Protecting yourself online means understanding common threats and how to reduce your risk. Phishing is a scam that tricks you into revealing personal information (like a password) by pretending to be a trustworthy source, often through a fake email or website. Malware is malicious software designed to damage a device or steal information, often installed unknowingly through a suspicious download or link. Strong, unique passwords (ideally managed with a password manager) and multi-factor authentication (requiring a second proof of identity, like a code sent to your phone, beyond just a password) significantly reduce the risk of an account being compromised, even if a password is somehow discovered.
Example
An email claiming to be from your bank, urgently asking you to 'click here to verify your account' and enter your password, is a classic phishing attempt — a legitimate bank would never ask for your password this way. Even if a scammer somehow obtained your password through a phishing attempt, multi-factor authentication would still block them from logging in without also having access to your phone.
Key terms
Phishing:
A scam that tricks you into revealing personal information by impersonating a trustworthy source.
Multi-factor authentication:
Requiring a second proof of identity beyond just a password to log in.
Questions
1. Phishing is:
A scam that tricks you into revealing personal information
A legitimate security feature
A type of antivirus software
Something unrelated to online safety
2. Malware is:
Malicious software designed to damage a device or steal information
Software that always improves device security
A type of strong password
Something unrelated to computers
3. Multi-factor authentication requires:
A second proof of identity beyond just a password
Only a username with nothing else
No login information at all
A single password only, with nothing extra
4. A phishing email often:
Pretends to be from a trustworthy source
Is always clearly and obviously fake
Never asks for any personal information
Comes only from friends you know
5. A password manager helps you:
Manage strong, unique passwords
Share your password with everyone
Use the exact same password everywhere
Avoid using passwords entirely
6. Malware is often installed through:
A suspicious download or link
Only official, verified app stores
Nothing at all, it appears randomly
A strong password
7. Multi-factor authentication can block a scammer even if they:
Have discovered your password
Have discovered nothing about your account
Have your phone as well
Have your permission
8. Why might a legitimate bank never ask you to "click here and enter your password" in an email?
This is a common phishing tactic, so legitimate organisations avoid this pattern to help you recognise scams
Banks always request passwords this way as standard practice
Email is always the safest way to share a password
This pattern has no connection to typical phishing scams
9. Why might using the same password across multiple accounts be particularly risky?
If one account is compromised, the same password could then be used to access all your other accounts too
Reusing passwords across accounts has no effect on your overall security
Using an identical password everywhere always makes your accounts more secure
A compromised password only ever affects the single account it was used on
10. Why does multi-factor authentication significantly improve account security even if a password is somehow stolen?
An attacker would also need access to your second authentication factor (like your phone), which they're much less likely to have
A stolen password always grants full account access regardless of any other security measures
Multi-factor authentication provides no additional protection beyond a password alone
Having a second authentication step makes an account easier, not harder, to access
11. Why might a password manager help you use stronger, more unique passwords across all your accounts?
It can generate and securely remember complex, unique passwords for each account, removing the need to memorise them yourself
Password managers always make your passwords significantly weaker
Remembering many unique complex passwords yourself is always easier than using a manager
Password managers have no genuine security benefit
12. Why might downloading software from an unofficial, unverified website be riskier than using an official app store?
Unofficial sources are less likely to be checked for malware, increasing the risk of unknowingly installing malicious software
Unofficial download sources are always exactly as safe as official app stores
Malware can only ever come from official app stores
Where you download software from has no bearing on security risk
13. Why might a phishing email create a false sense of urgency (e.g. "your account will be closed in 24 hours")?
Urgency can pressure a target into acting quickly without carefully checking whether the message is genuinely legitimate
Urgency in an email always indicates the message is completely trustworthy
Scammers never use urgency as a manipulation tactic
Creating a sense of urgency has no effect on how people respond to a suspicious message
14. Why might checking a sender's actual email address (not just the display name) help identify a phishing attempt?
Scammers often use a display name that looks legitimate while the actual underlying email address reveals it is not genuine
The sender's actual email address never provides any useful information for identifying scams
Display names are always a completely reliable way to verify a sender's identity
Checking the underlying email address has no bearing on identifying phishing
15. Why might cyber criminals specifically target people through emotionally manipulative or urgent messages rather than purely technical attacks?
Exploiting human psychology (fear, urgency, trust) can be an easier way to gain access than trying to break through technical security measures directly
Cyber criminals never use any psychological or emotional manipulation tactics
Technical attacks are always far easier to execute than manipulating human behaviour
Human psychology has no relevance to how cyber attacks are actually carried out
16. Why might an organisation experiencing a data breach (where user passwords are stolen) recommend that affected users change their passwords on OTHER unrelated accounts too?
If a user reused that password elsewhere, those other accounts would also be vulnerable using the same stolen password
A breach on one specific service can never have any effect on the security of a user's other accounts
Password reuse across different accounts has no connection to a data breach's wider impact
Users should never be advised to change any passwords after a data breach
17. Why might relying only on a strong password, without multi-factor authentication, still leave an account vulnerable?
A password alone can potentially be stolen, guessed or leaked through a data breach, providing no additional barrier for an attacker to overcome
A strong password alone always provides complete, unbreakable account protection
Multi-factor authentication provides no additional security benefit beyond a strong password
Passwords, no matter how strong, can never be compromised under any circumstances
18. Why might cyber security be considered an ongoing practice rather than a one-time setup?
New threats and scam tactics constantly emerge, requiring continued awareness and updated security measures over time
Once security measures are set up once, no further vigilance or updates are ever needed
Cyber security threats have remained completely unchanged and static over time
Ongoing security practice provides no additional protection over a single initial setup
19. A student receives a text message claiming to be from a delivery company, asking them to click a link and "confirm their address" by entering personal details. Why should this message be treated with the same suspicion as a phishing email?
It uses the same manipulation pattern — impersonating a trusted source to extract personal information — just through text message instead of email
Only phishing attempts sent by email should ever be treated with suspicion
Text messages are always a completely safe and verified communication method
Requests for personal information are always legitimate when they arrive via text message
20. Why might a company's security team consider both technical defences (firewalls, encryption) AND staff training on recognising phishing to be equally necessary parts of cyber security?
Even strong technical defences can be bypassed if a single staff member is tricked into revealing credentials, so human awareness is also a critical layer of protection
Technical defences alone are always completely sufficient with no need for staff awareness
Staff training has no real impact on an organisation's overall cyber security
Human error and technical vulnerabilities are always completely unrelated security concerns
21. Understanding cyber security and protecting your data mainly helps you to:
Recognise common online threats and use practical strategies (strong passwords, multi-factor authentication) to reduce your risk
Ignore the tactics scammers commonly use to trick people
Treat cyber security as a single, one-time task with no ongoing effort
Answer key (parent copy)
1. A scam that tricks you into revealing personal information
2. Malicious software designed to damage a device or steal information
3. A second proof of identity beyond just a password
4. Pretends to be from a trustworthy source
5. Manage strong, unique passwords
6. A suspicious download or link
7. Have discovered your password
8. This is a common phishing tactic, so legitimate organisations avoid this pattern to help you recognise scams
9. If one account is compromised, the same password could then be used to access all your other accounts too
10. An attacker would also need access to your second authentication factor (like your phone), which they're much less likely to have
11. It can generate and securely remember complex, unique passwords for each account, removing the need to memorise them yourself
12. Unofficial sources are less likely to be checked for malware, increasing the risk of unknowingly installing malicious software
13. Urgency can pressure a target into acting quickly without carefully checking whether the message is genuinely legitimate
14. Scammers often use a display name that looks legitimate while the actual underlying email address reveals it is not genuine
15. Exploiting human psychology (fear, urgency, trust) can be an easier way to gain access than trying to break through technical security measures directly
16. If a user reused that password elsewhere, those other accounts would also be vulnerable using the same stolen password
17. A password alone can potentially be stolen, guessed or leaked through a data breach, providing no additional barrier for an attacker to overcome
18. New threats and scam tactics constantly emerge, requiring continued awareness and updated security measures over time
19. It uses the same manipulation pattern — impersonating a trusted source to extract personal information — just through text message instead of email
20. Even strong technical defences can be bypassed if a single staff member is tricked into revealing credentials, so human awareness is also a critical layer of protection
21. Recognise common online threats and use practical strategies (strong passwords, multi-factor authentication) to reduce your risk