Learning evidence
A personal threat model, incident record, recovery plan and family safety checklist
Turns passwords, MFA, updates, backups, phishing, social engineering, privacy and cyberbullying into behaviour-based security habits.
Completion evidence for this pathway is a personal threat model, incident record, recovery plan and family safety checklist. Page count or time spent alone does not demonstrate competence.
The intended capstone is a family digital-safety plan built with fictional accounts and sample messages. It should connect the lessons in one artefact and retain failed tests as evidence.
A personal threat model, incident record, recovery plan and family safety checklist
A family digital-safety plan built with fictional accounts and sample messages
When opening a new account or device, after a breach notice, when recovery details change and every three months.
Lesson · Account security combines unique credentials, protected recovery methods, additional authentication and attention to unusual activity. This lesson includes
Open page →Lesson · A personal digital safety plan identifies important accounts and devices, likely risks, preventive controls and recovery actions. This lesson includes a wo
Open page →Lesson · Synthetic media can imitate faces, voices and events, so urgent or surprising content should be verified through independent evidence. This lesson includes
Open page →Lesson · Digital footprints are the records created by our online actions and by material that other people publish about us. This lesson includes a worked example,
Open page →Lesson · Phishing uses trusted-looking messages to pressure people into opening links, files or forms that steal information or money. This lesson includes a worked
Open page →Lesson · App permissions should match the feature being used and remain limited in time, scope and data access. This lesson includes a worked example, practice task
Open page →Lesson · Ethical security testing requires explicit permission, a defined scope, safe methods and responsible reporting. This lesson includes a worked example, prac
Open page →Lesson · Photos can reveal location, routines and identity through visible details, file metadata and the context in which they are shared. This lesson includes a w
Open page →Project · This project turns digital safety principles into a clear, family-friendly checklist that can be reviewed without collecting anyone’s passwords. This lesso
Open page →Project · This project builds a scenario laboratory where learners identify phishing signals and choose a safe verification path. This lesson includes a worked examp
Open page →Lesson · Network safety depends on knowing which network is trusted, protecting the router and limiting what devices can reach. This lesson includes a worked exampl
Open page →Lesson · Safe downloading means checking the source, file type, signature or reputation and the permissions requested after installation. This lesson includes a wor
Open page →Lesson · Social engineering targets human trust, habits and urgency rather than relying only on a technical vulnerability. This lesson includes a worked example, pr
Open page →Lesson · Two-factor authentication asks for a second proof, while passkeys use domain-bound cryptographic credentials that resist many phishing attacks. This lesson
Open page →Lesson · Updates close known weaknesses, backups protect important work and recovery plans turn a failure into a manageable event. This lesson includes a worked exa
Open page →Lesson · A safe response to cyberbullying protects the person, preserves evidence and brings in trusted adult or platform support. This lesson includes a worked exa
Open page →Quiz · A 12-question interactive assessment for Digital Safety and Mindful Internet Use, with explanations and a newly shuffled option order on every start. This
Open page →No week closes with reading alone. Use one session for concept and example, a second for practice, and a short third session for testing and explanation. Do not accelerate when a prerequisite is missing.
| Week | Focus | Evidence to produce |
|---|---|---|
| 1 | Account Security: More Than a Password, How to Recognise Phishing Messages, Project: A Family Digital Safety Checklist, Social Engineering: Attacks That Target People | A personal threat model, incident record, recovery plan and family safety checklist |
| 2 | Building a Personal Digital Safety Plan, Managing App Permissions Mindfully, Project: Phishing Detective Scenario Lab, Two-Factor Authentication and Passkeys | A family digital-safety plan built with fictional accounts and sample messages |
| 3 | Deepfakes, Voice Cloning and Synthetic Media, Permission and Boundaries in Ethical Hacking, Public Wi-Fi and Home Network Security, Updates, Backups and Recovery Plans | Error log and second version |
| 4 | Digital Footprints: The Traces We Leave Online, Photo, Location and Metadata Privacy, Safe Downloads and Malware Protection, What to Do About Cyberbullying | Quiz result, misconception and next application |
The pathway's distinctive question is: How do you recognise real risk around an account, device, message or online relationship and choose a safe response? A first response may be a definition, but completion requires a personal threat model, incident record, recovery plan and family safety checklist. If input, method, limits and review date are unclear, the result is not traceable even when it looks strong.
Start with two different activities among Deepfakes, Voice Cloning and Synthetic Media, Digital Footprints: The Traces We Leave Online, Permission and Boundaries in Ethical Hacking, Photo, Location and Metadata Privacy. In one, explain the concept in your own words; in the other, perform an application, measurement or user test. The two activities should not close with the same type of evidence. This distinction shows that Digital Safety and Mindful Internet Use has been tested through different forms of production.
Later connect What to Do About Cyberbullying, Social Engineering: Attacks That Target People, Managing App Permissions Mindfully, Public Wi-Fi and Home Network Security to the capstone: A family digital-safety plan built with fictional accounts and sample messages Keep failed tests as well as successful ones. For every error, record conditions, expected result, actual result, possible cause and the single change made.
Check these traps separately: Responding immediately to urgent or frightening messages; Reusing one password across accounts; Treating updates as only new features; Calling unauthorised testing ethical hacking. Reading a trap is insufficient; find an example from your own work and state which evidence made the problem visible.
Return rule: When opening a new account or device, after a breach notice, when recovery details change and every three months. Do not delete the previous record; add a date, changed tool or source, new evidence and the next mini trial. Progress is therefore tracked through the quality of explanation, application and correction—not the number of pages completed.
The answer must produce evidence, not only a definition: A personal threat model, incident record, recovery plan and family safety checklist.
Keep it with conditions, expected result, actual result and the correction.
No. Sources define method and limits; practice evidence must be produced separately.
When opening a new account or device, after a breach notice, when recovery details change and every three months.
A family digital-safety plan built with fictional accounts and sample messages
Primary or institutional source for method and technical limits.
Open source →Primary or institutional source for method and technical limits.
Open source →Primary or institutional source for method and technical limits.
Open source →