Florence's Computing · Online Safety · Lesson 1
KS3

Looking after
yourself online.

The internet is yours to use — for school, for friends, for everything you love. A few quiet habits keep it that way, and they're easier than they sound.
For Florence,
calm and in charge.
Florence's Computing · Lesson 1
Where we start

Your data is worth looking after.

Every time you sign in somewhere — a game, a chat, an email, a shop — you leave a little of yourself behind. Your name. A photo. A password. The messages you send. None of it is dramatic on its own. Put together, though, it adds up to a picture of who you are, and that picture has value — to companies, and occasionally to people who'd rather you didn't have control of it.

So we look after it. Not because the internet is a frightening place — most of it is friendly, useful, and exactly what it claims to be — but because a few small habits keep you in charge of your own information instead of leaving it lying around. Think of it the way you think of a front-door key. You don't carry a key because you're afraid of the street. You carry one because the things behind your door are yours.

The word behind it

cyber comes from the Greek kybernetes — a steersman, the person who steers a ship. Cybersecurity is really about staying at the wheel: keeping your hand on where your own information goes. You're the steersman here.

A detail worth knowing
30–45 seconds · MF 1
Cool fact

The single most-used password in the world, year after year, is still "123456". Security researchers find it at the top of nearly every list of leaked passwords — used on tens of millions of accounts. A password a computer can guess in well under a second isn't really a password at all.

Florence's Computing · Lesson 1
The first habit

A strong password is mostly about length.

For years people were told to make passwords with a capital, a number, and a squiggle — something like P@ssw0rd! The trouble is that those are hard for you to remember and surprisingly quick for a computer to guess. The advice has changed. What actually slows a guessing machine down is length — and the simplest way to get length you can remember is the UK National Cyber Security Centre's three random words idea.

otter copper balloon word one word two word three three unrelated words = 18 letters, quick for you to picture, slow for a machine to guess pick words that don't go together — never your name, pet, or birthday
Three random, unrelated words make a passphrase you can actually remember — and the length is what does the work. Original schematic · after NCSC guidance

What makes one strong

  • Length — longer beats clever. Three words is a good floor.
  • Unrelated words — "otter copper balloon", not "summer holiday sun".
  • Unique per account — a different one for each important sign-in.
  • Private — yours alone, not shared, not written on a sticky note by the screen.

What makes one weak

  • Anything guessable — your name, your pet, your birthday.
  • Short ones, even with a "!" on the end.
  • The same password reused everywhere.
  • Common picks like "123456" or the word "password".
A password manager — the calm option

You can't remember a strong, different password for forty accounts, and you don't have to. A password manager is an app that makes them, stores them, and fills them in for you. You remember one strong passphrase to open the manager; it remembers everything else. Lots of grown-ups use one — it's worth asking a trusted adult about setting one up.

A detail worth knowing
30–45 seconds · MF 1

Tap each card — the second habit that backs up your password:

Two-factor authentication A second check after your password — usually a code from your phone. Even if someone learns your password, they can't get in without the code.
Why turn it on? It's the single biggest step you can take. It turns "knows my password" into "not enough" — a locked door behind the locked door.
Where you'll see it Email, social apps, games — often called "2FA", "two-step", or "login verification" in the settings. Switch it on for the accounts that matter most.
Cool fact

A password made of three random words is roughly a trillion times harder for a machine to guess than a single common word — yet it's far easier for a human to keep in their head. Pictures stick; random letters don't. Your memory and the maths are, for once, on the same side.

Florence's Computing · Lesson 1
Spotting a fake

Phishing — a message dressed up as something it isn't.

Phishing is when someone sends a message pretending to be a company or a person you trust, hoping you'll hand over a password, a code, or money. It might arrive as an email, a text, or a chat message. The good news: fakes nearly always carry the same few tells, and once you know them you'll spot them in seconds.

Here's a fake email of the kind that does the rounds. The highlighted bits are the clues — tap each one to see what gives it away.

From: Netflx Billing <support@netfllx-account-verify.com>The sender address is the loudest clue. "netfllx" is misspelled, and a real company uses its own plain domain (netflix.com), never a tacked-on "-account-verify". The display name can say anything — always read the actual address.
Subject: URGENT: Your account will be closed in 24 hoursManufactured urgency. A countdown is there to make you act before you think. Real services give you time and don't threaten you in the subject line.

Dear Valued CustomerNo real name. A company you actually have an account with usually knows your name. A vague greeting suggests a message blasted to thousands of strangers.,

We could not process your payment. Your account has been suspended. To avoid permanent deletion, you must confirm your password and card detailsThe big one. No genuine company will ever ask you to confirm your password by email or message. A request for a password, a code, or payment details is the clearest sign of a scam. immediately.

Click here to verify now → http://netflix-secure.account-check.ru/loginThe link doesn't match the company. Read it from the right: the real address sits right before the first single slash — here that's "account-check.ru", not netflix.com. Hover before you click; on a phone, press and hold to preview.

Failure to act will result in legal action.

Tap the highlighted parts. Four clues hide in this one short message — and any single one is enough to walk away.

If a message feels off — three calm steps

  1. Don't click. Links and "open this" buttons are how the trick lands. Pausing costs you nothing.
  2. Check it yourself. If it claims to be from a service you use, go to that app or site the way you normally do — type the address, use your own bookmark — never through the message's link.
  3. Ask. Show it to a trusted adult. A second pair of eyes spots a fake in a moment, and there's no such thing as a silly question here.
If you did click — it's fixable

Clicking a bad link, or even typing a password into a fake page, happens to plenty of careful people. It is not a disaster and it is not your fault. Tell a trusted adult straight away, change the password on that account (and anywhere you reused it), and turn on two-factor if it isn't already. Acting quickly is what matters — and you already know how.

A detail worth knowing
30–45 seconds · MF 1
Cool fact

The word "phishing" is a deliberate misspelling of "fishing" — because the scammer casts out thousands of messages like baited hooks and waits to see who bites. The odd spelling dates back to the 1990s, borrowed from an even older slang for tricking people over the phone: "phreaking".

Florence's Computing · Lesson 1
The bigger picture

Your footprint, your software, your fellow humans.

Three more ideas round out the picture, and none of them needs to weigh on you. They're worth a quiet place in your head.

Your digital footprint

  • Everything you post leaves a trail — and a trail is hard to fully take back.
  • Before posting, a quiet test: would I be happy for this to still be around in a few years?
  • Use privacy settings — choose who sees what. They're yours to set.
  • Share less than feels natural, especially your location, school, and full name with strangers.

Malware & staying updated

  • Malware is software written to cause harm — viruses, and the like.
  • It usually arrives through a dodgy download or a bad link — the same caution applies.
  • Keep software updated. Updates quietly patch the gaps that malware sneaks through.
  • Stick to official app stores; be wary of "free" downloads from unknown sites.
Being a good person online counts too

Safety isn't only about passwords and links. It's also about how we treat each other. Be the kind of person online you'd want to meet — patient, honest, not unkind in the moment. And if anything ever feels off — a message that upsets you, someone asking for things that don't feel right, anything at all — you don't have to handle it alone. Telling a trusted adult is always a strong first move, never a last resort.

A detail worth knowing
30–45 seconds · MF 1
Cool fact

The very first computer "worm" to spread across the early internet, in 1988, was written by a student who claimed he only meant to measure how big the network was. A small bug made it copy itself far too fast, and it accidentally jammed thousands of machines — the first time the world saw that code could run away from the person who wrote it.

Florence's Computing · Lesson 1
Watch

Phishing, seen from the other side.

You've learned to read the clues in a fake message. This short film from Khan Academy shows how phishing works and why it fools people — watch for the same tells you met a moment ago: the rush, the odd sender, the link that doesn't match, the request to never answer.

Khan Academy — “Phishing attacks”, from the Internet Safety series.YouTube
Florence's Computing · Lesson 1
Question 1 · circle the answer

What makes a password strong?

You met the idea that the advice on passwords has changed. Which of these matters most for making a password hard for a computer to guess?
Question 2 · circle the answer

The three-random-words idea.

Following the approach from the lesson, which of these is the strongest passphrase?
Question 3 · circle the answer

What is two-factor authentication?

You read about a second layer that backs up your password. What does two-factor authentication add?
Question 4 · circle the answer

The clearest sign of a scam message.

From the fake email you read, which single thing is the clearest sign that a message is a scam?
Question 5 · type your answer

Reading a web address.

You learned to read a link from the right — the real address sits right before the first single slash. In this link, which website does it actually go to?
http://netflix-secure.account-check.ru/login
Type the real address (the part before the first slash).
goes to:
Question 6 · circle the answer

A message makes you feel rushed.

A text says your account will be closed in one hour unless you click a link right now. From the three calm steps, what is the first thing to do?
Question 7 · circle the answer

Why keep software updated?

You read one practical reason to let your apps and device update. What do updates mainly do for your safety?
Question 8 · circle the answer

Your digital footprint.

You met a quiet test to use before posting something. Which statement matches what the lesson said about a digital footprint?
Florence's Computing · Lesson 1
Writing room · in your own words

Write a calm warning to a friend.

Imagine a friend messages you in a panic: they've had an email saying their account will be deleted in an hour unless they "click here and confirm their password". Write a short, kind reply — around 100–150 words — telling them what you'd do and why. Use what you learned: the clues that mark it as fake, and the calm steps. Keep it reassuring; they're worried.

0 words
reading what you wrote…

A few thoughts on your reply, Florence

strong You led with reassurance — telling your friend to breathe and that nothing's lost yet — before getting to the warning. That's exactly the move: a worried person can't take in advice until the panic drops a little. And you named real clues, not only "it looks dodgy", which is what makes your reply trustworthy.

try this You mentioned the link and the rush, which are two solid clues. One more would round it off — the request to confirm a password is the single loudest sign, since no real company ever asks for that. Naming it would make your friend able to spot the next one without you.

to add Try adding one because to your advice — "don't use the link in the message, because the safest way is to open the app the way you normally do." A reason turns a rule into something your friend can carry forward on their own.

Watch together

Films and series about the connected world.

Sit down with Dad for any of these. They make the hidden machinery of the internet feel understandable — and a little more human. Heavier titles flagged for a chat first.

Documentary · 2020 · 12
The Social Dilemma
Former tech insiders explain how apps are designed to hold your attention — and what that means for your data and your time. Pairs perfectly with the footprint idea. Some heavier moments — chat afterwards.
Series · BBC · PG
Click — BBC technology programme
Short, friendly episodes on how everyday technology actually works, including regular pieces on staying safe online. Pleasant to dip into one segment at a time.
Documentary · 2014 · PG
Lo and Behold: Reveries of the Connected World
Werner Herzog's curious, wandering look at the internet — where it came from, what it does to us, where it might go. More wonder than warning.
Drama · 2010 · 12A
The Social Network
The story of how Facebook was built. Not a safety film, but a sharp look at how much of our lives now lives online — and who builds the places we live there. Heavier themes — chat afterwards.
Documentary · 2014 · 15
Citizenfour
A real-time documentary about online privacy and surveillance. Grown-up and slow, but it's the clearest film on why data matters. For an older sit-down with Dad.
Florence's Computing · Lesson 1
Glossary

The words from today.

Cybersecurity
Looking after your information and devices online — staying in charge of where your own data goes.
Passphrase
A password made of several words — long enough to be hard to guess, simple enough to remember.
Two-factor authentication
A second check after your password — often a code on your phone — so a password alone isn't enough to get in.
Phishing
A message pretending to be from someone you trust, trying to get a password, a code, or money out of you.
Malware
Software written to do harm — viruses and the like. Updates and care with downloads keep it out.
Digital footprint
The trail you leave online — posts, photos, accounts. Hard to take back fully, so worth a pause before posting.
End of lesson one

You're the steersman now.

You learned why your data is worth looking after, how three random words make a strong password, and why a second check backs it up. You can read a fake message for its clues, and you know the calm steps — don't click, check, ask. None of this is about being afraid. It's about a few small habits that keep you in charge. Mistakes online are normal and fixable, and a trusted adult is always a good first port of call. Florence, this is computing.

F.M. · Computing · Online Safety · Lesson 1
Images · The "three random words" password diagram on this page is original SVG line-art, drawn for this lesson after the UK National Cyber Security Centre's public guidance — feel free to use it freely. · The "spot the clue" email is an illustrative mock-up written for this lesson; no real company is involved.
Video · Khan Academy, “Phishing attacks” (Internet Safety series), embedded from YouTube — see the channel for its own licensing.
Film recommendations are factual reference only — see each title's own copyright owner.