CYBERSECURITY

Online safety for children: a calm plan for parents

A practical online-safety plan for children and parents: accounts, privacy, games, messages, scams, reporting and what to do after an incident.

tomek.st5 min readBEGINNER

Online safety for children is not about reading every message or banning the internet. It works when a child can bring a problem to an adult without fear or shame, and the parent has prepared the accounts and a simple response plan.

Set rules that are easy to remember

Start with a short list:

  • never send passwords, codes or document photographs in a message,
  • confirm urgent requests for money through another channel,
  • do not install an application because someone in a game or chat asked,
  • do not meet an online contact without a guardian’s knowledge,
  • bring threats, blackmail or requests for intimate images to a trusted adult immediately.

The most important rule is that reporting a problem does not automatically mean losing the device. Otherwise the incident will be hidden.

Secure accounts and devices

Each important account needs a unique password and an additional sign-in factor. A parent or guardian should keep recovery codes safely. Keep the operating system, browser and games updated.

Check who can send messages, whether the profile exposes a school or location, which purchases need approval, whether photos and contacts are backed up, and how to sign every device out of the account.

Parental controls are an additional barrier. They do not replace a conversation and cannot stop a scam when the child willingly gives away a code.

Games and messaging

A contact in a game remains a stranger until their identity has been confirmed outside the game. Free currency, a rare item or an “account test” often leads to a fake sign-in page.

Use the official application or type the known address yourself. Do not sign in through a chat link, and never give an MFA code to someone claiming to recover the account.

When something happens

Do not immediately delete the conversation. Record screenshots, the account name, website address, date and time. Then:

  1. stop contact and do not pay a blackmailer,
  2. change the password from a trusted device,
  3. revoke other sessions,
  4. report the account to the platform,
  5. contact the bank if payment data was shared,
  6. report threats, blackmail or sexual material to the appropriate authorities.

The account-takeover emergency card keeps recovery steps in a sensible order. When the scope is unclear, lawful incident triage can establish the next steps.

Review monthly, not once

Together, check privacy settings, active sessions, recovery methods and applications with account access. A short recurring review builds a stronger habit than one conversation after an incident.

Want this in a lab or in production?

The article stays free. The form is for scope, not a paywall.

I usually reply within 1 business day. The inquiry is stored on the server; you get a confirmation from hello@tomek.st. Sending does not commit you to a contract.