, and ask directly if that isn’t clear before handing over anything sensitive. It sounds basic, but most people skip this entirely — a quick scan of a privacy notice before signing up somewhere new is one of the few ways to actually know what you’re agreeing to rather than assuming.
Review your browser and social media privacy settings
The ICO also recommends spending some time in your browser’s own security and privacy settings — most modern browsers let you block third-party tracking cookies, control which sites can access your location or camera, and clear stored data. The same applies to social networks: reviewing who can see your posts, profile and contact details is worth revisiting periodically, not just at sign-up, since platforms change their defaults and add new features over time.
Where a VPN actually fits in
A VPN sits alongside all of the above, not in place of it. It handles a specific job — hiding your browsing destinations from your ISP and local network, and changing your apparent location — that none of the other habits on this page cover. But it does nothing for weak passwords, missing 2-step verification, out-of-date software, or the data you’ve chosen to hand over in a privacy notice you never read. See What a VPN Actually Protects You From for exactly where that line sits.
A simple starting checklist
Password manager
Unique password per account, protected by a strong master password and 2FA.
2-Step Verification
Turn it on for email, banking and social accounts first.
Automatic updates
Phone, computer, browser and apps — leave auto-update switched on.
Read the privacy notice
Before signing up somewhere new, especially for anything sensitive.
Review app permissions
Periodically check what has access to your location, camera and contacts.
Add a VPN
For the specific job of hiding browsing destinations from your network.
Ready for the VPN layer? Compare real providers
Sources: NCSC – Password manager buyer’s guide; NCSC – Securing your accounts (2SV guidance); ICO – Online safety guidance.