Secure your accounts in 30 minutes
A short, ordered checklist for two-factor authentication, passwords, and account recovery.
You do not need to overhaul everything. Protecting the handful of accounts that can reset all the others gets you most of the benefit.
Start with the keys to the kingdom
Your primary email and your phone/carrier account come first. Whoever controls your email can reset almost every other password you own; whoever controls your phone number can intercept SMS codes.
- Give email a long, unique password used nowhere else.
- Turn on two-factor authentication — an authenticator app or a passkey is stronger than SMS.
- Save the backup codes somewhere offline.
- Ask your mobile carrier to add a port-out PIN or SIM-swap lock to your account.
Then everything that touches money
Banking, payment apps, and any shopping account with a saved card. Unique password plus two-factor on each. Turn on transaction alerts so an unexpected charge reaches you within seconds rather than at the end of the month.
Make it sustainable
Use a password manager — the one built into your browser or operating system is fine — so unique passwords cost you nothing to remember. Adopt passkeys where they are offered; there is no password for anyone to phish. Finally, check your recovery email and phone are still ones you control, because an out-of-date recovery address is how people permanently lose accounts.