Skip to main content

🔒 Lesson 1.3: The Internet & Working Safely Online

The internet is one of the most powerful tools on any work computer — you'll use it to look things up, fill in forms, sign in to company systems, and find answers fast. But being good with the internet at work isn't just about using it; it's about using it safely. Protecting your accounts, your company's data, and your customers' information is part of nearly every modern job. In this lesson you'll learn to browse and search effectively, build strong login habits (strong passwords and multi-factor sign-in), spot phishing scams, and protect data and privacy at work. None of this requires being a "computer person" — these are simple, learnable habits, and they make you a trusted employee.

🎯 About this course

This course builds Northstar-aligned digital skills; the official Northstar assessment/certificate is earned separately at sponsoring sites (many libraries and programs offer it free). Web browsers and company sign-in tools vary (Chrome, Edge, Safari, Firefox; different password managers and MFA apps), so we focus on the transferable habits and general steps — check the exact buttons on the computer and systems you use. Best of all: practice on a real computer as you go, and you can't break anything by exploring a browser.

📚 What You'll Learn

By the end of this lesson, you will be able to:

  • Use a web browser confidently — tabs, the address bar, bookmarks — and search smartly
  • Tell reputable sources from unreliable ones when you look things up for work
  • Create strong, unique passwords and understand password managers
  • Use multi-factor authentication (MFA/2FA) and know why it matters
  • Spot phishing and scams, and know to report them to IT and protect company data

⏱️ Estimated Time: 55 minutes (go at your own pace — there's no clock on you)

🎯 Project: Add a "My Online Safety at Work" page to your "My Workplace Digital Toolkit" folder — your password + MFA plan and your phishing red-flag checklist.

In This Lesson

The Internet at Work

The internet is a core work tool. On the job you'll use the web to check a company website, look up a policy or a "how-to," fill out an online form, submit a timesheet, sign in to systems your employer uses, and find quick answers when you're stuck. Being comfortable and quick on the web saves time every single day — and employers notice.

But there's a second half to this skill that matters just as much: security is part of the job. When you sign in to a company account, you're holding a key to your employer's information — and sometimes to customers' private data too. That's why nearly every workplace now expects employees to use strong passwords, verify their identity with a second step, and know how to spot a scam. This isn't about being paranoid; it's about being trustworthy and professional.

Good news: the safety habits in this lesson are simple and completely learnable. You don't need to understand how the internet works under the hood. You just need a handful of reliable habits — and once they're habits, they protect you automatically. This is workplace-focused online safety; if you'd also like a gentle tour of personal online safety (phones, personal accounts, bills, government and health services), the Digital & Life Skills course covers that. Here, we focus on company accounts, company data, and phishing at work.

🧠 Mindset

You might worry that "online security" is only for tech experts. It isn't. Security at work is really just a small set of good habits — like locking a door when you leave — that anyone can learn. Every strong password you make and every scam you catch protects both you and your employer, and that makes you more valuable, not less capable. Attackers count on people feeling rushed or embarrassed to ask. So slow down, ask questions freely, and remember: being careful online is a strength, and it's a skill you can absolutely build. 🌱

Browsers & Searching Effectively

A web browser is the program you use to visit websites. The common ones at work are Google Chrome, Microsoft Edge, Safari (on Apple computers), and Firefox. They look a little different, but they all work the same way, so the skills transfer from one to the next.

Here are the parts of a browser you'll use constantly:

PartWhat it does
Address barType a website's address here (like irs.gov) to go straight to it
Search box / address bar searchType words (not an address) and press Enter to search the web
TabsOpen several pages at once, side by side, and click between them
Back / Forward buttonsReturn to the page you were just on, or go forward again
Refresh (reload)Reloads the current page if it looks stuck or out of date
Bookmarks / FavoritesSave a page you use often so you can reopen it in one click

One point that trips people up: the address bar versus searching. In most modern browsers the same bar does both. If you know the exact web address, type it (for example, your company's website) and press Enter to go there directly. If you don't know the address, type words — a question or keywords — and press Enter to search. When in doubt, searching is fine; you'll usually find what you need in the first few results.

🔎 Searching smartly

Good searching is a real work skill. A few habits make a big difference:

  • Use specific keywords. Instead of "help," search "how to add a signature in Outlook." The more specific your words, the better your results.
  • Read the results before clicking. Each result shows a title, a web address, and a short description. Skim these to pick the most relevant, trustworthy one — don't just click the very first thing.
  • Prefer official and reputable sources. For rules, benefits, or forms, government sites (ending in .gov) and the official company's own website are the most reliable. For how-to steps, the software maker's own help pages (for example, Microsoft or Google support) are excellent.
  • Refine and try again. If the results aren't helpful, change your words and search again. Searching is a conversation, not a one-shot.
  • Watch for ads. The top results are sometimes labeled "Sponsored" or "Ad." They're paid placements, not always the best answer — glance for that label.

Telling reliable sources from unreliable ones is a skill of its own, called information literacy. We'll go deeper on evaluating sources and solving problems at work in Lesson 4.2: Information Literacy & Problem-Solving at Work. For now, the rule of thumb is: prefer official sites, cross-check anything important, and be skeptical of results that seem too dramatic or want you to pay or sign in unexpectedly.

💡 Tabs are your friend

Tabs let you keep several pages open at once — say, a form you're filling out in one tab and the instructions in another. To open a link in a new tab, right-click it and choose "Open in new tab" (or hold Ctrl while clicking on Windows, Cmd on Mac). Switch between tabs by clicking them along the top. When you're done with a tab, click its little x to close it. Just don't open so many that you lose track — a handful is plenty.

Strong Passwords & Multi-Factor Login

Your password is the key to your work accounts. If it's weak or reused, an attacker can walk right in — and once they're in a company account, they can reach data, email coworkers pretending to be you, or cause real damage. The good news is that strong login habits are easy once you know them.

🔑 What makes a password strong

  • Long. Length matters most. A passphrase of several words — like PurpleCactusRiverStapler — is both strong and easier to remember than a short jumble.
  • Unique. Use a different password for every account. If you reuse one and any single site is breached, every account with that password is suddenly at risk.
  • Not guessable. Avoid your name, birthday, "password," "123456," or "Password123." These are the first things attackers try.
  • Not shared. Never share your work password — not with a coworker, and never in reply to an email or phone call. Real IT departments don't ask for your password.

You might be thinking, "How am I supposed to remember a different long password for every account?" You don't have to — that's what a password manager is for.

🗝️ Password managers

A password manager is a secure app that creates strong, unique passwords for you and remembers them all. You memorize just one strong master password (or unlock it with your fingerprint or face), and it fills in the rest automatically. Many workplaces provide one; popular options you may hear of include Bitwarden, 1Password, and the password features built into your browser or phone. Ask your employer whether they have a preferred tool — using it is a mark of a careful employee.

📱 Multi-factor authentication (MFA / 2FA)

Even a great password can sometimes be stolen. That's why workplaces add a second step called multi-factor authentication (MFA), also known as two-factor authentication (2FA). It means proving who you are with two things: something you know (your password) plus something you have (usually your phone).

In practice, after you type your password, the system asks for a second proof — for example:

  • A one-time code texted to your phone or shown in an app (like Microsoft Authenticator, Google Authenticator, or Duo).
  • A "Was this you?" tap that pops up on your phone for you to approve.
  • A physical security key or your fingerprint/face.

MFA is powerful because even if a thief steals your password, they still can't get in without also having your phone. It takes just a few extra seconds and blocks the vast majority of account break-ins. If your workplace offers or requires MFA, turn it on and keep it on — it's one of the best protections there is.

✅ Habit: one strong, unique password per account — plus MFA

Build two habits and you're ahead of most people: (1) make every password long and unique, letting a password manager create and remember them, and (2) turn on MFA wherever it's offered, especially for work email and company systems. Together, these two habits stop the overwhelming majority of account attacks — a small effort for a big, lasting payoff.

Spotting Phishing & Scams at Work

Phishing is when someone sends a fake email, text, or link pretending to be a real person or company — your bank, your boss, IT, a delivery service — to trick you into giving up a password, clicking a harmful link, or sending money or gift cards. It's the most common way workplaces get attacked, precisely because it targets people, not machines. Learning to spot it is one of the most valuable safety skills you can have.

🚩 Common red flags

  • Urgency and pressure. "Act now or your account will be closed!" Scammers rush you so you won't stop to think.
  • An odd or mismatched sender. The name says "IT Support," but the actual email address is a random string or a misspelled company name. Always check the real address, not just the display name.
  • Links that don't match. The text says one thing, but hovering over the link shows a different, strange web address. Don't click — inspect first.
  • Requests for secrets or money. Asking for your password, a verification code, gift cards, or a wire transfer. Legitimate employers and IT never ask for your password.
  • Unexpected attachments or messages you weren't expecting at all, especially ones that want you to "enable" something or sign in.
  • Odd wording. Awkward grammar, generic greetings ("Dear User"), or a tone that doesn't sound like the real person.

When something feels off, walk through a simple safety check before you act. Here's the flow to follow:

graph TD
    A["You get a message with a link or request"] --> B{"Were you expecting it?"}
    B -->|"Yes, expected"| C["Check the sender's real email address"]
    B -->|"No, unexpected"| D["Be cautious — slow down"]
    D --> C
    C --> E{"Does the address look right?"}
    E -->|"Looks wrong or odd"| H["Do NOT click"]
    E -->|"Looks okay"| F["Hover over links to inspect the real address"]
    F --> G{"Pressure, or asks for password / money?"}
    G -->|"Yes"| H
    G -->|"No, seems safe"| I["Proceed carefully"]
    H --> J["Report to IT & verify another way"]

The two most important steps in that flow: never click when something feels suspicious, and verify through a separate channel. If an email claims to be from your boss asking for gift cards, don't reply to the email — call or message your boss directly using a number you already trust. If it claims to be IT, contact IT through your normal help channel, not the email's links or phone number.

⚠️ When in doubt, don't click — report it

Almost every workplace has a rule: if a message looks suspicious, report it to IT (many email systems have a "Report phishing" button, or you forward it to a security address). You will never get in trouble for reporting a message that turns out to be fine — but clicking a real phishing link can expose the whole company. Reporting is exactly what a careful, professional employee does. And if you clicked something before you realized — tell IT right away; fast reporting limits the damage, and it's far better than staying quiet.

Protecting Data & Privacy at Work

Beyond passwords and phishing, a big part of working safely online is protecting the information you handle — your company's data and, often, your customers' private details. Much of this is just common-sense care, done consistently.

  • Guard company and customer data. Don't share confidential information, send it to personal accounts, or copy it onto random USB drives. Treat customers' details (names, addresses, payment info, health info) as private — handle only what your job requires.
  • Lock your screen when you step away. A quick Windows key + L (Windows) or Ctrl+Cmd+Q (Mac) locks the computer so no one can use your open accounts while you're gone. Make it a reflex whenever you leave your desk.
  • Be careful on public Wi-Fi. Free Wi-Fi at a café or airport can be watched by others. Avoid signing in to work accounts on it unless you're using a company VPN (a secure, private connection your employer may provide).
  • Don't install unknown software. Only install programs your employer approves. Random downloads and "free" tools can hide malware. If you need software, ask IT.
  • Follow the acceptable-use / IT policy. Most workplaces have a written policy on how to use company computers, email, and the internet. Read it, and when unsure, ask. Following it protects you as much as the company.

None of this requires technical expertise — it's about steady, respectful care with information that isn't only yours. Employers trust people who handle data carefully, and that trust opens doors.

✅ Habit: lock your screen and ask before installing

Two tiny habits carry a lot of weight: lock your screen every time you step away (Windows key + L, or Ctrl+Cmd+Q on Mac), and never install software or share company data without checking your IT policy first. They cost you seconds, they protect real people's information, and they mark you as an employee who can be trusted with responsibility.

Practice & Project

🏋️ Exercise 1: Strong or weak password?

Goal: Recognize what makes a password strong, and why.

Look at these three passwords. Which is strongest, which is weakest, and why?

  1. Password123
  2. Maria1985 (Maria's name and birth year)
  3. BreezyLanternMapleThicket (used only for one account)
✅ Answer

Strongest: #3 (BreezyLanternMapleThicket) — it's long, made of several words, hard to guess, and unique to one account. Weakest: #1 (Password123) — it's short, extremely common, and one of the first things attackers try. #2 is also weak because it uses a real name and birth year, which are easy to find or guess. The lesson: make passwords long, unique, and not based on personal info — and never reuse one across accounts.

🏋️ Exercise 2: Spot the phishing signs

Goal: Identify red flags and choose the safe action.

You get this email at work: "URGENT: Your account will be locked in 1 hour! Verify your password now." The sender's name says "IT Help Desk," but the actual address is it-support@secure-login-verify.co. There's a button that says "Verify Account," but hovering over it shows a strange, unrelated web address. What red flags do you see, and what should you do?

✅ Answer

Red flags: (1) Urgency/pressure ("URGENT... 1 hour"); (2) an odd sender address that isn't your real company or IT domain; (3) a link mismatch — the button text and the real web address don't match; (4) it asks for your password, which real IT never does. What to do: Do NOT click the link or enter anything. Report it to IT (use the "Report phishing" button or forward it to your security contact), and if you're unsure, verify through a channel you trust — contact IT directly using your normal help line. This is textbook phishing.

🎯 Your Project: My Online Safety at Work

Add a new page to your "My Workplace Digital Toolkit" folder that captures your personal plan for staying safe online at work. Do it on paper or, better, as a document you save into your toolkit folder from Lesson 1.1.

  1. (2 min) Title the page "My Online Safety at Work" and add today's date.
  2. (6 min) Write your password + MFA plan: how you'll make passwords long and unique, whether you'll use a password manager (and which, if your employer has one), and where you'll turn on MFA (start with work email).
  3. (6 min) List 3 phishing red flags in your own words (for example: urgency, odd sender address, link mismatch, asks for password or money), and write the action: don't click, and report it to IT / verify another way.
  4. (4 min) Add two data-protection habits you'll practice: lock my screen when I step away, and ask IT before installing software or sharing company data.
  5. (4 min) Practice for real: open a browser, search for one work-relevant thing using specific keywords, and bookmark a reputable page (like an official .gov or a software help site).
  6. (3 min) Save and date the page, and keep it in your toolkit folder.

✅ Project Completion Checklist

  • ☐ I created and dated my "My Online Safety at Work" page
  • ☐ I wrote my strong-password + MFA plan
  • ☐ I listed 3 phishing red flags and what to do (report to IT)
  • ☐ I noted two data-protection habits (lock screen; ask before installing)
  • ☐ I searched with specific keywords and bookmarked a reputable page

👥 Working with a tutor or group?

Practice spotting phishing together — it's genuinely fun in a group. One person reads a suspicious email aloud (make some up, or use safe examples your tutor provides) while others call out the red flags and decide: click, delete, or report? Compare the browsers you each use (Chrome, Edge, Safari, Firefox) and notice how the buttons differ but the ideas are the same. If a workplace uses MFA, someone who's set it up can describe the "code on your phone" step so it feels familiar. Keep it warm and judgment-free — everyone has almost clicked something once, and talking about it openly is exactly how teams stay safe.

🎯 Quick Quiz

Question 1: What is multi-factor authentication (MFA)?

Question 2: An unexpected work email urgently asks for your password through a link. What should you do?

Tips & Common Mix-Ups

✅ Do's

  • Search with specific keywords. The clearer your words, the better and faster the results.
  • Prefer official, reputable sources. Government .gov sites and the software maker's own help pages are reliable.
  • Use long, unique passwords. A passphrase and a password manager beat memorizing jumbles.
  • Turn on MFA. The second step blocks most account break-ins — especially for work email.
  • Report suspicious messages to IT. When in doubt, don't click; verify another way.
  • Lock your screen and follow the IT policy. Small habits protect real people's data.

❌ Common Mix-Ups

⚠️ Watch Out

  • Reusing one password everywhere. One breach then exposes every account — make each one unique.
  • Trusting the sender's display name. Check the real email address, not just the name shown.
  • Clicking under pressure. Urgency is a scam tactic; slow down and inspect links first.
  • Sharing a password or code. Real IT never asks for it; never give it out, even to a "helpful" caller.
  • Signing in to work on public Wi-Fi. Avoid it unless you're on a company VPN.
  • Installing random software. Ask IT first; "free" tools can hide malware.

✅ Affirmation

You just learned to use the internet the way careful professionals do — searching smartly, protecting your accounts with strong passwords and MFA, spotting scams, and guarding data. These are exactly the habits employers trust. You're not "bad with technology" or "an easy target"; you're someone who knows how to work safely online, and that makes you an asset to any team. Well done. 🔒

📓 Learning Journal

Keep a learning journal — a notebook, or a note on your phone or computer. After every lesson, take five minutes to write down:

  • What you learned — a skill or a new word
  • What clicked for you
  • What's still unclear, so you know what to revisit
  • Where you'll use it at work or in a job search
  • How you feel about your progress

✍️ This lesson's prompt: Have you ever received a message that felt like a scam — at work or in life? What tipped you off, or what do you know now that you'd watch for? Which one safety habit from this lesson (a stronger password, turning on MFA, locking your screen, reporting phishing) will you start this week, and why does it matter to you? Write a few sentences. Noticing your own instincts is a big part of staying safe.

📝 Lesson Summary

🎓 Key Takeaways

  • A browser (Chrome, Edge, Safari, Firefox) uses tabs, the address bar, and bookmarks; search smartly with specific keywords and prefer official, reputable sources.
  • Strong passwords are long, unique, and not guessable; a password manager creates and remembers them so you don't have to reuse any.
  • Multi-factor authentication (MFA/2FA) adds a second step — usually a code from your phone or app — so a stolen password alone can't get anyone in.
  • Phishing uses fake, urgent messages to steal logins or money; watch for urgency, odd senders, link mismatches, and requests for passwords or gift cards — don't click, and report to IT.
  • Protect data and privacy: guard company/customer information, lock your screen, be careful on public Wi-Fi, don't install unknown software, and follow the IT policy.

🎉 What You've Accomplished

You've built the online-safety foundation that every modern job depends on: you can browse and search effectively, build strong login habits with passwords and MFA, spot and report phishing, and handle company data with care. You also added a "My Online Safety at Work" page to your toolkit — a plan you can actually use starting today. That's a genuinely valuable, employer-trusted skill set. 🎉

❓ Common Questions at This Stage

I can't remember all these different passwords. What do I do?

That's exactly what a password manager is for. It creates strong, unique passwords and remembers them all, so you only memorize one master password (or unlock with your fingerprint/face). Many employers provide one; if yours does, ask IT how to set it up. Until then, a long passphrase of a few random words is far easier to remember than a short jumble — and much stronger.

I think I clicked a phishing link. Am I in trouble?

No — and speed matters more than blame. Tell IT right away (or your manager if there's no IT). Fast reporting lets them limit any damage, change passwords, and check your account. Everyone has almost clicked something; what protects the company is reporting quickly and honestly. You won't get in trouble for reporting — that's the responsible thing to do.

Is MFA the same as a password manager?

No, they're different (and best used together). A password manager stores and creates your passwords. MFA is the extra sign-in step — a code from your phone or app — that proves it's you after you enter your password. One organizes your keys; the other adds a second lock. Using both gives you strong protection.

Is this the Northstar certification?

No — this course builds the Northstar-aligned skills, and the official Northstar Digital Literacy assessment and certificate are earned separately at sponsoring sites (many libraries and programs offer them free). Working through this course is great preparation; when you're ready, ask a local library or adult-education program about taking the assessment.

🎯 Standards Alignment (for programs & tutors)

This lesson aligns to Northstar Digital Literacy — Essential Computer Skills and Using the Internet (web browsers, searching, and evaluating online information; online safety, strong passwords, and privacy) — and supports WIOA Title II digital-literacy workforce preparation, CCRS reading of informational/technical text, and NRS ABE/ASE functioning-level work toward Measurable Skill Gains. It continues the "My Workplace Digital Toolkit" portfolio thread and complements the Workforce Readiness and Career Exploration & Pathways courses. This course builds the skills; the official Northstar assessment/certificate is earned separately at sponsoring sites. Web browsers and security tools vary by version. Confirm current specifics with NDE/CRAELO.

🔭 Looking Ahead

With computers, email, and safe internet habits behind you, you're ready to start creating. In Lesson 2.1: Word Processing, you'll open a word processor (like Microsoft Word or Google Docs), type and format a document, and produce clean, professional-looking work — the kind of documents nearly every job asks for. It's hands-on and satisfying, and you already have the file-saving skills it builds on.

✅ Before the Next Lesson

  • Finish your "My Online Safety at Work" toolkit page and keep it with your folder.
  • Turn on MFA for at least one important account (start with your email) if you haven't yet.
  • Practice: search for one thing with specific keywords and bookmark a reputable page.
  • Write your Learning Journal entry for this lesson.
  • Optional: skim your workplace's IT / acceptable-use policy, or note to ask about it on your first day.

🌟 Encouragement for the Journey

Working safely online is one of the most respected skills an employee can have — and today you built it. You can find what you need on the web, protect your accounts, and see through the tricks scammers rely on. That's real confidence, and it protects both you and the people who count on you. Keep those habits, keep exploring, and I'll see you in Lesson 2.1! 👋