← all articles

How to secure a family member's devices without becoming IT support

If you are the person in the family who “knows computers”, you already know the pattern. A phone call comes in on a Sunday night. The laptop is slow, or a pop-up says the machine is infected, or someone got a text from “the bank”. You fix it, feel good for a day, and then it happens again. I have done this for my own parents for years, and the fixing was never the real problem. The real problem was that every device depended on me being awake and available.

This tutorial is for anyone supporting a parent, grandparent, aunt or in-law who is not going to learn security as a hobby. The goal is not to make them an expert. The goal is a one-time setup session of about two to three hours, after which the devices update themselves, back themselves up, resist the most common scams, and can be recovered without you sitting next to them. After that your job drops to a short check-in every few months.

I write this as a Singapore-based operator who manages a lot of infrastructure, and the same rule applies here as anywhere: automate the boring parts, remove single points of failure, and write down where the keys are.

what you need

  • physical access to their phone(s) and laptop for one session, plus their Apple ID or Google account login (they should be present and agree to this)
  • a password manager with a family plan: Bitwarden Families is around US$40 a year for up to six people at the time of writing, 1Password Families is more expensive but polished. check the current pricing page before you buy
  • an external drive or a cloud backup plan: a 1TB USB drive is roughly S$70 to S$100 in Singapore, or Apple iCloud+ and Google One plans start at a couple of dollars a month
  • a second phone number or email you control, used as their account recovery contact
  • one printed sheet of paper and a pen, for the emergency page in step 8
  • about two to three hours, ideally with tea and no rush

You do not need to buy security software subscriptions. The built-in tools on iOS, Android, Windows and macOS cover most of what matters if they are switched on.

step by step

1. take inventory before you touch anything

Write down every device and every account that matters: phones, laptop, tablet, email, banking, SingPass or your local government login, Apple ID or Google account, WhatsApp. Ask them which accounts they would panic about losing. Their answer is your priority list.

Expected output: a short list, usually 8 to 15 items, with the email account at the top. Email is the master key, because every password reset flows through it.

If it breaks: if they cannot remember which email they used for what, open the browser’s saved passwords page and read the usernames. That usually reveals the whole picture in five minutes.

2. fix the email account first

Open their main email account and do three things: set a long unique password, turn on two-step verification, and add your contact as the recovery option. For two-step, prefer passkeys or the phone’s prompt over SMS codes where the account supports it. CISA’s Secure Our World guidance explains why multi-factor authentication matters and is written for non-technical people, so it is a good page to send them afterwards.

Expected output: signing in on a fresh browser now asks for a second confirmation on their phone.

If it breaks: if they get locked out mid-setup, do not keep guessing. Use the provider’s recovery flow with the old phone in hand, and take your time. Repeated failed attempts can lengthen lockouts.

3. install a password manager and move the important logins

Install Bitwarden or 1Password on their phone and laptop, create the vault with a master passphrase they can actually remember (four or five unrelated words), and save the ten accounts from your inventory. Turn on autofill so they never have to type a password. Then set up the family plan so you can use emergency access. Bitwarden documents how this works in its emergency access help page, and it lets a trusted person request vault access after a waiting period you choose.

Expected output: they open their bank site, the manager offers the login, one tap, done.

If it breaks: if autofill does not appear on the phone, go to the system settings and set the password manager as the autofill provider (Settings > Passwords on iPhone, Settings > Passwords and accounts on Android). Most “it doesn’t work” cases are this.

4. turn on automatic updates everywhere

Unpatched software is the boring reason most family devices get compromised. Turn on automatic updates for the operating system, the browser and apps. On the laptop, check what is pending.

# Windows: list and apply pending app updates
winget upgrade
winget upgrade --all
# macOS: see pending system updates
softwareupdate --list

Expected output: the list is either empty or shows a handful of items that install cleanly. On phones, set the update option to automatic and let it run overnight on wifi.

If it breaks: if the laptop is too old to receive updates (Windows 10 support ended in October 2025 for most users, and older Macs age out too), tell them honestly. A device that cannot be patched should not hold banking logins. A used or entry-level replacement is cheaper than a compromised bank account.

5. encrypt the disks and set a real screen lock

If a phone or laptop is lost, encryption is what keeps their photos and saved sessions private. Modern phones encrypt by default once a passcode is set, so make sure the passcode is six digits or more, not 1234. On the laptop, check.

# Windows (run as administrator)
manage-bde -status C:
# macOS
fdesetup status

Expected output: “Protection On” on Windows, or “FileVault is On” on macOS. My Windows laptop lockdown guide covers the rest of the settings if you want to go further.

If it breaks: Windows Home sometimes shows device encryption in Settings > Privacy & security instead of BitLocker. Turn it on there and save the recovery key to their Microsoft account and to the printed sheet in step 8.

6. set up backups they never have to think about

Pick one automatic backup and test it. For phones, that is iCloud Backup or Google One backup with photos syncing. For the laptop, use File History on Windows or Time Machine on macOS pointed at the USB drive, and keep the drive plugged in or at least easy to plug in.

Expected output: a backup timestamp from within the last 24 hours in the settings screen. Then actually restore one photo or file to prove it works. An untested backup is just hope.

If it breaks: the most common failure is a full drive or a full iCloud quota. Check storage, and if their photos are eating 50GB, pay for the next tier rather than deleting memories.

7. add scam guardrails, because this is where the real losses happen

Devices are rarely broken into by clever hacking. They are talked into it. Set up the guardrails that fit how scams actually work:

  • install the ScamShield app if they are in Singapore, which is run by the government and filters scam calls and SMS. details are on scamshield.gov.sg
  • turn on “silence unknown callers” on iPhone or “spam protection” on Android
  • set bank transfer limits low in the banking app, and raise them only when needed
  • agree on a family rule: anyone who asks for money or codes by phone gets hung up on, and then called back on a number they already have

Also walk them through one real example. I wrote up what recovery looks like after it goes wrong in helping a parent recover from a scam call, and reading it once helps you explain the rule without lecturing.

Expected output: an unknown number rings and is silenced or flagged, and they know the callback rule.

If it breaks: if they keep overriding the filters because a real call got blocked, add the few numbers they expect (clinic, school, delivery) to contacts instead of disabling the protection.

8. write the emergency page and hand over the keys

On one sheet of paper, write: the password manager master passphrase, the device passcodes, the location of the backup drive, and your phone number. Put it somewhere safe at home, like with important documents, not taped to the laptop. Keep a copy of the recovery contact information on your side in your own vault.

Expected output: they can find the page, and you can get in if they cannot.

If it breaks: if they resist writing a master passphrase on paper, explain that a locked drawer at home is a better place for it than their memory alone. The threat is remote strangers, not a family member walking past the drawer.

common pitfalls

  • doing everything on their behalf and leaving. if they never touch the password manager during setup, they will not use it. make them tap through one login themselves.
  • using the same recovery email as the account it protects. if the recovery address is the account itself, it recovers nothing.
  • installing five security apps. more apps means more pop-ups and more confusion. the built-in protections plus a password manager beat a pile of trial software.
  • skipping the browser. a hijacked extension can read everything they type, so remove anything they do not recognise. see what browser extensions can see for what to look for.
  • never testing the recovery path. you find out the backup or the emergency access does not work at the worst possible moment.

scaling this

This method works for one household. What changes as you take on more people:

  • from 1 to 10 people (extended family, a few neighbours): the family plan on a password manager stops covering everyone, and the work becomes scheduling. I batch setups into a single afternoon and keep a simple checklist so nothing is missed. I would also stop being the recovery contact for everyone and spread that across two or three trusted relatives.
  • from 10 to 100 people (a community group, a small office, a church or a volunteer organisation): move to a business password manager plan, use a shared inventory sheet, and hold group workshops instead of one-to-one sessions. Standardise on one phone platform and one laptop configuration where you can. Scripts like the winget and fdesetup checks above can be run as a monthly audit.
  • from 100 to 1000 (a company or a large organisation): this is no longer a favour, it is IT. You need device management, written policies, a paid support process and a proper security owner. Do not try to do it from your phone on weekends. If you are curious how teams use AI helpers for documentation and helpdesk triage at that scale, AI Tool Gazette covers the tooling side.

The honest lesson from the small scale is that the process matters more than the tools. Document it once and the next family member takes half the time.

where to go next

If you want to keep going after the basics, these are the follow-ups I would read in order:

You can also browse everything else on the blog index.

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-09-29.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →