October is Cyber Security Awareness Month, and this year’s message is a simple one: your best defence isn’t a piece of software or a setting buried in an app. It’s you — the pause before you click, the second look at a message that feels slightly off, the habit of locking things down before there’s a reason to.
That pause matters more than it used to. AI has made scams harder to spot on sight — messages that once had obvious red flags now read smoothly, sound familiar, and arrive at exactly the right moment. The good news is that the fundamentals still work. A handful of everyday habits, done consistently, close most of the gaps criminals rely on.
This month, we’re covering four of them: spotting scams before you act on them, managing your passwords properly, turning on multi-factor authentication, and locking down the devices everything else runs on.
Spot the Scam Before It Spots You
AI has changed what a scam looks like. Poor grammar and generic greetings used to be the tell; now messages can be polished, personalized, and timed around something plausible — a delivery you’re expecting, a bill that’s overdue, a request from a coworker’s name you recognize. The writing itself won’t give it away anymore, so the shift has to be in what you do with it.
The Canadian Anti-Scam Coalition sums up the habit well: Stop. Check. Talk. Stop before you click a link, download an attachment, or reply with any personal information — urgency is the biggest tell of all, since real organizations rarely need an answer in the next ten minutes. Check the request through a channel you already trust and control, like the number on the back of your credit card or the app you already have installed, rather than any contact details included in the message itself. And if something still feels off, talk it through with someone before you act — a second opinion catches what a rushed decision misses.
Make Your Passwords Work Harder Than You Do
Reusing passwords means one breached account can unlock several others — if the same email-and-password combination works on your banking site as it does on a retailer that got hacked last year, criminals only need to find it once. A password manager removes the temptation to reuse anything, because it does the remembering for you: it generates a long, unique password for every account, fills it in automatically when you log in, and keeps everything locked behind one strong master password that you’re the only one who needs to know.
Setting one up takes a single afternoon and pays off for years. Start with the accounts that matter most — email, banking, and anything tied to your identity — and let the manager take over each time you create a new login or update an old one.
Turn On Multi-Factor Authentication
Multi-factor authentication (MFA) adds a second step beyond your password, so even if a criminal gets hold of it, that alone isn’t enough to get in. In practice, that second step usually shows up one of a few ways: a code texted or emailed to you, a tap to approve on an app you already use, or a code generated by a dedicated authenticator app. All of them are far better than a password on its own — a text or email code is a fine place to start, and an authenticator app is a stronger option where it’s offered, since it isn’t tied to your phone number.
It’s one of the single most effective things you can do to protect an account, and it takes a couple of minutes per account to switch on. Start with your email, since it’s often the account that can reset everything else, then work through banking and anything tied to your identity.
Protect the Devices Everything Else Runs On
Your phone and laptop are the front door to almost everything you do online — banking, email, saved passwords, years of messages. If either one is unlocked or unpatched, everything behind it is exposed too, which makes the basics worth taking seriously rather than clicking past.
Keep both updated: those updates usually patch the exact vulnerabilities criminals are actively exploiting, so a postponed update is a real window of risk, not just a nagging notification. Lock every device with a PIN, passcode, or biometric — not just the ones that feel important — and think twice before connecting to public Wi-Fi for anything involving banking or personal information, since an unsecured network is an easy place for someone else to intercept what you’re sending.
None of This Requires Becoming an Expert
You don’t need to understand how AI-generated scams work to defend against them, and you don’t need to overhaul how you use technology overnight. You just need the habits above, applied consistently — most of the people who avoid trouble aren’t doing anything exotic, they’re doing the basics reliably, on the days they’re busy as much as the days they’re not.
A password manager, MFA on your key accounts, updated devices, and a healthy pause before you click — together, that’s most of what a determined scammer is counting on you not to do. Pick whichever one you haven’t gotten around to yet and start there this week.
Remember to stay vigilant, stay informed, and stay safe.


