The short answer
Password manager with unique passwords everywhere, app-based or hardware two-factor on email and banking first, and a recovery plan. Email is the master key — secure it before anything else.
Attackers do not guess passwords, they reuse leaked ones. Uniqueness matters more than complexity.
Step by step
- Install a password manager and set one strong, memorable master passphrase.
- Secure your primary email account first — every reset flows through it.
- Turn on two-factor authentication using an authenticator app, not SMS, where offered.
- Store the backup codes somewhere offline.
- Change reused passwords, starting with email, banking, and anything with a saved card.
- Check your addresses against a breach database and rotate anything found.
- Review connected third-party apps and revoke what you do not recognise.
What it costs
| Item | Typical cost |
|---|---|
| Password manager | $0–$40 / year |
| Hardware security key (Two keys — one is a spare) | $25–$60 |
| Authenticator app | free |
Common questions
Is SMS 2FA useless?
It is much better than nothing, but vulnerable to SIM swapping. Prefer an app.
Is a password manager risky?
Far less risky than password reuse, which is the actual cause of most account takeovers.
How often should I change passwords?
Only after a breach or suspicion. Forced rotation makes passwords worse.