Small steps that reduce real risk.
Start with the accounts that can reset everything else: your primary email, mobile carrier, financial accounts, cloud storage, and password manager.
Use a unique password for every important account
When one service is breached, reused passwords can expose unrelated accounts. A password manager can create and store long, unique passwords so you do not have to memorize them all. Protect the manager itself with a strong master password and MFA.
Turn on multifactor authentication
Use the strongest method the account supports. Passkeys and hardware security keys resist common phishing attacks; authenticator apps are also useful. SMS is not the strongest option, but it is generally better than password-only access when alternatives are unavailable.
Install security updates promptly
Turn on automatic updates for operating systems, browsers, extensions, password managers, authenticator apps, and internet-connected devices. Remove software you no longer use.
Recognize and report phishing
Unexpected urgency, requests for secrets or payment, and unusual sender domains are warning signs. Verify through an official app or a separate contact channel. Never share passwords or one-time recovery codes.
Prepare account recovery
Keep recovery email addresses and phone numbers current. Save backup codes somewhere separate from your main phone. Review sessions and third-party access periodically.
Keep expectations honest
These steps reduce common risks but cannot guarantee protection. If you face stalking, domestic abuse, targeted harassment, major financial loss, or a compromise involving work systems, seek qualified local or organizational help suited to that risk.