Cyber Academy
Account security foundations
The four decisions that determine whether your accounts survive a leak: unique passwords, a second factor, recovery details, and session hygiene.
This lesson covers the smallest set of changes that meaningfully protects an ordinary set of online accounts. Work through it in order — each step assumes the previous one.
1. Make your email account the strongest one you have
Almost every other account can be reset through your email. That makes it the master key whether you intended it to be or not. Give it a long unique password, enable the strongest second factor it supports, and review the recovery phone number and backup address for anything you do not recognise.
2. Stop reusing passwords
A password manager is the only realistic way to hold unique credentials for every account. Generate rather than invent them: human-chosen passwords cluster around predictable patterns even when they feel original.
3. Add a second factor, then save the recovery codes
Enrol an authenticator app where possible. Immediately store the recovery codes somewhere separate from the device that generates the codes — a printed copy or an encrypted note both work.
4. Review sessions and connected apps
Every major service lists active sessions and third-party apps with access to your account. Old sessions on devices you no longer own, and apps you authorised years ago, are both quiet risks. Revoke anything you do not currently use.
Practice task
Generate a passphrase with the Passphrase Generator, then change your email account password to it and enrol a second factor. That single change is the highest-return security action available to most people.