Accessible Learning Center manual

Cybersecurity for Screen Reader Users Manual

Safer accounts, devices, browsing, and communication

Independent Self-Study Guide

First-time keyboard guide

Use this short routine before following the Cybersecurity for Screen Reader Users Manual procedures. It explains exactly how the keyboard directions in this manual work.

Press a single key

  1. Find the named key without pressing it if possible.
  2. Press and release the key one time. Do not hold it unless the step specifically says to hold it.
  3. Stop and listen to the full screen-reader announcement before pressing another key.

Press a keyboard combination

  1. When a command contains a plus sign, such as Ctrl+S, hold down the first key.
  2. While continuing to hold the first key, press and release the final key once.
  3. Release the first key. The plus sign is not a key and should not be pressed.
  4. Listen for the expected result described in the procedure. If nothing changes, verify that the correct application or webpage has focus and try the command once more.

Press a sequence of keys

  1. When keys are separated by commas or the word “then,” press and release them in order instead of holding them together.
  2. After each key, listen for a menu, tab, control, or new screen before continuing.
  3. If the announcement does not match the step, press Escape once to close the current menu or dialog and restart that procedure.

Know which navigation key to try

Verify before moving on

  1. Listen for the window, page, or application name so you know where focus is.
  2. Perform only one numbered step.
  3. Compare what the screen reader announces with the “What should happen” information in the procedure.
  4. If the result is wrong, stop. Use the procedure’s recovery directions, Escape to cancel, or Ctrl+Z to undo when that command is supported.
  5. Continue only after you can identify the result. Save completed work with Ctrl+S whenever the application supports saving.

First complete independent workflow

This rehearsal joins existing procedures into one uninterrupted session without repeating their directions. Follow the linked procedure when a step names it, then return here for the next verification.

Safety check: Confirm the active application, document or project name, and save location before changing content.

  1. Open Cybersecurity for Screen Reader Users Manual and wait until its name, starting screen, or connected-device status is announced.
  2. Choose a fictional, public, disposable, or instructor-provided practice item. Do not use private client, student, medical, financial, or account-recovery information.
  3. Open 3.1 Verify an Email Sender. Read its “What you will learn,” “Before you begin,” keyboard-command, and expected-result information before pressing anything.
  4. Complete that procedure one numbered action at a time. After each key, stop and identify what changed before continuing.
  5. State the result aloud or record it in a practice note. If it differs from “What should happen,” use that procedure’s recovery directions before advancing.
  6. Continue directly to 3.2 Verify a Caller or Text Sender without closing the application or device session. First confirm that focus, account, file, book, conversation, or project context is still correct.
  7. Complete the second procedure and verify the resulting name, state, location, permission, value, or content. Do not rely only on a success sound.
  8. Save or synchronize when the product supports it. Wait for the completed state before disconnecting a device, closing a browser, or switching accounts.
  9. Continue to 4.1 Inspect a Link Without Opening It. Use the exact command listed there; if the command varies by model or version, use Keyboard Help, the product’s shortcut list, or the linked official reference instead of guessing.
  10. Introduce one harmless recoverable error, such as opening the wrong menu or moving focus away. Press Escape once, identify the active window or device area, and return to the correct step.
  11. Review the finished practice item from its beginning. Confirm its title or filename, structure, content, destination, sharing state, and saved or synchronized status as applicable.
  12. Close and reopen the item or return to it from the product’s main screen. The workflow is complete only when you can locate it and verify the same result independently.

Success standard: Complete all three linked tasks, explain the commands used, recover from the practice error, and locate the finished result without another person directing the next key.

Purpose: This manual teaches practical cybersecurity to people who use screen readers, braille displays, keyboard navigation, or speech access. It assumes no technical security background.

Core approach: Security decisions should not depend on seeing color, logos, icons, hover previews, or visual layout. This guide teaches verification methods that work through accessible text, keyboard commands, screen-reader information, known apps, saved bookmarks, typed addresses, and trusted contact methods.

Safety principle: Urgency is not proof. A legitimate bank, employer, government agency, software company, or family member can be contacted independently. Never let a message force you to use only the contact method inside that same message.

How to Use This Manual

Part 1 - The Four Core Cybersecurity Habits

CISA's Secure Our World guidance centers on four simple habits. This manual expands them for screen-reader users.

Situation Safer action
Recognize and report phishing Do not engage with suspicious messages; verify independently and report/delete them.
Use strong, unique passwords Use a password manager; do not reuse a password across accounts.
Turn on MFA Use the strongest option offered; prefer phishing-resistant methods where available.
Install software updates Apply security updates promptly from official update mechanisms.

Password length: CISA's current consumer guidance recommends passwords of at least 16 characters, random and unique for each account, with a password manager to create and store them.

Part 2 - What Phishing Is

Phishing is an attempt to make you open a harmful attachment, visit a fake site, reveal information, approve a login, send money, or install software.

Screen-reader-specific warning: A link's spoken text can say one thing while its real destination is different. A sender display name can also be forged or misleading. Always verify the actual address/domain when the decision matters.

Part 3 - Accessible Sender Verification

3.1 Verify an Email Sender

What you will learn: Check the actual sender address instead of trusting the display name.

Before you begin: Do not reply yet.

Exactly how to do it

  1. Open the message without activating links or attachments.
  2. Move to the From/Sender field.
  3. Use your email program's message-details or sender-details command to read the full email address.
  4. Spell the domain character by character if necessary.
  5. Compare the domain with the organization's known official domain.
  6. If the message asks for action, leave the message and contact the organization using a known app, saved bookmark, statement/card number, or manually typed official website.

What should happen: You know the actual sender address and have verified the request independently.

If that does not happen: If your email client hides the full address, open message details/headers or use a different trusted client/device. Do not treat a display name as proof.

Practice: Inspect three legitimate messages and identify their full sender domains.

3.2 Verify a Caller or Text Sender

What you will learn: Do not trust Caller ID or the number in the message.

Before you begin: A call/text claims to be from an institution or person.

Exactly how to do it

  1. Do not provide credentials or money.
  2. End the call or stop replying.
  3. Find the contact through a trusted source you already possess.
  4. Call back using the trusted number, not the number supplied by the caller/message.
  5. For family emergencies, contact the person or another family member through a known number.

What should happen: You verify identity through a separate channel.

If that does not happen: Caller ID and message sender names/numbers can be spoofed.

Practice: Practice finding a bank or utility number from an official statement or app.

What you will learn: Determine the destination domain first.

Before you begin: Focus the link but do not activate it.

Exactly how to do it

  1. Listen to the visible link text.
  2. Use your screen reader's link-information command or the application's context menu where available.
  3. Press Shift+F10 on Windows to open the link context menu.
  4. Choose Copy link address when available instead of Open.
  5. Paste the copied address into a safe text editor such as Notepad.
  6. Read/spell the domain carefully.
  7. Cancel/delete the pasted text after inspection if it contains a personal token.

What should happen: You can examine the destination without visiting it.

If that does not happen: Some tracking links are long or obscured. If the message is asking you to sign in, skip the link entirely and reach the service through a known app/bookmark/typed address.

Practice: Inspect several trusted links and identify the domain.

Domain rule: Read the registered domain, not just words anywhere in the address. A name such as bank.example.com.evil-site.test is controlled by evil-site.test, not by 'bank.example.com'.

4.2 Use the Independent-Path Method

What you will learn: Avoid link analysis when a safer route exists.

Before you begin: A message says an account needs attention.

Exactly how to do it

  1. Close or leave the message.
  2. Open the institution's official app, your saved trusted bookmark, or type the known address yourself.
  3. Sign in normally.
  4. Check the account's alerts/messages/activity from inside the trusted service.
  5. If there is no matching alert, treat the original message as suspicious.

What should happen: You confirm the issue without trusting the message's link.

If that does not happen: If the organization is unfamiliar, search for its official website carefully and compare multiple trustworthy sources before entering credentials.

Practice: Verify a harmless account notification by independent path.

Part 5 - Suspicious Attachments and Downloads

5.1 Verify an Unexpected Attachment

What you will learn: Confirm purpose before opening.

Before you begin: An attachment arrived unexpectedly.

Exactly how to do it

  1. Read the sender's actual address.
  2. Read the attachment filename and file type.
  3. Do not open it.
  4. Contact the sender through a known separate method.
  5. Ask whether they intentionally sent that exact file.
  6. Open only after verification and only if the file type makes sense.

What should happen: You reduce the risk of opening malware sent from a spoofed or compromised account.

If that does not happen: If the sender cannot confirm it, delete/report the message and do not open the attachment.

Practice: Practice identifying filename extensions on safe files.

Part 6 - Passwords and Password Managers

6.1 Use a Password Manager Safely

What you will learn: Reduce memorization and password reuse.

Before you begin: Choose a reputable built-in or independent password manager.

Exactly how to do it

  1. Create or secure the manager account.
  2. Turn on MFA/passkey protection for the manager if offered.
  3. Let it generate a long random password for a test account.
  4. Save the login.
  5. Return to the site through a trusted path.
  6. Use autofill only when the password manager recognizes the correct site/domain.
  7. Review recovery options and store recovery codes securely.

What should happen: You no longer need to type/reuse the site's password manually.

If that does not happen: If autofill does not appear on a site you expect, stop and verify the domain before manually copying the password.

Practice: Create one unique generated password for a noncritical test account.

Useful security signal: A password manager refusing to autofill on a look-alike site can be a warning that the domain does not match the saved login.

Part 7 - MFA, Authenticator Apps, and Security Keys

MFA requires an additional factor beyond a password. Any MFA is generally better than none, but methods differ in resistance to phishing.

Method Security note
Passkey / FIDO security key Strong phishing resistance
Authenticator app with number matching or domain-aware approval Strong when used carefully
Authenticator time-based code Useful, but a phishing site can trick you into entering the code
SMS/email code Better than password alone, but weaker than phishing-resistant options

7.1 Turn On MFA

What you will learn: Protect an account even if its password is stolen.

Before you begin: Sign in through the service's known official app/site.

Exactly how to do it

  1. Open Account/Security settings.
  2. Find Two-factor authentication, Two-step verification, MFA, or similar.
  3. Choose the strongest method you can reliably use.
  4. Enroll the authenticator, passkey, or security key.
  5. Complete a test sign-in.
  6. Generate recovery codes if offered.
  7. Store recovery codes somewhere secure and separate from the main device.

What should happen: Future sign-ins require the additional factor.

If that does not happen: Do not turn off MFA because a scammer says it blocks a refund or account repair.

Practice: Enable MFA on a low-risk account before your most important accounts.

Part 8 - Passkeys

Passkeys use public-key cryptography and are tied to the real website/app. Microsoft currently describes passkeys as phishing-resistant and as a form of multifactor authentication because the passkey is on a device and is unlocked by a PIN or biometric.

8.1 Use a Passkey

What you will learn: Sign in without typing a reusable password.

Before you begin: Use a service that supports passkeys.

Exactly how to do it

  1. Reach the service through its official app/site.
  2. Open Security or Sign-in methods.
  3. Choose Add/Create passkey.
  4. Confirm the trusted device/password-manager location where the passkey will be stored.
  5. Authenticate with your device PIN, fingerprint, face, or other unlock method.
  6. Sign out and test the passkey sign-in.

What should happen: The service signs you in without exposing a reusable password to the website.

If that does not happen: If the device says no passkey exists for the site, verify you are on the correct domain and signed into the correct password-manager/account ecosystem.

Practice: Create a passkey on a noncritical supported service if you are comfortable doing so.

Why this helps: A passkey created for one registered domain cannot simply be presented to a different look-alike domain, which blocks a common phishing path.

Part 9 - One-Time Codes and MFA Fatigue

Part 10 - Browser and Website Security Warnings

FTC rule: The FTC warns that legitimate security pop-ups do not tell you to call a phone number for support.

Part 11 - Email Safety

11.1 Handle a Suspicious Email

What you will learn: Use a repeatable no-click workflow.

Before you begin: The message asks for urgent action.

Exactly how to do it

  1. Do not click or reply.
  2. Read the full sender address.
  3. Read the subject and request.
  4. Inspect attachment names without opening.
  5. Inspect links only if needed; prefer independent path.
  6. Open the organization's official app/site separately.
  7. Report the message as phishing/spam if your mail system provides that control.
  8. Delete/archive according to your organization policy.

What should happen: You investigate without giving the message control over the verification process.

If that does not happen: If the message concerns work/school, use the organization's phishing-report mechanism or IT/security contact.

Practice: Practice on a known spam/phishing sample without opening links.

Part 12 - Text Messages, Calls, and Voicemail Scams

Part 13 - Tech-Support and Remote-Access Scams

FTC guidance is clear: unexpected callers/messages that say your computer has a problem are a classic scam pattern. Legitimate technology companies do not cold-contact you to announce a virus, and real security warnings do not ask you to call a phone number.

13.1 Respond to a Fake Tech-Support Warning

What you will learn: Keep control of your device.

Before you begin: A pop-up or caller says the computer is infected.

Exactly how to do it

  1. Do not call the phone number in the pop-up.
  2. Do not install remote-control software.
  3. Do not give anyone a code from a remote-support app.
  4. Close the browser tab/window if possible.
  5. Open Windows Security or your known security software through Start, not through the pop-up.
  6. Run updates/scan if you have a genuine concern.
  7. Contact the computer/software company through its official support site if needed.

What should happen: You avoid granting a scammer remote control.

If that does not happen: If the screen is trapped in a browser full-screen page, try Escape, F11, Alt+F4, or Task Manager before following any instructions shown on the page.

Practice: Practice closing a harmless full-screen browser page.

Payment red flag: FTC warns that tech-support scammers commonly demand gift cards, wire/bank transfer, cryptocurrency, or payment apps because reversal is difficult.

Part 14 - Banking, Payment, Gift Card, and Refund Scams

Part 15 - Social Media, Dating, and Impersonation Scams

Part 16 - Shopping, Delivery, and Subscription Scams

Part 17 - Software Updates and Safe Apps

17.1 Update from the Official Mechanism

What you will learn: Install security fixes without trusting random pop-ups.

Before you begin: The device is online.

Exactly how to do it

  1. Windows: open Settings > Windows Update.
  2. iPhone/iPad: open Settings > General > Software Update.
  3. Android: open Settings > System / Software update as provided by the manufacturer.
  4. Browsers/apps: use the built-in update command or official app store.
  5. Install security updates.
  6. Restart when required.

What should happen: Updates come from the operating system/vendor rather than a message link.

If that does not happen: If a webpage says 'your browser is out of date' and offers a download, leave the page and update through the browser's official menu or operating system.

Practice: Check one device for updates.

CISA guidance: CISA's consumer security guidance emphasizes installing software updates promptly because they patch known weaknesses.

Part 18 - Backups and Ransomware Resilience

18.1 Test a Backup

What you will learn: Prove that recovery actually works.

Before you begin: Choose a harmless test file.

Exactly how to do it

  1. Back up or synchronize the test file.
  2. Rename the local copy.
  3. Use the backup/version-history service to retrieve or restore the earlier copy.
  4. Open the restored file.
  5. Confirm its contents.

What should happen: You know the recovery process before an emergency.

If that does not happen: If you cannot restore a harmless test file, fix the backup process before relying on it for important data.

Practice: Perform one restore test.

Part 19 - Public Wi-Fi, Bluetooth, and Device Privacy

Part 20 - Screen Reader and Braille Privacy

Assistive technology creates additional ways sensitive information can be exposed. These are not flaws in screen readers; they are privacy channels that deserve deliberate management.

20.1 Protect Password Entry in Public

What you will learn: Reduce audible/braille exposure.

Before you begin: You need to sign in around other people.

Exactly how to do it

  1. Use a passkey/biometric if available.
  2. Use headphones if speech feedback is required.
  3. Use password-manager autofill instead of reading/copying the password manually.
  4. Clear sensitive clipboard contents afterward if you copied anything.
  5. Lock the device when done.

What should happen: The credential is exposed less than with manual reading/typing.

If that does not happen: If the environment is not private enough, postpone the sensitive task.

Practice: Practice signing into a low-risk account with autofill.

Part 21 - Account Recovery and Security Alerts

Part 22 - What to Do After a Scam or Account Compromise

22.1 If You Gave Remote Access

What you will learn: Contain the device and accounts.

Before you begin: A scammer controlled your computer or phone.

Exactly how to do it

  1. End/disconnect the remote-support session and close/uninstall the remote-access app if safe to do so.
  2. Disconnect from the network if the attacker may still have control.
  3. From a clean/trusted device, change passwords for important accounts starting with email and financial accounts.
  4. Turn on or strengthen MFA.
  5. Update security software/operating system and run a scan.
  6. Contact your bank/card provider if financial information or payment was involved.
  7. Review account sessions and remove unfamiliar devices.
  8. Report the scam to the appropriate institution and FTC/authorities as applicable.

What should happen: You limit continued access and begin recovery.

If that does not happen: FTC guidance recommends updating security software, scanning/removing identified problems, changing passwords, and turning on two-factor authentication after giving a scammer access.

Practice: Write these steps somewhere accessible before an emergency.

22.2 If You Gave Away a Password or Code

What you will learn: Secure the account immediately.

Before you begin: Use a trusted device/path.

Exactly how to do it

  1. Change the affected password.
  2. Change any other account that reused that password.
  3. Turn on MFA/passkey protection.
  4. Sign out of other sessions/devices.
  5. Review recovery email/phone and forwarding rules.
  6. Review recent activity/transactions.
  7. Report unauthorized activity.

What should happen: The stolen credential stops being useful or becomes much harder to use.

If that does not happen: If the attacker changed recovery information, use the service's official account-recovery process immediately.

Practice: Practice locating security activity on one important account.

Part 23 - Work and School Security

Part 24 - Accessible Security Checklists

☐ Do I know the real sender address?

☐ Was I expecting this message?

☐ Is the request urgent, secret, threatening, or unusually rewarding?

☐ Can I reach the service through a known app/bookmark/typed address instead?

☐ Does the actual destination domain match the organization?

☐ Am I being asked for a password, code, money, remote access, or software install?

24.2 Before Sending Money

☐ Have I independently verified the person/organization?

☐ Is the payment method reversible/protected?

☐ Am I being pressured to use gift cards, crypto, wire transfer, or payment app?

☐ Did someone tell me not to speak with family, bank staff, IT, or police?

☐ Did I verify the request using a known number or official app?

24.3 Before Approving MFA

☐ Did I personally just attempt to sign in?

☐ Does the service/account name match?

☐ Does the location/device information make sense?

☐ Is someone on the phone telling me to approve it? If yes, stop.

☐ Am I seeing repeated unexpected prompts? If yes, deny and secure the account.

Part 25 - Practice Scenarios

Scenario 1 - Bank Text

Situation: A text says your debit card is locked and gives a link.

Safer response: Do not use the link. Open the bank's official app or call the number on the card/statement. Check alerts/transactions there.

Scenario 2 - Microsoft Pop-Up

Situation: A browser page says Microsoft found viruses and gives a phone number.

Safer response: Do not call. Close the tab/window. Run Windows Security/update through Start/Settings if concerned.

Scenario 3 - Boss Gift Cards

Situation: An email display name matches your manager and asks for gift cards urgently.

Safer response: Read the full sender address and verify through the manager's known contact method/work process.

Scenario 4 - MFA Prompt

Situation: Your phone asks you to approve a sign-in you did not start.

Safer response: Deny. Change the password through the official site/app and review sessions.

Scenario 5 - Delivery Fee

Situation: A text says a package needs a small redelivery fee.

Safer response: Go directly to the carrier's known official site/app and enter the tracking number independently.

Scenario 6 - Family Emergency

Situation: A caller sounds like a relative and asks for immediate money.

Safer response: End the call and contact the relative/another family member through known numbers.

Scenario 7 - Shared Document

Situation: A colleague sends an unexpected ZIP file.

Safer response: Confirm with the colleague through a separate channel before opening.

Scenario 8 - Refund

Situation: A caller says you were refunded too much and must return money through a payment app.

Safer response: Do not pay. Check the real account/statement and contact the company through its official support channel.

Part 26 - Quick Reference

Situation Safer action
Unexpected account alert Open the official app/site independently
Suspicious sender Read full address/domain
Suspicious link Copy/read destination or avoid it entirely
Unexpected attachment Verify sender separately before opening
Unexpected MFA prompt Deny, then secure account
Password needed Use password manager; unique password
Passkey available Prefer it when practical
Security pop-up gives phone number Do not call it
Caller requests remote access Decline unless you independently initiated trusted support
Gift card/crypto/wire demanded Stop and verify; classic scam indicator
Browser warning Do not bypass on someone's instruction
Software update Use official Settings/app-store/vendor mechanism
Possible compromise Change passwords, MFA, sessions, scan/update, contact institutions
Need proof of identity Use a separate trusted channel

Screen Reader Verification Pattern

1. Read the actual sender. 2. Read/copy the actual destination only if necessary. 3. Leave the message. 4. Open the service independently. 5. Verify the alert/activity inside the trusted service. 6. Report/delete the suspicious message.

Part 27 - Official Security Resources

CISA Secure Our World

CISA - Turn on MFA

FTC - Tech Support Scams

FTC - What To Do if You Were Scammed

FTC Consumer Advice - Online Privacy and Security

Microsoft - Passkeys FAQ

Google - Make your account more secure

Final Independence Checklist

☐ I know the four core cybersecurity habits.

☐ I can identify common phishing pressure tactics.

☐ I can read and verify an actual sender address.

☐ I can inspect or avoid suspicious links without opening them.

☐ I can verify an account alert through an independent trusted path.

☐ I know how to handle unexpected attachments/downloads.

☐ I use unique passwords and understand password managers.

☐ I understand MFA method differences.

☐ I understand why passkeys are phishing-resistant.

☐ I know never to share one-time or recovery codes with an unsolicited caller/message.

☐ I know that HTTPS alone does not prove a site is legitimate.

☐ I can identify tech-support and remote-access scams.

☐ I can identify gift-card, refund, payment, delivery, and impersonation scam patterns.

☐ I know how to update software through official mechanisms.

☐ I understand backups and can test recovery.

☐ I protect screen-reader speech, braille, and clipboard privacy.

☐ I know what to do after giving remote access or credentials to a scammer.

☐ I can use the no-click verification checklist independently.

Most important habit: A suspicious message should never control both the warning and the verification path. Leave the message, reach the real service or person independently, and verify there. That single habit defeats many phishing and impersonation scams.