Safe Browsing and Downloads
Practice safer decisions around websites, browser permissions, downloads, updates, and public networks.
Check the Website
theoryLearn what HTTPS can tell you and what it cannot.
A lock icon is not a trust certificate
HTTPS encrypts the connection between your browser and the website. It helps prevent people on the network from reading or changing traffic, but it does not prove that the website is honest. A phishing site can also use HTTPS.
Check the full domain, avoid lookalike spellings, and use a known bookmark for sensitive services. Never rely on a lock icon alone before entering a password or payment details.
Knowledge Check
A site shows HTTPS and a lock icon. What does that actually tell you?
Review Permissions and Downloads
theoryChoose the least access an application or website needs to perform its task.
Grant only the access you can explain
A website that wants access to your camera, microphone, location, or notifications should explain why it needs that access. Deny requests that do not match the task and remove permissions that are no longer needed.
Download software from the official publisher or a trusted app store. Avoid “urgent update” pop-ups and unsolicited attachments. Check the publisher, file name, and expected source before opening anything.
Knowledge Check
A simple website asks for microphone access but gives no reason. What is the safer choice?
Update and Connect Carefully
theoryReduce exposure by keeping devices updated and treating public networks as untrusted.
Reduce the opportunities attackers get
Install security updates from the device or software vendor and restart when required. Updates fix known weaknesses that attackers may already understand.
Public Wi-Fi can be monitored or impersonated. Avoid sensitive activity on an unknown network when possible, use your device’s cellular connection or a trusted VPN when appropriate, and never ignore certificate or browser security warnings.
Knowledge Check
You need to use public Wi-Fi. Which habit meaningfully lowers the risk?
Evaluate an Update Prompt
theoryDistinguish an official update path from a suspicious browser pop-up.
Start updates from the software, not the warning
A pop-up that says your device is infected or that you must install a codec immediately is not proof that an update is needed. Close the tab without clicking its buttons. Open the device settings or the software’s official update screen and check there instead.
Do not install extensions, remote-access tools, or “cleaners” because a web page demands them. If a warning keeps appearing, ask your organisation’s support team or use the vendor’s official help page.
Knowledge Check
A browser pop-up insists that an update is urgent. Where should you check first?
Choose the Safer Path
theoryApply safe browsing decisions to a website, download, and network scenario.
Stop when the source or request cannot be verified
Before entering sensitive information or opening a download, ask three questions: Do I recognise the full domain? Did I start this request? Can I verify the source through an official channel?
If the answer to any question is no, stop and find a safer path. Use a bookmark or manually typed address, obtain software from the vendor, deny unnecessary permissions, and postpone sensitive activity until you have a trusted connection.
Knowledge Check
On public Wi-Fi, a site asks you to install an extension before it will show your account. What should you do?
Investigate a Suspicious Download
theoryDecide how to respond when a download, permission request, and network warning appear together.
Do not let several warnings become one rushed decision
While using airport Wi-Fi, a website displays a fake “browser out of date” banner. It downloads an installer, requests administrator access, and asks you to disable security protection. The page uses HTTPS, but you reached it through an advertisement rather than a known bookmark.
Do not run the installer or disable protections. Close the page, delete the download without opening it, disconnect from the untrusted network if possible, and check for updates from the browser’s own settings. If the file ran or requested credentials, tell support and follow the device’s malware-response process.
Knowledge Check
An airport Wi-Fi page pushes an installer and asks you to disable security protection. What is the safest complete response?