Cyber safety at home and work: passwords, MFA, phishing and scams
Cyber safety starts with small habits
You don’t need to grow a black hoodie and start typing in green text to be safe online. Most cyber problems don’t start with a dramatic hack. They start with a reused password, a fake invoice, a rushed click, or a message that looks almost normal.
The good news: a few small habits cut a lot of risk at home and at work. You just need to slow down at the right moments, use stronger sign-in protection, and ask for help before clicking when something feels off.
Use stronger passwords
- Use a different password for every important account — especially email, banking, Microsoft 365, Apple ID, Google, and business systems.
- Avoid passwords based on birthdays, pet names, business names, suburbs, or favourite teams.
- Use a password manager if you have too many to remember safely (and you probably do).
- Change a password quickly if you think an account has been exposed.
Turn on MFA wherever possible
MFA — multi-factor authentication — adds another check when someone signs in, usually through an app, text message, security key, or prompt. It’s not perfect, but it makes stolen passwords much less useful.
- Turn on MFA for email first. Email is usually the key to resetting other accounts.
- Use an authenticator app rather than relying only on SMS where possible.
- Don’t approve a sign-in prompt you didn’t start.
- For business accounts, check with your IT contact before making MFA changes that affect staff access.
Spot common phishing signs
Phishing emails and scam messages often try to make you hurry. They may say your account will close, an invoice is overdue, a parcel is waiting, or a payment detail has changed.
- Check the sender address carefully — not just the display name.
- Hover over links before clicking, or skip the link entirely and go to the official website directly.
- Be careful with urgent payment, gift card, or bank-detail change requests.
- Don’t open unexpected attachments, especially when the message feels rushed.
- Verify unusual requests by phone using a known number — not a number printed in the suspicious message.
What to do if you clicked something
- Stop using the device for sensitive tasks like banking or email.
- Don’t keep trying different passwords on a suspicious page.
- Take a screenshot if it’s safe to do so.
- Call us or your internal IT contact as soon as possible.
- If money might be involved, call your bank immediately.
Simple tip
Use the ten-second rule: if a message asks you to act urgently, pause for ten seconds and ask, “Was I expecting this, and can I verify it another way?” That short pause stops most of the damage scammers are counting on.
Still worried something’s wrong? Call us on (08) 6555 6500 or book a cyber safety review.