Most accounts aren't 'hacked' by some genius breaking encryption — they're opened with a reused password from another site's breach, or a convincing phishing email. That's good news: the same handful of habits stops the overwhelming majority of attacks.
This guide is a practical, prioritised checklist to lock down your accounts, starting with the two that matter most.
What you need
- ✓A password manager (the single biggest upgrade to your security).
- ✓An authenticator app for two-factor codes.
- ✓20 minutes to secure your most important accounts first.
Step-by-step
- 1
Secure your email first
Your email can reset every other account, so it's the master key. Give it a unique, strong password and turn on two-factor authentication before anything else.
- 2
Give every account a unique password
Reuse is how one breach becomes ten. A password manager generates and stores a different strong password for every site so you never repeat one.
- 3
Turn on two-factor authentication
2FA blocks logins even when someone has your password. Use an authenticator app rather than SMS where possible — SMS can be intercepted or SIM-swapped.
- 4
Learn to spot phishing
Check the sender's real address, hover links before clicking, and never enter your password on a page you reached from an email. When in doubt, go to the site directly.
- 5
Review connected apps and old accounts
Revoke third-party apps you no longer use, and close dormant accounts — every one is a door. Check your email for 'sign in with' permissions.
- 6
Set up recovery and check for breaches
Add recovery contacts/codes and store them safely. Use a breach-check service to see if your email has appeared in a leak, and change those passwords.
Examples
- A reused password from a breached forum let attackers into someone's shopping account — a unique password per site would have contained it.
- A phishing email mimicking a bank linked to 'bank-secure-login.com' — checking the real domain revealed the fake instantly.
Tips
- →Protect email above all — it's the reset mechanism for everything else.
- →Let a password manager do the remembering; you only memorise its master passphrase.
- →Prefer app-based 2FA over SMS; keep backup codes somewhere safe.
- →Slow down on urgent-sounding messages — urgency is the phisher's main tool.
- →Passkeys, where offered, are even stronger than passwords plus 2FA.
Common mistakes
- Reusing passwords. Use a unique password per site so one breach can't cascade.
- Only securing 'important' accounts. Secure email first, then everything — attackers pivot from weak accounts.
- Trusting links in emails. Go to the site directly and never enter credentials from an emailed link.
- Relying on SMS 2FA alone. Use an authenticator app; SMS is vulnerable to interception and SIM swaps.
Conclusion
Account security isn't about paranoia — it's a short checklist: protect your email first, give every account a unique password via a manager, turn on app-based 2FA, and stay sceptical of urgent links. Do those and you've shut the doors attackers rely on.