Lock down your accounts
Why this matters: Being known isn't the same as being watched
What you’ll be able to do afterward
- A leaked password from some site you forgot about can’t unlock anything else you own.
- Your email — the master key to every reset — is the hardest account you have.
- A thief with your password still can’t get in.
- If someone does try, you’ll see it and know exactly what to do.
The plays
-
Lock down your email first
Where: your email provider's security settings — strong unique password, two-factor on
What this just did: email is the skeleton key. Nearly every "forgot password" flow runs through it, so securing it first secures the reset path for everything else.
-
Turn on two-factor authentication everywhere it matters
Where: security settings of banking, email, social, and shopping accounts
What this just did: a stolen password stops being enough to get in. Use an authenticator app over text codes where you can — phone numbers can be hijacked at the carrier.
-
End password reuse with a manager
Where: your browser or phone's built-in password manager, or one you choose
What this just did: reuse is how one leaked site becomes every site. A manager makes unique passwords the lazy path instead of the diligent one. (If every device you own is Apple or every device is Google, passkeys are a nice upgrade on top for your biggest accounts — otherwise skip them guilt-free: they sync poorly across ecosystems, and this play plus two-factor is a complete answer.)
-
Point account recovery at yourself
Where: each major account's recovery email and recovery phone settings
What this just did: stale recovery details are an unlocked side door. An old phone number can be reassigned to a stranger — who can then "recover" your account with it.
-
Review active sessions and sign out strangers
Where: security settings → "your devices" or "where you're signed in"
What this just did: the device list is your account's guest log. Anything you don't recognize gets signed out — and the password changed while it's locked out.
-
Know the takeover drill
When: password-reset emails you didn't request, or login alerts from places you've never been
What this just did: gave you the response before you need it — change the password from a device you trust, sign out every session, re-check recovery settings. Speed beats diagnosis.
You’re now covered against…
- Credential stuffing — the leaked-password-from-one-site trick dies when no password opens two doors.
- Password theft — two-factor means the password alone is a souvenir, not a key.
- Recovery hijacks — resets and recovery codes only go to places you still control.
- Slow-motion takeovers — you’ll spot the warning signs and already know the drill.
Twenty minutes across your handful of accounts that actually matter. None of it needs to be repeated tomorrow — this one compounds.
Progress is saved only on this device. It never leaves your phone.