Secure Your Most Important Accounts in 30 Minutes
Teki-SL Team
Start with the account that can reset all the others: your email. Then secure banking or mobile-money accounts, followed by work and school accounts. Do not try to fix everything at once. A short ordered session is far more likely to be completed.
1. Make each important password different
Reusing a password turns one leaked website into a risk for every account using it. Use a long unique passphrase for each important account, and store it in a reputable password manager if you can. Never send a password or one-time code through WhatsApp, SMS, or email.
2. Turn on multi-factor authentication
Open the account’s security settings and look for two-step verification, multi-factor authentication, or sign-in verification. Use an authenticator app or security key where it is offered; a text message code is still better than using a password alone when stronger options are unavailable.
3. Save recovery information deliberately
- Confirm the recovery email and phone number are still yours.
- Store backup codes somewhere offline and private.
- Remove old devices and unfamiliar sessions from the account settings.
- Tell a trusted person what to do if you lose your phone, without sharing your passwords.
4. Slow down when a message creates urgency
A request to “verify now”, a surprise prize, or a caller asking for a code should make you pause. Open the official app or type the organisation’s web address yourself rather than using the message link. Real support channels do not need your secret sign-in code to help you.
Why this works
Current CISA guidance is clear that passwords alone are not enough for important accounts. Multi-factor authentication adds another check that makes a stolen password much less useful to an attacker.
Related