Cyber security

How to stay safe online: 4 Essential security tips

Written by Matt Lukas | Jul 5, 2026, 12:15:00 PM

The internet makes everyday life easier—but staying safe online requires a few simple habits.

We use the internet to manage our finances, shop, communicate, work, access government services and store personal information. That convenience also creates opportunities for fraudsters and cybercriminals to steal passwords, personal information, banking credentials and money. The good news is that you don't need to be a cybersecurity expert to improve your online security.

Start with four simple cornerstones:

  1. Use strong, unique passwords and multi-factor authentication
  2. Verify websites before entering sensitive information
  3. Be careful when using public Wi-Fi
  4. Keep your devices and software updated

These habits can help reduce your risk of phishing, account takeovers, malware and other online threats.

1. Use strong, unique passwords and multi-factor authentication

Your passwords are one of the most important lines of defence protecting your online accounts. One of the biggest mistakes you can make is using the same password for multiple accounts.If a fraudster obtains your username and password from one website, they may try those same credentials on other websites. This type of attack is known as  credential stuffing.

How to create safer passwords

Whenever possible:

  • Use a different password or passphrase for every important account.
  • Make passwords long and difficult to guess.
  • Avoid using personal information such as your name, birthday, address or pet's name.
  • Never share your passwords, PINs or security codes.
  • Consider using a reputable password manager to create and store unique passwords.
  • Change a password promptly if you believe it has been compromised.

The Canadian Centre for Cyber Security recommends using different passwords or passphrases for different accounts, particularly accounts containing sensitive information.

Turn on multi-factor authentication

A strong password is important, but it shouldn't be your only layer of protection. Multi-factor authentication (MFA) requires two or more authentication factors when you sign in. This provides an additional layer of protection if someone obtains your password.

Enable MFA on important accounts whenever it is available, particularly for:

  • Online banking
  • Email
  • Social media
  • Cloud storage
  • Shopping accounts
  • Government accounts

Where available, consider stronger authentication options such as authenticator apps or passkeys.

Remember: Never give your password, PIN or one-time verification code to someone who contacts you unexpectedly.

2. Verify websites before you log in

A website can look exactly like the real thing and still be fraudulent. Phishing scams often use fake websites designed to imitate legitimate financial institutions, retailers, government organizations and other trusted businesses.

A fraudulent website may copy:

  • Logos
  • Colours
  • Fonts
  • Login screens
  • Branding
  • Website layouts

The goal is to convince you to enter your username, password, banking information or other sensitive details.

Don't use unexpected login links

If an email or text message asks you to sign in, don't automatically click the link.

Instead:

  1. Open your browser yourself.
  2. Type the organization's website address manually or use a trusted bookmark.
  3. Use the organization's official mobile app where appropriate.
  4. Contact the organization through a trusted phone number if you're unsure.

The Canadian Centre for Cyber Security specifically recommends avoiding links and attachments in unexpected emails or text messages unless you've confirmed the sender and the request.

Check the website address

Before entering sensitive information, look carefully at the website address.

Be cautious about:

  • Misspelled domain names
  • Unusual domains
  • Extra words or characters
  • Suspicious subdomains
  • Shortened URLs
  • Websites you reached through an unexpected message

Is HTTPS enough to make a website safe?

No. HTTPS helps encrypt the connection between your browser and a website, but it does not prove that the website belongs to the organization you think it does. Fraudsters can create websites that use HTTPS too.

For sensitive activities such as online banking, the safest approach is to navigate directly to your financial institution's official website or use its official app.

3. Be careful when using public wi-fi

Public Wi-Fi can be convenient when you're at a coffee shop, hotel, airport, library or other public location. But you shouldn't treat every public Wi-Fi network as trustworthy. Fraudsters can create fake Wi-Fi networks that imitate legitimate networks. These spoofed networks can potentially be used to intercept information or expose connected devices to additional risks.

Avoid sensitive activities on untrusted networks

If possible, avoid accessing sensitive accounts or conducting financial transactions over unknown or unsecured public Wi-Fi.

For activities such as online banking, consider using:

  • Your mobile data connection
  • A trusted private Wi-Fi network
  • A reputable VPN where appropriate

The Canadian Centre for Cyber Security recommends using a secure Wi-Fi network and suggests using cellular data or a VPN when using a public network.

Be careful when connecting to public networks

Before connecting:

  • Confirm the network name with the business or organization.
  • Avoid networks with suspicious names.
  • Don't assume a network is legitimate because its name looks familiar.
  • Turn off automatic Wi-Fi connections where appropriate.
  • Keep your device's operating system and applications updated.

Convenience isn't worth compromising your financial information.

If you need to check your bank account while you're out, using your cellular data connection can be a simple alternative to an unknown public Wi-Fi network.

4. Keep your devices and software updated

Software updates aren't just about new features. Updates frequently include security fixes that address vulnerabilities in operating systems, browsers, applications and other software. If you delay important updates, you may leave known security weaknesses unpatched.

What should you update?

Keep the following up to date:

  • Smartphones and tablets
  • Computers
  • Web browsers
  • Mobile apps
  • Operating systems
  • Security software
  • Home Wi-Fi routers
  • Other internet-connected devices

Turn on automatic updates whenever they are available and appropriate. The Canadian Centre for Cyber Security recommends regularly updating and patching devices and software to address security vulnerabilities.

Don't ignore security warnings

If your device tells you that an important security update is available, don't continually postpone it. If you're unsure whether an update notification is legitimate, go directly to the device manufacturer's or software provider's official website rather than clicking an unexpected pop-up or message.

 

Five more ways to protect yourself online

The four cornerstones provide a strong foundation, but a few additional habits can make your online security even stronger.

Be cautious with unexpected messages

Don't click links, open attachments or provide information simply because an email or text message looks legitimate. Fraudsters can spoof sender information and create convincing messages that appear to come from trusted organizations. If you're unsure, verify the request independently.

Protect your personal information

Think carefully before sharing personal information online, including:

  • Full name
  • Date of birth
  • Address
  • Phone number
  • Social Insurance Number
  • Account information
  • Security-question answers

This information can potentially be used to impersonate you or target you with more convincing scams. Your digital footprint can provide fraudsters with information they may use for identity theft or targeted social engineering attacks.

Don't give anyone remote access to your device

Be suspicious if someone unexpectedly contacts you and asks you to install software or give them remote access to your computer or phone. This is a common tactic used in technical-support scams. If you receive an unexpected warning that your device is infected, don't automatically call the number displayed in the pop-up. Instead, close the message and seek help through a trusted source.

Monitor your accounts

Regularly review your bank and credit card accounts for transactions you don't recognize.

Also watch for unusual activity such as:

  • Password changes you didn't make
  • Login notifications you don't recognize
  • Unexpected emails sent from your account
  • New devices connected to your accounts
  • Unfamiliar transactions

If something doesn't look right, act quickly.

Back up important information

Regular backups can help protect important photos, documents and other files if your device is lost, damaged, stolen or affected by malware. Keep backups protected and consider using a backup method that isn't continuously connected to your device.

 

What should I do if I think my online account has been compromised?

Act quickly. If you believe someone has accessed your account:

1. Change your password

Change the affected password immediately using a trusted device. If you used that password anywhere else, change it on those accounts too.

2. Enable multi-factor authentication

Turn on MFA if it is available.

3. Contact your financial institution

If your banking or payment information may have been compromised, contact your financial institution immediately using a trusted phone number. Do not use contact information provided in a suspicious email, text or phone call.

4. Monitor your accounts

Watch for unusual transactions, login attempts or changes to your account information.

5. Report the incident

In Canada, suspected fraud can be reported to the Canadian Anti-Fraud Centre (CAFC) at 1-888-495-8501 or through its online reporting system. The Canadian Centre for Cyber Security also recommends contacting your bank immediately if you've fallen victim to fraud or attempted fraud.

Online security: A simple checklist

You don't have to remember every cybersecurity rule.

Start with these habits:

Passwords: Use a unique, strong password or passphrase for every important account.

MFA: Turn on multi-factor authentication wherever available.

Websites: Navigate directly to websites instead of clicking unexpected login links.

Wi-Fi: Use a trusted private network or cellular data for sensitive activities.

Updates: Install security updates and patches promptly.

Messages: Be cautious with unexpected emails, texts and attachments.

Personal information: Share only what is necessary.

Accounts: Monitor your financial and online accounts for unusual activity.

Scams: If something feels wrong, stop and verify it independently.

 

The bottom line: security starts with small habits

Online security doesn't have to be complicated. You can significantly improve your protection by developing a few simple habits:

Use unique passwords.

Turn on multi-factor authentication.

Verify websites before logging in.

Be cautious on public Wi-Fi.

Keep your devices and software updated.

Think before clicking, downloading, replying or sharing information.

And remember:

If something feels urgent, unusual or too good to be true, stop before you act.

Taking a few extra seconds to verify a request can help protect your money, identity, accounts and personal information.

 

Frequently asked questions about online security

What are the four cornerstones of online security?

The four cornerstones are using strong, unique passwords and multi-factor authentication, verifying websites before entering sensitive information, being careful when using public Wi-Fi, and keeping devices and software updated.

How can I protect my online banking information?

Use a strong, unique password or passphrase, enable multi-factor authentication where available, access your financial institution through its official website or app, avoid unexpected login links and use a trusted network or cellular data when accessing sensitive financial information.

Is public Wi-Fi safe for online banking?

It's better to avoid using unknown or unsecured public Wi-Fi for sensitive activities such as online banking. Use a trusted private network or cellular data instead. A reputable VPN can also provide additional protection when using a public network.

Should I use the same password for multiple websites?

No. Using the same password on multiple websites increases your risk if one account is compromised. Fraudsters may try stolen credentials on other services in a credential-stuffing attack. Use unique passwords or passphrases for your important accounts.

Should I use a password manager?

A reputable password manager can help you create and store unique passwords and passphrases for different accounts. If you use one, protect the password manager with a strong primary password and multi-factor authentication where available.

Is HTTPS enough to know that a website is legitimate?

No. HTTPS helps secure the connection between your browser and a website, but it doesn't prove that the website itself is legitimate. Verify the website address and navigate directly to the organization's official website whenever possible.

Why are software updates important for online security?

Software updates often include security patches that fix known vulnerabilities. Keeping your operating system, browser, apps and other connected devices updated can reduce your exposure to known security weaknesses.

What should I do if my banking information has been compromised?

Contact your financial institution immediately using a trusted phone number. If you believe you've been the victim of fraud or attempted fraud, report it to the Canadian Anti-Fraud Centre at 1-888-495-8501 and monitor your accounts for suspicious activity.

What should I do if I clicked a suspicious link?

Don't panic. Close the page and don't enter additional information. If you entered a password, change it using a trusted device. If you provided banking or payment information, contact your financial institution immediately.

Where can I report an online scam in Canada?

You can report suspected fraud to the Canadian Anti-Fraud Centre at 1-888-495-8501 or through its online reporting system. If you've lost money or believe a crime has occurred, you should also contact your financial institution and local police as appropriate.

YNCU members: Need help?

If you are a YNCU member and believe your banking information or account has been compromised, contact YNCU as soon as possible.

YNCU Service Excellence Centre:
1-888-413-YNCU (9628)