Skip to main content

IT Start

The real risks of the internet, and what actually stops them

Hands connecting cable in server room

The risks of the internet fall into four buckets: content you’re exposed to, contact from people who mean harm, conduct that causes damage (yours or someone else’s), and contract or commercial risks like scams and data theft. Underneath all four sits a mess of cyberbullying, grooming, phishing, ransomware, privacy breaches, and misinformation that most families and small businesses only think about after something goes wrong.

Three things cut the odds of harm more than anything else, and none of them cost money:

  • Turn on automatic updates on every device tonight
  • Switch on multi-factor authentication (MFA) for email, banking, and social accounts
  • Check your backups actually restore, not just that a job “completed”

Almost three in four Australian children aged 10 to 15 have seen or heard content associated with harm online, and 53% have experienced cyberbullying. That single stat should tell you enough: this isn’t a fringe problem you can ignore until it happens to your kid or your business. Updates close the holes attackers use, MFA stops stolen passwords from being enough on their own, and a real backup is the difference between a bad afternoon and a business that doesn’t reopen.

Key Takeaways

The biggest reduction in internet risk comes from three unglamorous habits: automatic updates, MFA everywhere, and backups you’ve actually tested.

Point Details
Four risk categories Content, contact, conduct, and contract cover almost every online harm you’ll encounter.
Cyberbullying is common 53% of Australian children aged 10 to 15 have experienced cyberbullying, per eSafety research.
Never pay ransomware demands The ACSC advises against paying, since it doesn’t guarantee recovery and can invite repeat attacks.
Backups need testing A synced folder is not a backup; only an offsite, versioned, tested restore counts.
Conversation beats filters Open, non-punitive talks with kids catch grooming and bullying that blocking software misses.

Table of Contents

Understanding the risks of the internet: content, contact, conduct, contract

Security researchers group online harm into four categories, and once you know them you’ll spot risks faster than any filter can catch them.

  1. Content risk is exposure to material that’s harmful, illegal, or age-inappropriate: violent videos, extremist propaganda, self-harm content, or pornography reaching a child’s feed uninvited.
  2. Contact risk involves another person initiating harmful interaction: grooming, harassment, unwanted solicitation, or a scammer pretending to be your bank.
  3. Conduct risk is about behaviour, either the child’s own or someone else’s, such as sending explicit images, bullying a classmate, or oversharing location data.
  4. Contract risk covers the commercial side: exploitative terms of service, data harvesting, in-app purchases aimed at kids, or being locked into a scam subscription.

Then there are cross-cutting risks that don’t sit neatly in one box. Algorithmic amplification pushes engaging content (often the most extreme version) to the top of a feed regardless of category. Addictive design features and “sticky” game mechanics keep users glued to platforms longer than they intend, which multiplies exposure to every other risk. Privacy erosion, where data quietly accumulates across apps, sits underneath the lot. Knowing which bucket a problem falls into tells you who to talk to and what setting to check first.

The most common online threats and how to spot them

Cyberbullying

Cyberbullying is repeated, deliberate harm delivered through messages, comments, or exclusion online, and the single biggest mitigation is early, calm conversation, not confiscating the device. Among Australian children aged 10 to 15, 53% have experienced cyberbullying and 60% have seen online hate directed at others.

Warning signs to watch for:

  • Sudden reluctance to use a phone or laptop they used to enjoy
  • Mood changes right after checking notifications
  • Deleting apps or accounts abruptly
  • Reluctance to say who they’re talking to online

Grooming and image-based abuse

Online grooming follows a pattern: a stranger builds trust through friendly, non-sexual contact first, then isolates the child into private chats, pushes for secrecy, and asks rapid personal questions before attempting to meet or requesting images. eSafety documents these tactics clearly and recommends talking early and adjusting supervision as children get older, rather than waiting for a crisis.

Child's bedroom with digital safety setup

Some estimates suggest roughly 1 in 6 children have been sexually groomed online, and around 1 in 13 children under 18 have experienced non-consensual image-based abuse, with victims facing a higher risk of long-term mental health impacts. Sextortion, where an offender threatens to release images unless paid or given more content, often escalates fast once a child feels trapped by shame. The fix isn’t blocking every app. Pro Tip: Focus on making it safe for your child to tell you something felt weird, even if they think they caused it. Filters miss contact risk; open conversation catches it.

Scams, phishing, and quishing

Phishing remains the top vector for account takeover, and attackers now use QR codes (“quishing”) on parking signs and fake invoices to bypass email filters entirely, as explained in detail on the Phishing | Total Cyber Solutions site. The common tactics include impersonating a bank, urgent deadline language, and fake login pages nearly identical to the real one. Business email compromise (BEC) targets companies specifically: an attacker mimics a supplier or the CEO and asks finance to change bank details on an invoice. We’ve seen this play out at real businesses, where a bookkeeper pays a “updated” invoice without a phone call to confirm, and the money is gone within the hour.

Watch for: unexpected urgency, requests to bypass normal approval steps, slightly wrong email domains, and QR codes appearing somewhere they’ve never been before.

Generic parking sign with QR code

Malware and ransomware

Ransomware encrypts files or threatens to leak stolen data unless you pay. The ACSC’s Annual Cyber Threat Report recorded rising ransomware reports, and small businesses absorb real financial losses from these attacks. Here’s the bit most guides skip: paying rarely fixes anything. The ACSC is explicit that payment doesn’t guarantee file recovery and can mark you as a soft target for a second attack.

Privacy breaches, misinformation, and mental health

Data breaches expose passwords and personal details that get resold and reused elsewhere, which is why password reuse is such a liability. Misinformation and deepfakes now spread through the same feeds that recommend cat videos, and the algorithm doesn’t care which one keeps you scrolling. Heavy or compulsive use has been linked to anxiety, sleep disruption, and in some cases exposure to self-harm content pushed by recommendation systems that optimise for engagement, not wellbeing.

Practical safety measures that actually reduce your risk

Software updates, MFA, working backups, sane privacy settings, and honest supervision do more heavy lifting than any single app or filter you could buy.

Device and account checklist:

  1. Turn on automatic updates for every phone, laptop, and router
  2. Enable MFA on email, banking, and social accounts, not just the ones that nag you
  3. Use unique passphrases, not variations of the same password
  4. Check recovery email and phone numbers are current, not an old inbox nobody checks
  5. Retire devices past their vendor’s end-of-support date

Behaviourally, the habit that matters most is pausing before clicking. Verify unexpected requests by phone, not by replying to the same email or message that raised the alarm.

Parental controls, done realistically:

  • Set device-free zones (dinner table, bedroom overnight)
  • Use platform parental tools as a floor, not a ceiling; they don’t replace conversation
  • Give freedoms gradually as trust and age increase, rather than an all-or-nothing lockdown
  • Check in on gaming and messaging apps specifically; they’re where contact risk concentrates

Honestly, we see this a lot with small businesses too: owners assume their cloud sync counts as a backup. It doesn’t, not if ransomware can reach and encrypt that synced folder along with everything else. A real backup is offsite, versioned, and immutable so nothing can overwrite or encrypt it.

For SMBs, the Essential Eight at maturity level one is a sane baseline: patch fast, restrict admin rights, segment your network so one compromised laptop doesn’t take down the whole file server, and audit who actually needs admin access (usually far fewer people than have it).

Pro Tip: If you can’t remember the last time someone actually tried restoring a file from your backup, you don’t have a backup strategy. You have a hope.

What to do if something’s already gone wrong

Preserve the evidence first, report it second, and get support third. Don’t skip straight to deleting the offending message out of embarrassment or anger.

  1. Screenshot everything: messages, profiles, timestamps
  2. Don’t delete the account or message unless a platform or police officer tells you to
  3. Change passwords on the affected account and any account using the same password
  4. Isolate compromised devices from your network before doing anything else
  5. Report to the platform directly using its in-app reporting tool

Where to report:

  • eSafety Commissioner: cyberbullying, image-based abuse, and online harm involving Australians
  • Local police: threats, grooming, extortion, or anything involving a minor
  • Your bank: immediately, if money or card details were involved
  • cyber.gov.au: for businesses reporting a cyber incident

Support doesn’t have to wait until the report is filed. Kids Helpline, Lifeline, and 1800RESPECT all take calls about online harm, and confidentiality is standard practice unless there’s an immediate safety risk. Don’t wait for the “right” moment to talk to someone; the right moment is now, while details are fresh and evidence is intact.

Talking to kids about online safety without shutting them out

Open, non-punitive conversation paired with practical rules works better than either strict monitoring or hands-off trust alone.

For kids under 8, keep it simple: “Some people online pretend to be someone else, so we only talk to people we know in real life.” For 9 to 12 year olds, talk specifically about private chats and secrecy: “If someone asks you to keep a conversation secret from me, that’s a warning sign, not a rule you’re breaking by telling me.” With teens, drop the lecture tone and ask questions instead: “Has anyone online ever made you feel weird or pressured? What happened?”

Age-based checklist:

  • Under 8: devices used in shared spaces only, no private messaging apps
  • 9 to 12: supervised social accounts, location sharing off by default
  • Teens: privacy settings reviewed together, not imposed unilaterally

One thing eSafety’s own guidance stresses: parents who lean entirely on blocking sites miss the bigger risk, which is contact, not content. Pro Tip: Check your own parental control app’s login history occasionally. We’ve seen more than one parent shocked to find a “locked” account had been accessed from a device they didn’t recognise, because nobody ever changed the default password.

What we see in small businesses, and why it keeps happening

Most small businesses get breached because they skip the boring basics, not because attackers are especially clever. No MFA, backups that don’t actually restore, and admin accounts everyone shares because “it’s easier.” That’s the pattern, over and over.

We’ve walked into businesses where the previous IT setup had one shared admin password used by six people, written on a sticky note near the server. We’ve seen “backups” that were really just a synced folder, so when ransomware hit, the encrypted files synced straight to the “backup” too. We’ve seen invoices paid to a scammer’s account because nobody picked up the phone to confirm a bank detail change. None of these are exotic attacks. They’re gaps anyone could have closed in an afternoon.

Quick wins worth actioning this week:

  • Enable MFA on every account with financial or admin access
  • Audit who actually has admin rights, and strip it from anyone who doesn’t need it daily
  • Confirm your backup is offsite, versioned, and tested with an actual restore
  • Patch and update every device, especially anything past its vendor support date
  • Segment your network so one infected laptop can’t reach your whole file server

If you’re not sure whether you’ve got the basics covered, ask your IT provider three questions: when was the last successful restore test, who has admin access and why, and is MFA enforced everywhere or just on paper. If they can’t answer clearly, that’s your answer. IT Start covers cybersecurity best practices for small businesses in more depth if you want to check your own setup against it.

Pro Tip: Ask to see a restore, not a backup report. A green tick on a dashboard means the job ran. It doesn’t mean the file is recoverable.

A note from Matt

I’ve spent years watching businesses discover their gaps the hard way, usually the week after they decided MFA was “on the to-do list.” The pattern never changes: the fix is cheap, the breach is not.

IT Start, managed IT and cybersecurity for Brisbane SMBs, SMB 1001 Gold certified.

Sources

This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.

FAQ

What are the main risks of the internet?

The main risks fall into four categories: content (harmful material), contact (grooming, harassment), conduct (bullying, oversharing), and contract (scams, exploitative data practices), with cyberbullying and phishing among the most common.

What are 10 common internet threats?

Cyberbullying, grooming, sextortion, phishing, quishing, business email compromise, ransomware, malware, data breaches, and misinformation or deepfakes all rank among the most frequent threats users face.

What are the safety rules everyone should follow online?

Turn on automatic updates, enable MFA everywhere, use unique passphrases, verify unexpected requests by phone, back up data offsite, review privacy settings regularly, and talk openly with kids about odd online interactions.

What are the disadvantages of using the internet?

Beyond convenience, the internet exposes users to scams, privacy erosion, addictive design features, misinformation, and, for children particularly, grooming and cyberbullying risks that outpace many parents’ awareness.

Why shouldn’t a business pay a ransomware demand?

Paying doesn’t guarantee file recovery and can mark a business as a repeat target, which is why the ACSC recommends against payment as standard incident response.

Related Posts