Digital Life · Protect
Not all accounts are equal. This guide works in the order that protects your household fastest: email, then money, then everything else.
Why email comes first
When you forget a password anywhere, the reset link goes to your email. The FTC puts it plainly: a criminal who takes over your inbox can request reset links for your other accounts, change those passwords, and take them over too.[1]
That makes email your household's master key. Two steps protect it: a long password used nowhere else, and two-step verification. Do those tonight, for every adult's email, and the most damaging failure mode is closed.
Then work outward. Financial accounts next, since that is where losses land. Everything else can wait for the password manager below.
Passwords that hold
The federal password standard was rewritten around real evidence, and it now says the opposite of the old office rules.
NIST, the agency that sets the standard, dropped mandatory symbol-and-number rules and forced periodic changes. Length is what matters: when a password stands alone, the current guidance calls for at least 15 characters, and a passphrase of ordinary words beats a short string of symbols.[2]
A password should change for one reason only: evidence it was compromised. Routine forced changes push people toward predictable patterns, which is why the standard now prohibits them.[2]
The practical tool here is a password manager, an application that generates and remembers a long unique password for every account, locked behind one strong passphrase you memorize. The FTC recommends the approach for exactly this reason: unique passwords everywhere, without the memory burden.[3] Solid options run from free to roughly $60 a year for a family plan.
The one-evening version
Install a password manager. Set a long passphrase you can say out loud, four or five ordinary words. Move your email and bank logins into it first and let it replace both passwords with generated ones. Everything else migrates naturally as you log in over the next month.
The second lock
Two-step verification, often written as 2FA or MFA, means logging in takes your password plus one more proof, usually a code from your phone. CISA's guidance is direct: any form of it beats none, because a stolen password alone stops working.[4]
The forms are not equal. Codes sent by text message can be intercepted or phished. An authenticator app, a small free app that generates codes on your phone, is stronger. The FTC names authenticator apps and security keys as the more secure choices when a site offers them.[3]
The strongest option is a passkey. A passkey replaces your password with the way you already open your device, the same fingerprint, face, or PIN you use every day. There is no password to steal and nothing to type into a fake site, which is why CISA calls this class of sign-in the gold standard.[4] When an account offers a passkey, take it.
Priority order stays the same throughout: email first, financial accounts second, then anything holding your identity documents or photos.
Adjustments
Less technical adults
Set up the password manager together, at their pace, on their device. One session covering email and the bank is a complete win. Skip the lecture on everything else.
Shared household accounts
Streaming, utilities, and shopping accounts shared by the family belong in a shared vault inside the password manager, so nobody keeps a sticky note copy.
The paper fallback
Write the password manager's master passphrase and your email recovery codes on paper. Store the page with your household documents, where a trusted adult can find it.
Common mistakes
Reusing one good password. One breach at any site turns that password into a key for all of them. Unique everywhere is the point of the manager.
Answering security questions honestly. Your mother's maiden name and first car are researchable. Treat the answers as extra passwords and store them in the manager.
Ignoring software updates. Updates carry the security patches. Turn on automatic updates and let the phone restart overnight.[3]
Stale recovery contacts. A recovery method pointing at an old phone number or dead email locks you out at the worst moment. Check yours once a year.
Next steps
Accounts secured, protect the humans next. Five minutes, costs nothing.
Make your plan →
Where your recovery codes and account list actually belong.
Build your list →
The calm response guide for fraud and identity theft.
Get the response guide →
This page was last reviewed in July 2026. Digital guidance changes faster than most preparedness topics. If that date is more than a year old, confirm key steps against the sources above before acting on them.
Enough for now
Look at this again once a year, or when anyone in the household gets a new phone.