1. Secure primary email
Use a unique password or passkey and enable MFA. Review recovery information and signed-in devices.
Email is the foundation because many other accounts reset through it.
2. Replace reused passwords
Use a password manager to generate unique passwords. Start with banking, cloud accounts, shopping, social media, and any site storing payment information.
Do not wait to change a password you already know is reused after a breach.
3. Turn on MFA
Use an authenticator app, trusted-device prompt, security key, passkey, or another available method. SMS is still better than password-only when stronger methods are not available.
Never approve a sign-in or share a code you did not initiate.
4. Update devices
Enable automatic operating-system, browser, and app updates where practical. Updates close known security weaknesses.
Replace devices that no longer receive security updates when they are used for sensitive accounts.
5. Verify unexpected messages independently
FTC guidance repeatedly emphasizes avoiding links or attachments in unexpected messages and contacting the organization through a phone number, app, or website you know is real.
Use the message as an alert, not as the path to the account.
6. Review privacy and permissions
Check location, microphone, camera, photos, contacts, and Lock Screen notifications. Remove permissions that no longer serve a purpose.
Delete apps you no longer use when you are confident they are not needed.
7. Prepare for recovery
Store recovery codes securely, keep backup phone numbers current, and know how to replace a lost authentication device.
A secure account you cannot recover is not a practical security system.
8. Review activity
Check recent sign-ins, devices, and account alerts periodically. Unexpected activity should be investigated using the official account security page.
Do not call a phone number included in a suspicious security alert.
Quick Reference
| Checklist item | Status |
|---|---|
| Primary email unique sign-in + MFA | Done / Review |
| Password manager in use | Done / Review |
| Reused important passwords replaced | Done / Review |
| MFA on important accounts | Done / Review |
| Recovery methods current | Done / Review |
| Automatic updates enabled | Done / Review |
| Phone privacy permissions reviewed | Done / Review |
| Unexpected messages verified independently | Habit in place / Needs practice |
| Account/device activity reviewed | Done / Review |
Protect the accounts that can unlock everything else
Start with primary email, your Apple or Google account, banking, payment services, and your password manager if you use one.
Give each a unique password and an additional sign-in step. These accounts deserve more attention than a low-value website you rarely visit.
Make reused passwords your first cleanup project
If the same password is used on several sites, one breach can put all of them at risk.
Replace reused passwords gradually, beginning with the most important accounts. Let a password manager generate and store the new ones.
Create a verification habit for unexpected messages
Urgent emails, texts, and calls are easier to handle when you have one rule: verify through a contact method you choose.
Open the official app, use a saved bookmark, or call the number printed on a card or statement. Do not let the message itself choose the route you use to verify it.
Prepare for losing a device
Security planning should include recovery. Keep account-recovery information current, know where backup codes are stored, and understand how to sign out a lost phone or computer.
A strong account is one you can both protect and recover.
Build a security routine you can keep
You do not need to understand every technical detail to protect your accounts. Use unique passwords, protect email carefully, add a second sign-in step where practical, keep devices updated, and verify unexpected requests through a route you choose.
When something feels wrong, stop before entering a password, sharing a code, sending money, or installing software. A few extra minutes of independent verification can prevent a much larger problem.
Make security easier to maintain
A security system only works when you can live with it. Use a password manager if remembering many unique passwords is unrealistic, keep recovery information current, and choose an additional sign-in method you understand. The goal is stronger protection without creating a system so complicated that you work around it.
Review the important accounts once or twice a year. Confirm the recovery phone number, recovery email, and trusted devices. Remove old devices and outdated contact methods before you need account recovery.
Slow down when a message creates urgency
Scammers often try to compress your decision into a few minutes. They may claim your account will close, a payment failed, a relative needs help, or suspicious activity requires immediate verification. Urgency is a reason to verify, not a reason to skip verification.
Close the message and contact the organization through an official app, saved bookmark, statement, card, or number you already trust. If the problem is real, you should be able to find it without using the message’s link or phone number.
Keep a simple recovery sheet
Write down which email address is used for your most important accounts, where recovery codes are stored, and which trusted person should be contacted if you cannot access a device. Do not put actual passwords, one-time codes, or full account numbers on a general household sheet.
Store the recovery information somewhere secure but practical. A plan that exists only in your memory can disappear at the exact moment you need it.
Update devices and browsers regularly
Security updates fix known weaknesses in phones, tablets, computers, browsers, and apps. Turn on automatic updates when that works for you, or set a recurring reminder to check for them.
If an old device can no longer receive important security updates, consider whether it should still be used for sensitive tasks such as email, banking, or password management. A familiar device can become less trustworthy when its software is no longer maintained.
Review account alerts instead of ignoring them
Sign-in alerts, password-change notices, and recovery-email messages can be useful early warnings when something changes on an account. Do not automatically click the alert’s link, especially if the message was unexpected. Open the official app or website yourself and check recent activity there.
If the alert is legitimate and the activity was yours, no further action may be needed. If you do not recognize the activity, change the password from a trusted device, review recovery settings, and sign out unfamiliar sessions.
Sources
Frequently Asked Questions
What should I secure first?
Your primary email, then financial, cloud, shopping, and social accounts.
Do I need to do everything in one day?
No. Work through the checklist in priority order.
Is antivirus enough?
No. Account security also depends on unique credentials, MFA, updates, phishing awareness, and recovery planning.
What if I already reuse passwords?
Replace the most important reused passwords first and use a manager going forward.
Can any setup guarantee I will never be hacked?
No. Good security reduces risk and limits damage; it does not create a guarantee.
Keep this visual on Pinterest
Save the infographic so you can return to the checklist or comparison when you need it.
Save on Pinterest