These worksheets are free forever. Want lessons that adapt to your child as they learn, plus progress tracking? Try Ignition Learning free.

Sign up free

Ignition Learning — Activity Sheet

Cyber security & protecting your data

Technologies · Year 8

Name: ______________________Date: ____________

Protecting yourself online means understanding common threats and how to reduce your risk. Phishing is a scam that tricks you into revealing personal information (like a password) by pretending to be a trustworthy source, often through a fake email or website. Malware is malicious software designed to damage a device or steal information, often installed unknowingly through a suspicious download or link. Strong, unique passwords (ideally managed with a password manager) and multi-factor authentication (requiring a second proof of identity, like a code sent to your phone, beyond just a password) significantly reduce the risk of an account being compromised, even if a password is somehow discovered.

Example

An email claiming to be from your bank, urgently asking you to 'click here to verify your account' and enter your password, is a classic phishing attempt — a legitimate bank would never ask for your password this way. Even if a scammer somehow obtained your password through a phishing attempt, multi-factor authentication would still block them from logging in without also having access to your phone.

Key terms

Phishing:
A scam that tricks you into revealing personal information by impersonating a trustworthy source.
Multi-factor authentication:
Requiring a second proof of identity beyond just a password to log in.

Questions

  1. 1. Phishing is:

    • A scam that tricks you into revealing personal information
    • A legitimate security feature
    • A type of antivirus software
    • Something unrelated to online safety
  2. 2. Malware is:

    • Malicious software designed to damage a device or steal information
    • Software that always improves device security
    • A type of strong password
    • Something unrelated to computers
  3. 3. Multi-factor authentication requires:

    • A second proof of identity beyond just a password
    • Only a username with nothing else
    • No login information at all
    • A single password only, with nothing extra
  4. 4. A phishing email often:

    • Pretends to be from a trustworthy source
    • Is always clearly and obviously fake
    • Never asks for any personal information
    • Comes only from friends you know
  5. 5. A password manager helps you:

    • Manage strong, unique passwords
    • Share your password with everyone
    • Use the exact same password everywhere
    • Avoid using passwords entirely
  6. 6. Malware is often installed through:

    • A suspicious download or link
    • Only official, verified app stores
    • Nothing at all, it appears randomly
    • A strong password
  7. 7. Multi-factor authentication can block a scammer even if they:

    • Have discovered your password
    • Have discovered nothing about your account
    • Have your phone as well
    • Have your permission
  8. 8. Why might a legitimate bank never ask you to "click here and enter your password" in an email?

    • This is a common phishing tactic, so legitimate organisations avoid this pattern to help you recognise scams
    • Banks always request passwords this way as standard practice
    • Email is always the safest way to share a password
    • This pattern has no connection to typical phishing scams
  9. 9. Why might using the same password across multiple accounts be particularly risky?

    • If one account is compromised, the same password could then be used to access all your other accounts too
    • Reusing passwords across accounts has no effect on your overall security
    • Using an identical password everywhere always makes your accounts more secure
    • A compromised password only ever affects the single account it was used on
  10. 10. Why does multi-factor authentication significantly improve account security even if a password is somehow stolen?

    • An attacker would also need access to your second authentication factor (like your phone), which they're much less likely to have
    • A stolen password always grants full account access regardless of any other security measures
    • Multi-factor authentication provides no additional protection beyond a password alone
    • Having a second authentication step makes an account easier, not harder, to access
  11. 11. Why might a password manager help you use stronger, more unique passwords across all your accounts?

    • It can generate and securely remember complex, unique passwords for each account, removing the need to memorise them yourself
    • Password managers always make your passwords significantly weaker
    • Remembering many unique complex passwords yourself is always easier than using a manager
    • Password managers have no genuine security benefit
  12. 12. Why might downloading software from an unofficial, unverified website be riskier than using an official app store?

    • Unofficial sources are less likely to be checked for malware, increasing the risk of unknowingly installing malicious software
    • Unofficial download sources are always exactly as safe as official app stores
    • Malware can only ever come from official app stores
    • Where you download software from has no bearing on security risk
  13. 13. Why might a phishing email create a false sense of urgency (e.g. "your account will be closed in 24 hours")?

    • Urgency can pressure a target into acting quickly without carefully checking whether the message is genuinely legitimate
    • Urgency in an email always indicates the message is completely trustworthy
    • Scammers never use urgency as a manipulation tactic
    • Creating a sense of urgency has no effect on how people respond to a suspicious message
  14. 14. Why might checking a sender's actual email address (not just the display name) help identify a phishing attempt?

    • Scammers often use a display name that looks legitimate while the actual underlying email address reveals it is not genuine
    • The sender's actual email address never provides any useful information for identifying scams
    • Display names are always a completely reliable way to verify a sender's identity
    • Checking the underlying email address has no bearing on identifying phishing
  15. 15. Why might cyber criminals specifically target people through emotionally manipulative or urgent messages rather than purely technical attacks?

    • Exploiting human psychology (fear, urgency, trust) can be an easier way to gain access than trying to break through technical security measures directly
    • Cyber criminals never use any psychological or emotional manipulation tactics
    • Technical attacks are always far easier to execute than manipulating human behaviour
    • Human psychology has no relevance to how cyber attacks are actually carried out
  16. 16. Why might an organisation experiencing a data breach (where user passwords are stolen) recommend that affected users change their passwords on OTHER unrelated accounts too?

    • If a user reused that password elsewhere, those other accounts would also be vulnerable using the same stolen password
    • A breach on one specific service can never have any effect on the security of a user's other accounts
    • Password reuse across different accounts has no connection to a data breach's wider impact
    • Users should never be advised to change any passwords after a data breach
  17. 17. Why might relying only on a strong password, without multi-factor authentication, still leave an account vulnerable?

    • A password alone can potentially be stolen, guessed or leaked through a data breach, providing no additional barrier for an attacker to overcome
    • A strong password alone always provides complete, unbreakable account protection
    • Multi-factor authentication provides no additional security benefit beyond a strong password
    • Passwords, no matter how strong, can never be compromised under any circumstances
  18. 18. Why might cyber security be considered an ongoing practice rather than a one-time setup?

    • New threats and scam tactics constantly emerge, requiring continued awareness and updated security measures over time
    • Once security measures are set up once, no further vigilance or updates are ever needed
    • Cyber security threats have remained completely unchanged and static over time
    • Ongoing security practice provides no additional protection over a single initial setup
  19. 19. A student receives a text message claiming to be from a delivery company, asking them to click a link and "confirm their address" by entering personal details. Why should this message be treated with the same suspicion as a phishing email?

    • It uses the same manipulation pattern — impersonating a trusted source to extract personal information — just through text message instead of email
    • Only phishing attempts sent by email should ever be treated with suspicion
    • Text messages are always a completely safe and verified communication method
    • Requests for personal information are always legitimate when they arrive via text message
  20. 20. Why might a company's security team consider both technical defences (firewalls, encryption) AND staff training on recognising phishing to be equally necessary parts of cyber security?

    • Even strong technical defences can be bypassed if a single staff member is tricked into revealing credentials, so human awareness is also a critical layer of protection
    • Technical defences alone are always completely sufficient with no need for staff awareness
    • Staff training has no real impact on an organisation's overall cyber security
    • Human error and technical vulnerabilities are always completely unrelated security concerns
  21. 21. Understanding cyber security and protecting your data mainly helps you to:

    • Recognise common online threats and use practical strategies (strong passwords, multi-factor authentication) to reduce your risk
    • Assume strong passwords alone always guarantee complete online safety
    • Ignore the tactics scammers commonly use to trick people
    • Treat cyber security as a single, one-time task with no ongoing effort

Answer key (parent copy)

  1. 1. A scam that tricks you into revealing personal information
  2. 2. Malicious software designed to damage a device or steal information
  3. 3. A second proof of identity beyond just a password
  4. 4. Pretends to be from a trustworthy source
  5. 5. Manage strong, unique passwords
  6. 6. A suspicious download or link
  7. 7. Have discovered your password
  8. 8. This is a common phishing tactic, so legitimate organisations avoid this pattern to help you recognise scams
  9. 9. If one account is compromised, the same password could then be used to access all your other accounts too
  10. 10. An attacker would also need access to your second authentication factor (like your phone), which they're much less likely to have
  11. 11. It can generate and securely remember complex, unique passwords for each account, removing the need to memorise them yourself
  12. 12. Unofficial sources are less likely to be checked for malware, increasing the risk of unknowingly installing malicious software
  13. 13. Urgency can pressure a target into acting quickly without carefully checking whether the message is genuinely legitimate
  14. 14. Scammers often use a display name that looks legitimate while the actual underlying email address reveals it is not genuine
  15. 15. Exploiting human psychology (fear, urgency, trust) can be an easier way to gain access than trying to break through technical security measures directly
  16. 16. If a user reused that password elsewhere, those other accounts would also be vulnerable using the same stolen password
  17. 17. A password alone can potentially be stolen, guessed or leaked through a data breach, providing no additional barrier for an attacker to overcome
  18. 18. New threats and scam tactics constantly emerge, requiring continued awareness and updated security measures over time
  19. 19. It uses the same manipulation pattern — impersonating a trusted source to extract personal information — just through text message instead of email
  20. 20. Even strong technical defences can be bypassed if a single staff member is tricked into revealing credentials, so human awareness is also a critical layer of protection
  21. 21. Recognise common online threats and use practical strategies (strong passwords, multi-factor authentication) to reduce your risk