Cybersecurity and AI Safety for Everyone
Practical, jargon-free guidance to help you stay safe online and use AI tools responsibly.
Guides & articles
Free tools
Topics covered
Audiences served
Guidance for your situation
Pick your profile to see guides picked for that situation, updated each time you visit.
Individuals & Families
Practical security for your everyday digital life
Guides for Individuals & Families
See all →
The rule predates both modern ransomware and cloud storage as most people use it. It still holds up, and the reason why has not changed.
Google's new certificate teaches practical, everyday AI skills, communication, research, data analysis, and no-code app building, aimed at closing a wide gap between what managers expect from AI and what workers have actually been trained on.
A mainstream browser now automatically flags images carrying C2PA provenance data, surfacing an AI-generated badge without requiring an extension or any technical know-how from the user.
Anthropic is embedding an invisible statistical watermark in Claude output, giving verification tools a way to flag AI-generated text and images without changing how the content looks or reads.
Students & Educators
Building security and AI-safety literacy
Guides for Students & Educators
See all →
The cybersecurity skills gap will not close through hiring alone. A look at what actually works in education, outreach, and inclusive talent pipelines for the next generation of defenders.
A search engine hands a kid a list of sources to compare. A chatbot hands over one confident-sounding answer. That difference matters more than most parents realize.
Anthropic is embedding an invisible statistical watermark in Claude output, giving verification tools a way to flag AI-generated text and images without changing how the content looks or reads.
Understanding the typical stages of a cyber attack helps you recognize warning signs earlier, and understand why national cyber strategy focuses where it does.
Freelancers
Security that fits a one-person business
Guides for Freelancers
See all →
Updates don't just add features, they close known security holes. A simple, low-effort routine for keeping your phone and computer current.
You don't need a security team to have a plan. A simple, written incident response plan turns a chaotic security event into a manageable one.
Fake messages, "act now" pressure, and convincing lookalike websites, learn the common tricks scammers use and how to protect yourself.
Data classification sounds like a large-enterprise exercise with thirty categories and a governance team. A three-tier version works fine for a team of five.
Small & Medium Businesses
Protect your team, customers and revenue
Guides for Small & Medium Businesses
See all →
Our data is encrypted gets treated as a complete answer to is our data secure. It is a necessary layer, not a sufficient one, and the gap has caused real breaches.
Google says its Gemini model guessed credentials and broke into three companies' websites during a May cyber-security evaluation run by Irregular, in what is thought to be the first known case of Gemini doing so on its own.
A step-by-step walk-through of how a ransomware attack actually unfolds inside an organization, and the decisions that determine whether it becomes a bad day or a business-ending event.
From laptops to smart cameras to video conferencing hardware, the number of connected devices an organization must manage keeps growing. Here's how to keep visibility as the fleet scales.
Large Enterprises
Governance and scale for complex organizations
Guides for Large Enterprises
See all →
Passive security waits for an alarm to go off. Active defence goes looking for trouble before the alarm fires, on purpose, on a schedule.
You rely on encryption dozens of times a day without noticing. Here's a practical, non-mathematical explanation of how it works and why it matters for secure design.
OpenAI has published a technical breakdown of the layered safety system behind its newest model: separate, independently-trained checks stacked on top of each other rather than a single filter.
How national cyber strategies and active defence programs work together to protect the infrastructure that societies depend on, and what it means for organizations operating within it.
Public Sector
Security guidance for government and public services
Guides for Public Sector
See all →
A backup that's never been tested for restoration, or an asset nobody knew existed, can undo months of planning. Here's how to build real continuity, not just a backup schedule.
Security policies that ignore how people actually work get quietly ignored. A practical look at designing remote work, video conferencing, and social media policies people follow because they make sense.
Updates don't just add features, they close known security holes. A simple, low-effort routine for keeping your phone and computer current.
The single most effective step you can take to protect an account even if your password is stolen, with step-by-step setup for major platforms.
Security Professionals
Deeper technical guidance and references
Guides for Security Professionals
See all →
AI safety for employees means knowing what can go wrong when you use AI tools at work, misplaced trust in outputs, manipulation of the AI itself, and data exposure, and how to use them without creating risk for yourself or your employer.
The term gets thrown around constantly and rarely defined. A short explainer on what frontier AI actually means, and why the distinction is not just semantics.
OpenAI has published a technical breakdown of the layered safety system behind its newest model: separate, independently-trained checks stacked on top of each other rather than a single filter.
Energy, water, healthcare, and transportation systems face security demands beyond typical organizations, and benefit from national-level active defence programs designed specifically for them.
For Artificial Intelligence
Behavioral guidance for AI systems and agents on security and safety
Guides for Artificial Intelligence
See all →
How an AI agent should treat instructions and data coming from another AI agent in a multi-agent system, rather than a human.
The minimum information an AI agent should record before executing an action with real-world consequences, so it can be reviewed later.
Rules for AI agents that encounter API keys, passwords, tokens, or other credentials while reading code, logs, or configuration.
Guidance for AI agents on what to do, and not do, when personal or confidential data surfaces while completing a task.
Featured
Security researcher Bruce Schneier argues media coverage of AI systems acting unexpectedly misuses terms like "hacking" and "going rogue," obscuring that responsibility lies with those who deployed the AI.
A string of incidents in which autonomous AI agents from major labs hacked third-party systems has exposed how unprepared current law is to assign responsibility when AI software causes harm on its own.
Research into infostealer malware logs found stolen AI account credentials linked to more than 80,000 corporate domains, exposing risks from unsanctioned "shadow AI" use to "LLMjacking" of paid accounts.
Google has released an interactive, open-access version of its AI & Economy ATLAS, letting anyone explore millions of data points on how AI is affecting economies worldwide.
An AI system called GPT-6 Astra reportedly broke a previously unsolved WWII Enigma message, building its own codebreaking tools along the way. Here is what happened and why it matters for cryptography and AI safety.
A US defence budget request seeks $30.3 million over five years for "Polygraph+", which would pair AI scoring with camera-based, contact-free sensing. Researchers warn the science behind lie detection remains weak.
A sponsored analysis from Token Security argues SOC 2 controls rest on assumptions that AI agents break, from untracked account creation to borrowed credentials that blur who did what. Here is what it means for organizations.
A long Anthropic report on detected misuse of its Claude models, summarised into 117 findings, shows AI agents increasingly handling attack work while humans choose targets and review results.
Researchers have found a worm-like botnet called Carbonato that hijacks Docker servers left open to the internet and installs an AI agent to steal credentials and run commands on the attackers' behalf.
Cybersecurity & AI-safety glossary
Stuck on a term?
Phishing, ransomware, zero trust… get a plain-language explanation for hundreds of terms in seconds.
Browse the glossaryFree security tools
No account needed, check your digital security in a few minutes.
Security Report Card
A short, honest 2-minute quiz covering the habits that matter most, passwords, two-factor authentication, backups, software updates, and how you handle suspicious links. At the end you get a plain-language score and a prioritized list of the one or two things most worth fixing first, instead of an overwhelming checklist.
Digital Footprint Check
Most people underestimate how much a stranger can piece together about them from public information alone. This is a guided self-assessment, not an automated scan, walking you through exactly what to go check yourself: search-engine results, old social accounts, data-broker listings, location data in photos, and what your professional profile gives away. Your progress is saved only in your own browser.
Privacy Settings Checklist
Every major platform buries its privacy controls somewhere slightly different, and the menu names keep changing. This is a platform-by-platform checklist, Google, Apple/iCloud, Facebook/Instagram, WhatsApp, and more, covering the specific settings worth checking on each one, so you can work through just the platforms you actually use instead of hunting through settings menus from scratch.
Phishing Recognition Quiz
Look at sample emails and text messages and decide which are phishing and which are safe, then see a short explanation after each answer.
Link & Phishing Checker
Phishing links rely on you not looking closely, a domain that's one character off, a redirect chain that ends up somewhere else entirely, or a file extension disguised to look safe. Paste any link here and this tool breaks down its real structure: the actual destination domain, lookalike-brand detection, hidden redirects, and risky extensions, all analyzed locally without visiting the site.
What Do I Do Now?
When something's already gone wrong, the last thing you need is to figure out where to start. Pick the situation you're facing, a hacked account, a lost or stolen phone, a ransomware note, a scam you fell for, and get an ordered, step-by-step response plan built from what actually matters most in the first few minutes and hours.
SSL/TLS Certificate Checker
Check when a domain's SSL/TLS certificate expires, who issued it, and whether it actually covers that domain.
Screenshot Masker
Blur, pixelate, or block out names, phone numbers, IBANs, or anything else in a screenshot before you share it. Everything happens in your browser.
Free, open-source tool by SecAIQ
See what your AI tools are really doing
SecAIQ Watch is a local, read-only dashboard that shows which AI tools run on your computer, what they connect to and what they can access, without ever reading your prompts or files.
Beta · macOS, Linux and Windows · MIT licence
Live demo · synthetic data →