I spent seven parts of this series explaining why the government's teen internet plans will leak. A reader wrote to me, reasonably, with the only question that matters once the critique is over: "Fine — so what do I actually do?"

This is the answer, and it is the most important thing I have written in the whole series. Because here is the fact that survives all seven parts of pessimism: a parent has the one thing a government does not — you are actually in the room with the child. Every enforcement layer Westminster reaches for can be proxied, streamed, federated or offshored around. You cannot be. You know this specific child, you control the device you bought them, and you have a relationship that predates every platform they will ever join. That is more leverage than the entire Online Safety Act, and this piece is about spending it well.

A warning before we start: this is a security posture, and I am going to lay it out the way I lay out any defence — in layers, ordered by effectiveness, honest about what each one does and doesn't do. It is longer than my usual. Read it with a cup of tea, do the first layer tonight, and come back for the rest. There is no single switch. There never is.

Prefer paper? Everything below is condensed into a free, five-page printable field guide — the layered posture, the per-platform settings to change, the two threats to know by name, and the crisis reporting routes on a keep-this-by-the-fridge page. Download the parent's field guide (PDF) — no sign-up, no email, and made to be forwarded to another parent.

First, the uncomfortable reordering

Most parents, faced with online risk, reach first for the controls — the apps, the filters, the monitoring. It is the instinct the entire parental-controls industry is built to satisfy. And it is, according to the actual evidence, backwards.

The largest analysis we have — a meta-analysis by Chen and Shi pooling fifty-two studies and seventy-odd thousand participants — found something every parent should have tattooed somewhere visible: the parenting approach that best reduces a child's screen time is not the one that best reduces their exposure to harm. Restriction and blocking cut hours. Conversation, co-use and teaching cut harm. They are different levers, and most households pull hard on the first while barely touching the second.

The NSPCC says it plainly: parental controls "shouldn't be seen as a whole solution", and "content filters are never 100% effective." Internet Matters puts it as a layer model: "network, device and app controls each play a different role… none of them replaces the need to talk." The Children's Commissioner reduces it to four words worth more than any setting: "talk early, talk often."

So we are going to build the posture in the order that actually works, not the order that feels productive. The conversation is the primary control. Everything technical is a supporting layer that buys time and cuts the casual, accidental exposure — real value, but not the main event. If you do only one thing from this entire guide, do the first section.

Layer one — the conversation, and the one rule that matters most

There is a single principle that the NSPCC, UNICEF, the Australian eSafety Commissioner and the Children's Commissioner all endorse independently, and if you take nothing else from this piece, take this:

Your child must believe, correctly, that telling you about something bad online will not cost them the device.

This is not softness; it is engineering. Ofcom's 2025 research found that among 11–17s, roughly three-quarters had seen harmful content in a single four-week window — and only about fifteen per cent told an adult. Most harm never reaches the parent at all. The single biggest reason a child stays silent is the fear that disclosure means confiscation — that reporting the frightening message gets the phone taken away, so they say nothing and handle it alone, which is precisely the outcome you least want. UNICEF's script is worth memorising: "I'm glad you told me. You are not to blame, and I'm here to help. Let's figure it out together."

That principle only works if the relationship it rests on already exists, which is why the advice is talk early and often, not one solemn Big Talk at thirteen. The Children's Commissioner's research is blunt about the alternative: children describe their parents as "in the dark," and covert snooping, when discovered, detonates the trust that disclosure depends on — "don't suddenly go behind a child's back." Frequent, low-stakes, genuinely curious conversation beats one dramatic intervention every time. Ask what games they're into. Ask what they'd do if a stranger messaged them. Ask them to show you something they like. You are not conducting an interrogation; you are keeping a channel open, so that when something goes wrong — and across a childhood, something will — you are the first call and not the last.

And when a child does disclose, the NSPCC's guidance for the moment is precise: listen without projecting your own alarm, tell them they did the right thing, tell them it is not their fault, take it seriously, explain what happens next, and write down what they told you while it is fresh. Do not confront whoever did it directly — that can make things worse for the child. Your calm in that moment is itself a control; your panic teaches them never to come to you again.

This is the layer that does not leak. Build it first.

Layer two — the device, because it travels with the child

Now the technical layers, in the order I would actually configure them, starting with the one that matters most for the reason the whole series kept arriving at: the device is the only place that is always, unavoidably, in the room with the child. Set protections here and they hold on mobile data, on a friend's Wi-Fi, inside apps — everywhere the traffic goes, because it all runs on that device.

On iPhone/iPad, that is Screen Time under a Child Account in Family Sharing: Downtime (a schedule where only what you allow works), App Limits, Content & Privacy Restrictions (web filtering, age-rated app and media limits, blocking app installs and deletions), and — set it on — Communication Safety, which detects and blurs nude images in Messages and FaceTime on the device itself. On Android and Chromebooks, the equivalent is Google Family Link: app approval, screen-time and bedtime, content maturity limits, SafeSearch locked on. On Windows and Xbox, Microsoft Family Safety.

Three honest cautions, because I will not sell you a control I would flag in a review:

First, the lock is only as strong as the password behind it. On Apple, the Screen Time passcode can be reset by anyone who knows the Apple Account password used to set it up — so that password must be one your child does not have. This is the most common way these controls quietly fail: not defeated, just unlocked with a known password.

Second, roughly two in five UK children report getting around age checks and controls of one kind or another. A determined teenager with a second-hand phone you never configured, a friend's device, or a factory reset defeats most of this. That is not a reason to skip it — raising the floor stops a great deal of casual and accidental exposure, which is most of it — but it is a reason not to mistake a configured device for a solved problem. The controls are a seatbelt, not a force field.

Third, the highest-value device setting isn't in a menu. It is a rule: the phone charges overnight outside the bedroom. Internet Matters and the NSPCC both put devices-out-of-bedrooms near the top of their practical advice — it was the very first thing this series told you to do tonight — and it is the one control with no bypass — a phone on the kitchen counter cannot be doomscrolled at 2am or used to send a message a child will regret. A £3 charging habit outperforms most of the software.

Layer three — the platforms, audited by function

In part two I argued that the harm follows a function — stranger contact with your child — not a brand, and that the honest test for any app is: can an unknown adult start a private conversation here? That is the test to run across every app and game they use, and for the ones that fail it, these are the settings genuinely worth your evening. Platforms change these constantly, so treat the specifics as a starting point and check the current app.

Roblox — the big one, because it is a social platform wearing a game's clothing. Set up Parental Controls by linking your own (age-verified) account: set a content maturity ceiling, set an Account PIN so the child can't reverse your settings, and configure communication by age. Since January 2026 all chat sits behind a facial age check that sorts users into age bands — useful, but know its blind spot: it governs Roblox's own chat, not chat built inside individual games. The PIN and the maturity ceiling are your real levers.

Discord — turn on Family Centre (it shows you who your teen is friending and messaging, though not the content), set who can DM to friends-only and keep the sensitive-content filters on. Discord's own age-assurance changes now default teens to the stricter settings.

Snapchat — confirm Ghost Mode is on so location isn't shared (it's the default, but check), set Contact Me to friends-only, and link Family Centre. The location-sharing default is the one to verify by hand.

Instagram and TikTok — both now run Teen Accounts that default under-16s to private, restricted messaging and content filters, many of which a younger teen can't loosen without your linked approval. Set up the supervision (Meta Family Centre; TikTok Family Pairing) so that approval actually routes to you. On TikTok, note that under-16s can't send or receive direct messages at all — a genuinely good default worth knowing about.

YouTube — for younger children use the separate YouTube Kids app with search turned off; for older ones, a supervised account via Family Link with one of the three content levels set. Restricted Mode on the main app is per-device and easily switched off, so don't lean on it.

The pattern under all of these is the same: lock who can contact the child down to people they actually know, and put a PIN or a linked-parent approval between the child and the ability to undo it. You are not trying to surveil the conversation. You are trying to make sure a stranger can't start one.

Layer four — the network, the cheap whole-home floor

The weakest layer, but nearly free and worth ten minutes. Every UK broadband provider — BT, Sky, TalkTalk, Virgin — offers account-level filtering you can switch on to block adult categories across the whole house. For a bit more control, a DNS filter like Cloudflare for Families (set your router's DNS to 1.1.1.3) or NextDNS blocks whole categories of site for every device on your Wi-Fi.

Be clear-eyed about what this does not do, because it is the layer most oversold. It blocks whole domains, so it cannot filter one bad video on a site you otherwise allow, and it cannot see inside apps at all. It is trivially bypassed by a VPN, by switching from Wi-Fi to mobile data, or by changing the phone's DNS. Treat it as a coarse net that catches accidental and casual stumbles for the whole household — useful, cheap, and not to be trusted an inch further than that.

The two threats worth knowing by name

Layers are posture; these are the specific attacks the posture exists to stop, and both are worth understanding directly.

Grooming rarely looks like the stranger-danger cartoon. It is patient. An adult — often posing as younger — offers attention, flattery, advice and small gifts, builds a bond over weeks, and then, at the critical moment, steers the conversation off the original platform onto something private or encrypted: "let's talk on [somewhere else]." That platform-switch is the single most important tripwire you can teach a child to notice and report. The NSPCC's warning signs for parents: new secrecy about time online, an older boyfriend or girlfriend, unexplained gifts or money, going missing, withdrawal, or sexual language beyond their years. None is proof; together they are a reason to gently open the conversation.

Sextortion is the one I most want you to read carefully, because it is fast, financially motivated, aimed squarely at teenage boys aged roughly 14–17, and it has driven children to catastrophe. The pattern: an attractive stranger makes contact, moves quickly to sexual chat, persuades the young person to send a nude — then instantly threatens to send it to their family and friends unless they pay. The demands escalate within the hour. The National Crime Agency's research found three-quarters of boys didn't recognise a nude-image request as a warning sign, and most didn't know it could happen to them. Talk to your sons about this specifically, before it happens, because the shame is engineered to keep them silent.

And know the correct response cold, because doing the wrong thing here makes it worse. If it happens:

When it goes wrong — the routes that actually work

Bookmark these now, while it is calm, because you do not want to be searching for them in a crisis. The names matter; parents' guides muddle them constantly. (They are all on the last page of the printable field guide too — designed to be kept somewhere you can find it in a hurry.)

Report to the platform as well, keep the reference number, and preserve your evidence before you block. And afterwards, remember the support doesn't stop at the report: Childline for the child, the NSPCC helpline for you, and the Marie Collins Foundation for families dealing with the aftermath of technology-assisted abuse.

Where this leaves you

Step back and look at the shape of it. The conversation is the load-bearing wall. The device controls are the locks on the doors. The platform settings close the windows a stranger climbs through. The network filter is a fence at the bottom of the garden. And the reporting routes are the emergency services you hope never to call. No single layer holds on its own — but a determined threat has to get through all of them, and a relationship in which your child will actually tell you when something is wrong sits underneath the lot, catching what every technical layer misses.

That is a genuinely strong posture, and you can build most of it this weekend, regardless of what Parliament does next spring. Which returns me to the sentence this whole series kept arriving at, and I will end the series where its argument always pointed: governments regulate platforms. Parents raise people. The law that arrives in the spring will leak, as every part of this series has shown. The protections that hold are the ones in your house — the device you configured, the settings you closed, and, worth more than all of it combined, a child who knows that whatever happens online, they can come to you first and they will not lose the phone for telling the truth.

This concludes "Regulating the Teen Internet." All eight parts are collected here. None of this is legal advice, and none of it substitutes for the professionals named above — if you are worried about a child right now, contact the NSPCC on 0808 800 5000, or the police.