How-To

How to Secure Your Online Accounts in an Afternoon

A step-by-step afternoon plan to secure your online accounts — password manager, two-factor authentication, passkeys, and breach cleanup, in the order that matters.

GetSmartStuffs HOW-TO

Disclosure: GetSmartStuffs is reader-supported. When you buy through links on our site, we may earn an affiliate commission — at no extra cost to you. We only recommend gear we'd use ourselves. Learn more.

Forget the hoodie-hacker imagery. Most people get compromised in boring ways: a password reused on fifty sites shows up in one breach, or a convincing phishing page harvests a login that had no second factor. Both problems die in one afternoon of setup — no technical skill required, mostly free.

Only have 30 minutes? Do these three things

The full plan below is worth an afternoon, but if today only gives you half an hour, triage:

  1. Put app-based two-factor authentication on your email (10 minutes). This single move blocks the most common takeover path even if your password leaks tomorrow.
  2. Change your email password to a long, unique passphrase (5 minutes) — one you use nowhere else.
  3. Install a password manager and save your email login into it (15 minutes). Don’t migrate anything else yet; just get the vault existing with a strong master passphrase.

That’s the load-bearing 20% of this article. Everything else compounds from there, and you can pick up at step 3 of the full plan whenever your next free hour appears.

Step-by-step: the afternoon plan

1. Lock down your email first

Every “forgot password” flow on the internet ends at your inbox — whoever controls your email controls your entire digital life. Before anything else: give it a long, unique passphrase; enable two-factor authentication with an authenticator app (not SMS if avoidable); and verify the recovery phone and backup email are current and belong to you (stale recovery details are a quiet takeover risk).

While you’re in those settings, do a two-minute audit of everything else on the security page:

  • Recovery phone number. Is it your current number? An old number can get recycled to a stranger by the carrier — and whoever holds it can receive your reset codes.
  • Backup email address. If it points to some ancient account you barely remember, you’ve just moved the master key to a building with worse locks. Either secure that account to the same standard or remove it.
  • Connected apps and sessions. Most providers show a list of devices signed in and third-party apps with access. Sign out anything you don’t recognize and revoke apps you stopped using years ago.

If your email provider profits from reading your mail and you’d rather it didn’t, this is also the natural moment to consider a privacy-first provider:

Proton

Proton

Proton Mail is the mainstream privacy-first email choice — encrypted, and the suite bundles a VPN and password tools if you want one privacy subscription.

Free, or from $3.99/mo (Mail Plus, billed annually) — full suite (Unlimited) from $9.99/mo (verified 2026-07-10)

2. Install a password manager

This is the tool that makes everything after it easy — it generates, remembers, and fills a different strong password for every site.

Bitwarden

Bitwarden

Free, open-source, audited, all devices. The default recommendation — our full comparison covers when paying for 1Password or Dashlane makes sense.

Free, or from $1.65/mo (Premium, billed annually) (verified 2026-07-10)
1Password

1Password

The paid upgrade pick — smoothest apps and the best family plan, which matters if you're also setting this up for a partner or parents.

From $2.99/mo (Individual, billed annually) (verified 2026-07-10)

Two settings before moving on: a master passphrase of four-plus random words (the one password you’ll still remember), and two-factor on the vault itself.

What a good master passphrase actually looks like. The pattern: four or more genuinely random words, separated by something, with no personal meaning. Something shaped like plum-radiator-canoe-thursday — easy to type, easy to remember after a week of use, and long enough that guessing it by brute force isn’t practical. (Don’t use that exact example, obviously — anything printed in an article is on every guessing list.) The rules that matter:

  • Random beats clever. Song lyrics, your kids’ names plus a year, P@ssw0rd!-style substitutions — these follow patterns cracking tools already know. Most password managers can generate a random passphrase for you; use that, or pull words by flipping a book open to arbitrary pages.
  • It must be unique. Never a password you’ve used anywhere before, even a beloved one. If it ever appeared on another site, assume it’s in a leaked list somewhere.
  • Write it down while you learn it. A slip of paper in your wallet or a drawer at home is a perfectly sensible bridge for the first couple of weeks — the attackers who worry us are on the internet, not in your kitchen. Once it’s muscle memory, shred the note or move it to long-term safekeeping.
  • Make a recovery plan now. Check whether your manager offers a recovery/emergency kit or account-recovery option, set it up, and store a printed copy somewhere safe. Forgetting the master passphrase with no recovery path means losing the vault — that’s the price of nobody else being able to open it either.

3. Fix your critical accounts

Don’t try to fix everything today — fix what matters. The critical list: banking and payment apps, email (done), cloud storage, main social accounts, and any shop with a saved card. For each: generate a unique password into the manager, then switch on two-factor authentication — authenticator app first, SMS only as fallback. This step is the bulk of the afternoon and the bulk of the protection.

A useful rhythm so it doesn’t drag: open the site, let the manager generate and save a new password, flip on two-factor while you’re in the settings, save the backup codes (next paragraph), done — two to five minutes per account. Do the money accounts first, then work outward. If a site fights you on where the security settings live, searching “site name enable two-factor” usually lands you on their own help page.

About those backup codes. When you enable two-factor, most services hand you a set of one-time backup codes — your way back in if your phone is lost, broken, or in a drawer at home. Treat them as part of the setup, not an optional extra:

  • Best homes for them: a secure note attached to that login inside your password manager, a printed sheet in a safe place at home, or both.
  • Bad homes for them: a screenshot in your photo library (synced, searchable, and exposed if your cloud account is), an email to yourself (the exact account the codes are supposed to rescue), or a file named backup codes.txt on the desktop.
  • If you set up two-factor months ago and have no idea where your codes are, most services let you regenerate a fresh set from security settings — the old ones stop working, which is what you want.

The same logic covers a lost or new phone: authenticator apps generally offer encrypted backup or transfer between devices. Set that up on a calm Tuesday, not during the panic of a cracked screen.

4. Turn on passkeys where offered

The password’s successor is already here: passkeys sign you in with your device’s fingerprint/face unlock, there’s nothing reusable to leak, and phishing pages can’t capture them. Google, Apple, Microsoft, and a growing list of major services support them ([TODO: verify current adoption examples]) — when a security-settings page offers “add a passkey,” say yes. Your password manager can store these too.

Two practical notes so passkeys don’t surprise you later. First, decide where they live: passkeys saved to your phone or laptop sync through that platform’s ecosystem (Apple, Google, Microsoft), while passkeys saved into your password manager travel with the manager across all your devices — for most people the manager is the tidier home, for the same reason it’s the tidier home for passwords. Second, keep a fallback: most services keep your password active alongside the passkey, so the account is only as strong as its weakest door. Adding a passkey doesn’t excuse a weak password on the same account — you did the password properly in step 3, so this is just a reminder not to undo it.

Don’t turn this step into a scavenger hunt, either. Add passkeys opportunistically — when a service you’re already signing into offers one, take the ten seconds. The accounts worth seeking out deliberately are the same critical list from step 3.

5. Check what’s already leaked

Now find out what’s already out there: run your email through a breach-check service, or use the breach report built into your password manager (Bitwarden and 1Password both flag compromised logins). Anything that appears: change that password everywhere it was reused. This is the moment most people discover why reuse is the real killer.

A calibration note, because the first breach report can look alarming: appearing in a breach list means a service you once signed up for leaked data — it does not mean someone is inside your accounts right now. The correct response is methodical, not panicked. Change the leaked password and its reuses, make sure two-factor is on for anything important that appeared, and move on. Old breaches of long-dead accounts with passwords you no longer use anywhere are history, not emergencies.

6. Clean up the long tail

The remaining hundred accounts don’t need today. The habit that finishes the job: whenever you log into an old site, let the manager upgrade the password on the spot. And delete accounts you’ll never use again — data you don’t leave lying around can’t leak.

Two low-effort accelerators: most password managers include a health or “watchtower”-style report that lists your weak and reused logins ranked by risk — knocking out the top five once a week finishes the long tail faster than it sounds. And when you delete an old account, check whether the service has an actual deletion option in settings rather than just abandoning it; searching “service name delete account” usually surfaces the path.

How attackers actually get in: the recovery back door

Worth understanding, because it explains several of the steps above: the modern account takeover often doesn’t guess your password at all. It walks through the account-recovery flow — the “forgot password?” door — using whatever that flow trusts:

  • A stale recovery phone or email you no longer control (which is why step 1 has you audit them).
  • Guessable security questions. Your mother’s maiden name, first school, and first pet are shallow research for anyone motivated — some of it is on your social profiles right now. Where a site still forces security questions, treat them as passwords: give a random, false answer and store it in your manager’s notes for that login. Nothing requires the answer to be true; it only has to match.
  • SMS codes rerouted by SIM-swapping — an attacker convincing or bribing a carrier into moving your number to their SIM. This is the concrete reason app-based codes and passkeys beat SMS: they live on your device, not your phone number.

The pattern behind all three: recovery paths are only as strong as the weakest thing they trust. The afternoon plan closes each one — current recovery details, no truthful security answers lying around, and app-based second factors.

What about a shared family computer?

A household machine everyone uses is fine — a household login everyone shares is where it goes wrong. One browser profile holding everyone’s saved passwords and live sessions means one person’s bad click exposes the whole family, and nobody can tell whose saved card just paid for what.

The fix is built into every operating system and takes minutes: give each person their own OS user account, each with its own login. Passwords, sessions, autofill, and browsing stay separated; a compromise or mistake stays in its lane. Password managers fit neatly on top — each person gets their own vault (a family plan makes this tidy, and 1Password’s is the smoothest we’ve seen), and shared logins like the streaming services live in a shared collection instead of a sticky note. Give kids non-administrator accounts while you’re at it — most junk software needs admin rights to do real damage, and homework doesn’t.

Phishing red flags worth memorizing

Everything above hardens the locks; phishing tries to talk you into opening the door yourself. The tells repeat so reliably they’re worth learning as a checklist:

  • Manufactured urgency. “Your account will be suspended in 24 hours.” “Unusual sign-in — verify immediately.” Real services rarely demand speed; attackers always do, because pressure short-circuits scrutiny.
  • The almost-right sender. An address like support@yourbank-security-alerts.com instead of the bank’s actual domain, or a display name saying “PayPal” over a random address it doesn’t match. On phones, tap the name to expand the real address.
  • Links that don’t go where they claim. Hover (or long-press) before clicking: if the text says one site and the destination says another, that’s the whole story.
  • Unexpected two-factor prompts. A code or approval request arriving when you didn’t just try to sign in means someone else did — never approve it, and change that password.
  • Requests to “verify” what they should already know: full card numbers, passwords, one-time codes. No legitimate service asks you to read a security code to a human, ever.

The universal escape hatch when anything feels off: don’t interact with the message at all. Type the site’s address yourself or use your bookmark, log in, and check. If something genuinely needs your attention, it’ll be waiting in the account. Bonus of the password-manager life: autofill refuses to fill your credentials on a lookalike domain — a quiet built-in phishing alarm.

Common mistakes

  • Doing this in the wrong order. New passwords everywhere while your email is weak = new locks, master key under the mat.
  • A weak master password on the vault. It’s your new single point of failure; the passphrase + vault 2FA combo is non-negotiable.
  • Skipping 2FA because it’s “annoying.” Modern app-based 2FA prompts take two seconds and stop the most common account takeovers cold.
  • Falling for urgency. “Your account will be closed in 24 hours” is the phishing tell. Real services don’t threaten; when in doubt, type the site address yourself instead of clicking.

What about a VPN?

Deliberately last: a VPN protects your traffic (useful on public Wi-Fi and against snooping providers — our honest VPN guide covers who actually needs one), but it does nothing about how most people really get compromised. Passwords and 2FA first; VPN after, if your situation calls for it.

This plan is the heart of our Privacy & Security Kit — the password manager comparison helps you pick step 2’s tool, and remote workers have a few extra layers worth adding.

Frequently asked questions

What should I do first to secure my accounts?

Secure your email account before anything else — long unique passphrase, app-based two-factor authentication, current recovery details. Every other account sends its password resets there, so whoever controls your email controls everything downstream. Then install a password manager and work through your critical accounts.

Is SMS two-factor authentication good enough?

It's dramatically better than nothing, but it's the weakest form — SIM-swap attacks can intercept it. Prefer an authenticator app or, better, passkeys wherever offered, and keep SMS as the fallback only. One exception: for accounts that offer nothing else, turn SMS on rather than skipping two-factor entirely.

What are passkeys and should I use them?

Passkeys replace passwords with cryptographic sign-in tied to your device, unlocked by fingerprint, face, or PIN. Nothing to remember, nothing reusable to steal, and phishing sites can't capture them — which is why the big platforms are pushing them. Yes: wherever an account offers a passkey, add it.

How do I know if my passwords have been leaked?

Breach-notification services let you check your email address against known data breaches, and most good password managers include ongoing breach monitoring that flags affected logins automatically. If a password shows up in a breach, change it everywhere you used it — that last part is why reuse is the real danger.

Where should I store my two-factor backup codes?

Somewhere that survives losing your phone: a secure note inside your password manager is the convenient option, and a printed copy in a drawer or safe at home is the resilient one — doing both is reasonable. What doesn't work is a screenshot in your camera roll or an email to yourself, because anyone who gets into those gets your codes too.

What if my whole family shares one computer?

Give each person their own operating-system user account with their own login — it's free, takes minutes, and keeps saved passwords, browser sessions, and autofill from bleeding between people. A shared browser profile where everyone's accounts stay logged in is how one person's phishing mistake becomes the whole family's problem.

Do I really need to change every password I have?

No — and trying to is how people burn out and quit. Change the critical ones today (email, banking, cloud storage, anything with a saved card), change anything flagged in a breach report, and let your password manager upgrade the long tail naturally as you log into old sites over the following weeks.

Free download

Get the free Digital Security Checklist

The afternoon lockdown plan on two pages — passwords, two-factor, and the phishing red-flag card. Honest security picks in your inbox, no fear-mongering.