Learn how to secure your devices, recognize suspicious messages, and protect your account, with clear explanations of common security terms.

A phone, tablet, or computer used for study and everyday communication may also contain personal messages, photographs, documents, and access to online accounts. Protecting it means protecting more than the device itself. It also means looking after your privacy and information that other people have entrusted to you.
However, advice about passwords, passkeys, encryption, and suspicious links can be difficult to follow when those terms are unfamiliar. Understanding what each precaution does makes it easier to put it into practice.
You do not need to become a technology expert. The aim is to develop a few dependable habits, understand when to pause, and know when to ask for help.
Online security helps prevent someone from accessing your information or using your accounts without permission. The consequences can extend beyond losing a password. Someone who takes over an account may change its settings, lock out its owner, or send messages that appear to come from that person. Friends who recognize the sender’s name may then trust those messages.
Different precautions address different risks. A screen lock helps protect a device left unattended. A unique password helps limit the damage when another website suffers a security breach. Updated software repairs weaknesses that could otherwise be exploited. These measures work together rather than replacing one another.
The goal is not to become afraid of using technology. It is to use it with reasonable care.
A screen lock requires you to prove that you are allowed to use a device before it opens. Depending on the device, you may unlock it with a PIN, a password, a fingerprint, or facial recognition. A PIN, short for personal identification number, is a number-based code. Fingerprint and facial recognition are examples of biometrics, which use physical characteristics to recognize you.
Choose a code that is difficult for someone else to guess. Avoid a birthday, repeated digits, or an obvious sequence. Where supported, choose a longer PIN or a strong password rather than the shortest available option. The code used to unlock your device should also be different from your online account passwords.
Fingerprint or facial recognition can make unlocking more convenient, but protect the backup PIN or password as carefully. Someone who knows that code may be able to unlock the device without using your fingerprint or face.
To review these options, open the device’s Settings and look for its screen-lock or security settings. The names vary between devices. Enable automatic locking, which locks the screen after a period of inactivity, and choose a reasonably short delay. Lock the device yourself when you finish using it instead of relying only on the timer.
An operating system is the main software that runs a device, such as Android, iOS, Windows, or macOS. Apps, short for applications, are programs that perform particular tasks. A browser, such as Safari, Chrome, Edge, or Firefox, is an app used to open websites.
Updates do more than change a device’s appearance or add features. They can repair security weaknesses, sometimes called vulnerabilities. A security patch is a correction intended to fix such a weakness. Leaving updates uninstalled may leave a known problem unresolved.
Use the device’s built-in update settings and its official app store or the software’s genuine update mechanism. Enable automatic updates where practical, and complete a restart when an update requires one. Do not rely on an unexpected website message claiming that you must immediately download an update or security program. Such messages can themselves be deceptive.
It is also important to understand support. Software manufacturers provide security fixes for particular products and versions. Older software may eventually stop receiving them, even though the device still switches on and appears to work normally. “Still working” and “still receiving security protection” are not the same thing.
When you are unsure whether a device is still receiving security fixes, consult the manufacturer’s information or ask a knowledgeable person. Check whether a supported software upgrade is possible before assuming that the device must be replaced.
Encryption scrambles information so that it cannot be read normally without the appropriate digital key. Device encryption protects information stored on the device, rather than merely placing a lock screen in front of it. This can help protect your files if someone obtains the device and attempts to read its storage.
The available protection depends on the device. Windows may provide Device Encryption or BitLocker, while Mac computers use FileVault as part of their storage protection. Some encryption is enabled automatically under particular conditions, so it is better to check the actual settings than assume that it is either on or off.
During setup, you may be given a recovery key, a special code that can help restore access when the usual unlocking method is unavailable. Follow the manufacturer’s instructions for saving it securely. Do not keep the only copy on the device that it unlocks. Losing both the normal access method and the recovery key can make encrypted information inaccessible.
Encryption is valuable, but it does not make a fraudulent website safe or prevent someone from reading information that you have already opened for them.
Physical care still matters. Keep your phone or tablet in your possession or in a secure place when it is not in use. Avoid leaving it unattended on a public table, in a vehicle, or somewhere that another person could easily take it. Lock it before putting it away.
Your username identifies the account you are trying to access. Your password is a secret used to help prove that you are entitled to access it. The two should not be treated alike: knowing someone’s username does not give a person permission to know their password.
Use a password for your JW.ORG® account that you do not use for email, shopping, social media, or another website. When passwords are stolen from one service, attackers may try them elsewhere. A different password for each account helps prevent one exposed password from unlocking several accounts.
A strong password should be long and difficult to predict. One option is a passphrase, made from several randomly chosen, unrelated words. Avoid familiar quotations, names, birthdays, and other information that someone could associate with you. Follow the website’s requirements, but do not assume that meeting its minimum requirements automatically makes a password a good choice.
A password manager can help when remembering many different passwords becomes difficult. It stores them in a protected digital vault and may generate strong passwords for you. Password managers may be built into a device or browser or provided as a separate app. Protect the manager itself with a strong unlocking method and additional authentication where available. Use it on devices that you control and trust, not as a reason to save your passwords on a public computer.
Someone can help you use your account without knowing its password. When receiving assistance, ask the person to explain the steps while you enter the password privately. Avoid sending it in a message, including it in a screenshot, or reading it aloud. A request from a familiar or helpful person does not make sharing it necessary.
A verification code is a temporary code used to confirm an action or help verify your identity. It may arrive by text message or email, or be generated by an authenticator app, an app used for account verification. Such a code may be part of two-factor authentication, which adds another kind of identity check to a password. Where an account offers additional sign-in protection, follow its instructions to set it up.
A code is not harmless simply because it expires quickly. Someone trying to access an account may need it only once. Do not send or dictate an account-access code to another person, including someone who claims to be helping with a security problem.
Entering a code into a genuine website during a sign-in you initiated is different from giving that code to a person. Before entering it, check both the website and the action being authorized. Do not approve an unexpected sign-in request merely to make the notification disappear.
For account access, treat both your password and your verification codes as private.
A passkey is not another password to memorize. It is a digital sign-in credential managed by a device, a password manager, or a physical security key. You usually authorize its use with the same kind of action used to unlock a device, such as entering its PIN or using a fingerprint or facial recognition. Your fingerprint or facial information stays with the device rather than being sent to the website as your login information.
Behind the scenes, a passkey proves that you hold the correct digital credential without sending a reusable password to the website. It is designed to work with the service for which it was created, making it resistant to fake sign-in pages that try to steal passwords. This is an important advantage, although it does not remove the need to secure your device.
The JW.ORG sign-in page provides Use a Passkey to Log In. A passkey must first be set up for the account, and the device and software must support its use. Follow the account’s on-screen instructions rather than assuming that the button means a passkey already exists.
Before replacing or resetting a device, understand where your passkey is stored and how you would regain access. Some passkeys synchronize through a provider so they can be available on your other devices. Others remain on a particular device or security key. Do not assume that every passkey will automatically transfer to a new phone.
A trusted person can help explain the setup, but the passkey should remain under your control.
A search engine helps you find websites. A browser’s address bar shows the address of the website you are visiting and lets you enter an address directly. Although many browsers use the same bar for searches and addresses, searching for a service is not the same as entering its known website address.
For JW.ORG, type jw.org directly into the address bar and use the official website’s Log In link. You can also use the appropriate website links on the JW Library® Home tab or a bookmark that you previously saved from the genuine website. A bookmark, sometimes called a favourite, is a saved shortcut to a webpage.
Avoid using search results as your usual route to account sign-in. A prominent result or paid advertisement is not proof that a page is genuine. Deceptive advertisements can lead people to imitation websites. A saved bookmark is useful only when the address was checked before it was saved.
Before entering your JW.ORG username or password, check that the website name is login.jw.org. For instance, in https://login.jw.org/username, the website name is login.jw.org; /username identifies a page on that website. Tap or click the address bar when necessary to see the full address.
Be careful with addresses that merely contain familiar words. The fictional address https://login.jw.org.account-check.example/ is not login.jw.org. Extra words have been added to the website name, not just to the page information after a slash.
Also, HTTPS does not prove that a website is trustworthy. It indicates an encrypted connection to that website. A fraudulent website can use HTTPS too, so a padlock symbol, where displayed, is not a guarantee of legitimacy.
When an address is confusing, stop and return through a route you already know.
Phishing, pronounced “fishing,” is an attempt to trick someone into revealing information or taking an unsafe action by pretending to be trustworthy. A message may claim that an account will be closed, that a document needs immediate attention, or that a security problem must be fixed. Its purpose may be to make you act before checking.
A familiar sender’s name is not enough to establish that a message is safe. Names and addresses can be imitated, and a real person’s account can be taken over. A message may also look polished and contain no obvious spelling mistakes.
A link is clickable text, an image, or a button that opens another location. An attachment is a file included with a message, such as a document or photograph. When a message is unexpected or suspicious, leave its links and attachments unopened while you verify it.
Contact the sender separately using a telephone number or messaging contact you already know. Do not rely on contact details supplied in the suspicious message, and do not simply reply to that email. Otherwise, you may be asking the person behind the deception whether their own message is genuine.
On a computer, move the pointer over the link without clicking. The browser or email app will often display the destination address near the pointer or along the bottom of the window.
On a phone or tablet, pressing and holding a link may display its destination or a menu with a preview. The behaviour varies between apps and devices. Avoid selecting Open while trying to inspect the address.
The words displayed in a message may be different from the address behind them. A button labelled “View Document” does not tell you where it goes.
Previewing a link is a useful check, not a guarantee. When you cannot clearly establish its destination, leave it alone and reach the service independently.
Sign in to your JW.ORG account regularly through a trusted route and review your account settings. Reviewing your settings means checking that your personal information is correct, that your sign-in options are still under your control, and that no unfamiliar changes have been made.
Check the information shown in your account, such as your name and personal email address. Make sure the email address is current and that you still have access to it. Review any saved passkeys, too. An unfamiliar entry deserves a closer look, although not immediately recognizing its name does not necessarily mean that someone has accessed your account.
If your account includes an Account Activity feature, use it as an additional check for activity you do not recognize. Read the details carefully before drawing conclusions. An unsuccessful sign-in attempt, where shown, is different from someone successfully accessing your account.
When you notice suspicious changes or believe someone may have obtained your password, change it promptly and check the rest of your account settings. Seek help investigating unfamiliar passkeys or other sign-in options rather than assuming that changing the password resolves every concern.
When you do not understand a setting or an unexpected change, ask your usual account help contact or another trusted, knowledgeable person. They can explain the steps without needing your password or verification codes. Do not dismiss a concern simply because you can still sign in and the account appears to work normally.
A shared device is not limited to a computer in a library or hotel. It can also be a borrowed phone or a family computer used by several people. Prefer your own updated, secured device for sensitive accounts. On another person’s device, you may not know who can access the browser or what software is running.
When using a device that is not yours, decline offers to save your password. Avoid options such as Remember me, Stay signed in, or Trust this device. Do not save a passkey to someone else’s device or leave your personal password manager accessible there.
When finished, use the website’s Log Out or Sign Out control. Closing a tab is not a reliable substitute because the browser may still remember the signed-in session. A session is the period during which a website recognizes that you have signed in. After signing out, close the browser windows you used.
A private, incognito, or guest window may reduce the browsing information left behind, but it does not make an untrusted computer safe or hide everything from whoever manages it. Downloaded files may also remain after a private window is closed. Avoid downloading private documents onto a shared device unless genuinely necessary.
Receiving a suspicious message does not itself mean that your account has been accessed. However, entering your password on a deceptive page, sharing an account-access code, or noticing unauthorized changes calls for prompt action.
Reach the genuine service independently, using a trusted device. Change an exposed password immediately. When that password was reused elsewhere, replace it on those accounts too, using a different password for each one. Use any available option to end other signed-in sessions, and review the account’s security settings. When access has been lost, use the service’s genuine recovery process or established help contact.
When a suspicious download or installation may have affected the device, avoid entering more passwords on it while the problem is investigated. Malware means harmful software that can steal information, interfere with a device, or damage files. Use the device’s appropriate security tools and seek assistance from someone you trust, rather than calling a number displayed in a frightening pop-up.
There is no need to hide a mistake out of embarrassment. Explaining what happened can help someone give you the right assistance.
Good security is not one setting that you enable and forget. It is a combination of careful choices: locking your device, keeping it updated, protecting account access, checking where you sign in, and pausing when something seems unusual.
Start with the precautions you understand, and ask for help with the others. A trusted helper can explain what to select and why without taking control of your private passwords or verification codes.
Asking for help is part of protecting your account, not a sign that you have failed.