LEARNING PATHWAY

Digital Safety and Mindful Internet Use

Turns passwords, MFA, updates, backups, phishing, social engineering, privacy and cyberbullying into behaviour-based security habits.

Last updated: 27 July 2026
CENTRAL QUESTION

How do you recognise real risk around an account, device, message or online relationship and choose a safe response?

Completion evidence for this pathway is a personal threat model, incident record, recovery plan and family safety checklist. Page count or time spent alone does not demonstrate competence.

The intended capstone is a family digital-safety plan built with fictional accounts and sample messages. It should connect the lessons in one artefact and retain failed tests as evidence.

Learning evidence

A personal threat model, incident record, recovery plan and family safety checklist

Capstone

A family digital-safety plan built with fictional accounts and sample messages

Return trigger

When opening a new account or device, after a breach notice, when recovery details change and every three months.

LESSON MAP

17 items from concept to evidence

Account Security: More Than a Password

Lesson · Account security combines unique credentials, protected recovery methods, additional authentication and attention to unusual activity. This lesson includes

Open page →

Building a Personal Digital Safety Plan

Lesson · A personal digital safety plan identifies important accounts and devices, likely risks, preventive controls and recovery actions. This lesson includes a wo

Open page →

Deepfakes, Voice Cloning and Synthetic Media

Lesson · Synthetic media can imitate faces, voices and events, so urgent or surprising content should be verified through independent evidence. This lesson includes

Open page →

Digital Footprints: The Traces We Leave Online

Lesson · Digital footprints are the records created by our online actions and by material that other people publish about us. This lesson includes a worked example,

Open page →

How to Recognise Phishing Messages

Lesson · Phishing uses trusted-looking messages to pressure people into opening links, files or forms that steal information or money. This lesson includes a worked

Open page →

Managing App Permissions Mindfully

Lesson · App permissions should match the feature being used and remain limited in time, scope and data access. This lesson includes a worked example, practice task

Open page →

Permission and Boundaries in Ethical Hacking

Lesson · Ethical security testing requires explicit permission, a defined scope, safe methods and responsible reporting. This lesson includes a worked example, prac

Open page →

Photo, Location and Metadata Privacy

Lesson · Photos can reveal location, routines and identity through visible details, file metadata and the context in which they are shared. This lesson includes a w

Open page →

Project: A Family Digital Safety Checklist

Project · This project turns digital safety principles into a clear, family-friendly checklist that can be reviewed without collecting anyone’s passwords. This lesso

Open page →

Project: Phishing Detective Scenario Lab

Project · This project builds a scenario laboratory where learners identify phishing signals and choose a safe verification path. This lesson includes a worked examp

Open page →

Public Wi-Fi and Home Network Security

Lesson · Network safety depends on knowing which network is trusted, protecting the router and limiting what devices can reach. This lesson includes a worked exampl

Open page →

Safe Downloads and Malware Protection

Lesson · Safe downloading means checking the source, file type, signature or reputation and the permissions requested after installation. This lesson includes a wor

Open page →

Social Engineering: Attacks That Target People

Lesson · Social engineering targets human trust, habits and urgency rather than relying only on a technical vulnerability. This lesson includes a worked example, pr

Open page →

Two-Factor Authentication and Passkeys

Lesson · Two-factor authentication asks for a second proof, while passkeys use domain-bound cryptographic credentials that resist many phishing attacks. This lesson

Open page →

Updates, Backups and Recovery Plans

Lesson · Updates close known weaknesses, backups protect important work and recovery plans turn a failure into a manageable event. This lesson includes a worked exa

Open page →

What to Do About Cyberbullying

Lesson · A safe response to cyberbullying protects the person, preserves evidence and brings in trusted adult or platform support. This lesson includes a worked exa

Open page →

Digital Safety Quiz

Quiz · A 12-question interactive assessment for Digital Safety and Mindful Internet Use, with explanations and a newly shuffled option order on every start. This

Open page →
FOUR-WEEK PLAN

Place lessons in a production cycle

No week closes with reading alone. Use one session for concept and example, a second for practice, and a short third session for testing and explanation. Do not accelerate when a prerequisite is missing.

Place lessons in a production cycle table
WeekFocusEvidence to produce
1Account Security: More Than a Password, How to Recognise Phishing Messages, Project: A Family Digital Safety Checklist, Social Engineering: Attacks That Target PeopleA personal threat model, incident record, recovery plan and family safety checklist
2Building a Personal Digital Safety Plan, Managing App Permissions Mindfully, Project: Phishing Detective Scenario Lab, Two-Factor Authentication and PasskeysA family digital-safety plan built with fictional accounts and sample messages
3Deepfakes, Voice Cloning and Synthetic Media, Permission and Boundaries in Ethical Hacking, Public Wi-Fi and Home Network Security, Updates, Backups and Recovery PlansError log and second version
4Digital Footprints: The Traces We Leave Online, Photo, Location and Metadata Privacy, Safe Downloads and Malware Protection, What to Do About CyberbullyingQuiz result, misconception and next application
COMMON TRAPS

They look fast but weaken learning

DEEPENING

Deepening evidence in Digital Safety and Mindful Internet Use

The pathway's distinctive question is: How do you recognise real risk around an account, device, message or online relationship and choose a safe response? A first response may be a definition, but completion requires a personal threat model, incident record, recovery plan and family safety checklist. If input, method, limits and review date are unclear, the result is not traceable even when it looks strong.

Start with two different activities among Deepfakes, Voice Cloning and Synthetic Media, Digital Footprints: The Traces We Leave Online, Permission and Boundaries in Ethical Hacking, Photo, Location and Metadata Privacy. In one, explain the concept in your own words; in the other, perform an application, measurement or user test. The two activities should not close with the same type of evidence. This distinction shows that Digital Safety and Mindful Internet Use has been tested through different forms of production.

Later connect What to Do About Cyberbullying, Social Engineering: Attacks That Target People, Managing App Permissions Mindfully, Public Wi-Fi and Home Network Security to the capstone: A family digital-safety plan built with fictional accounts and sample messages Keep failed tests as well as successful ones. For every error, record conditions, expected result, actual result, possible cause and the single change made.

Check these traps separately: Responding immediately to urgent or frightening messages; Reusing one password across accounts; Treating updates as only new features; Calling unauthorised testing ethical hacking. Reading a trap is insufficient; find an example from your own work and state which evidence made the problem visible.

Return rule: When opening a new account or device, after a breach notice, when recovery details change and every three months. Do not delete the previous record; add a date, changed tool or source, new evidence and the next mini trial. Progress is therefore tracked through the quality of explanation, application and correction—not the number of pages completed.

MICRO QUIZ

Test the reasoning behind the module

1. How do you recognise real risk around an account, device, message or online relationship and choose a safe response?

The answer must produce evidence, not only a definition: A personal threat model, incident record, recovery plan and family safety checklist.

2. What should happen to the first failed test?

Keep it with conditions, expected result, actual result and the correction.

3. Does reading a source prove that practice occurred?

No. Sources define method and limits; practice evidence must be produced separately.

4. When should the module be reopened?

When opening a new account or device, after a breach notice, when recovery details change and every three months.

5. What does the capstone connect?

A family digital-safety plan built with fictional accounts and sample messages

OFFICIAL / PRIMARY SOURCES

Verify technical detail in current sources

CISA Secure Our World

Primary or institutional source for method and technical limits.

Open source →

NIST Cybersecurity Resource Center

Primary or institutional source for method and technical limits.

Open source →

NIST NICE cybersecurity education

Primary or institutional source for method and technical limits.

Open source →