Home Self-reliance Digital Life Account security

Digital Life · Protect

Lock down the accounts that matter most.

Not all accounts are equal. This guide works in the order that protects your household fastest: email, then money, then everything else.

Why email comes first

One account resets all the others.

When you forget a password anywhere, the reset link goes to your email. The FTC puts it plainly: a criminal who takes over your inbox can request reset links for your other accounts, change those passwords, and take them over too.[1]

That makes email your household's master key. Two steps protect it: a long password used nowhere else, and two-step verification. Do those tonight, for every adult's email, and the most damaging failure mode is closed.

Then work outward. Financial accounts next, since that is where losses land. Everything else can wait for the password manager below.

Passwords that hold

Long beats complicated.

The federal password standard was rewritten around real evidence, and it now says the opposite of the old office rules.

NIST, the agency that sets the standard, dropped mandatory symbol-and-number rules and forced periodic changes. Length is what matters: when a password stands alone, the current guidance calls for at least 15 characters, and a passphrase of ordinary words beats a short string of symbols.[2]

A password should change for one reason only: evidence it was compromised. Routine forced changes push people toward predictable patterns, which is why the standard now prohibits them.[2]

The practical tool here is a password manager, an application that generates and remembers a long unique password for every account, locked behind one strong passphrase you memorize. The FTC recommends the approach for exactly this reason: unique passwords everywhere, without the memory burden.[3] Solid options run from free to roughly $60 a year for a family plan.

The one-evening version

Install a password manager. Set a long passphrase you can say out loud, four or five ordinary words. Move your email and bank logins into it first and let it replace both passwords with generated ones. Everything else migrates naturally as you log in over the next month.

The second lock

Two-step verification, then passkeys.

Two-step verification, often written as 2FA or MFA, means logging in takes your password plus one more proof, usually a code from your phone. CISA's guidance is direct: any form of it beats none, because a stolen password alone stops working.[4]

The forms are not equal. Codes sent by text message can be intercepted or phished. An authenticator app, a small free app that generates codes on your phone, is stronger. The FTC names authenticator apps and security keys as the more secure choices when a site offers them.[3]

The strongest option is a passkey. A passkey replaces your password with the way you already open your device, the same fingerprint, face, or PIN you use every day. There is no password to steal and nothing to type into a fake site, which is why CISA calls this class of sign-in the gold standard.[4] When an account offers a passkey, take it.

Priority order stays the same throughout: email first, financial accounts second, then anything holding your identity documents or photos.

Adjustments

Fitting this to your household.

Less technical adults

Set up the password manager together, at their pace, on their device. One session covering email and the bank is a complete win. Skip the lecture on everything else.

Shared household accounts

Streaming, utilities, and shopping accounts shared by the family belong in a shared vault inside the password manager, so nobody keeps a sticky note copy.

The paper fallback

Write the password manager's master passphrase and your email recovery codes on paper. Store the page with your household documents, where a trusted adult can find it.

Common mistakes

Four habits worth retiring.

Reusing one good password. One breach at any site turns that password into a key for all of them. Unique everywhere is the point of the manager.

Answering security questions honestly. Your mother's maiden name and first car are researchable. Treat the answers as extra passwords and store them in the manager.

Ignoring software updates. Updates carry the security patches. Turn on automatic updates and let the phone restart overnight.[3]

Stale recovery contacts. A recovery method pointing at an old phone number or dead email locks you out at the worst moment. Check yours once a year.

Next steps

Where to go from here.

Sources

  1. FTC. "Creating Strong Passwords and Other Ways To Protect Your Accounts." consumer.ftc.gov
  2. NIST. "Digital Identity Guidelines: Authentication and Authenticator Management." SP 800-63B Revision 4, 2025. csrc.nist.gov
  3. FTC. "Password Checklist." consumer.ftc.gov
  4. CISA. "Implementing Phishing-Resistant MFA." cisa.gov
  5. FBI Internet Crime Complaint Center. "2025 Internet Crime Report." ic3.gov

This page was last reviewed in July 2026. Digital guidance changes faster than most preparedness topics. If that date is more than a year old, confirm key steps against the sources above before acting on them.

Enough for now

You are prepared enough when...

  • You use a password manager, and it holds a unique password for your email and financial accounts.
  • Two-step verification is on for your email account.
  • Your recovery phone number and backup email are current, checked within the last year.
  • One other adult in your household can reach your account list if you cannot.

Look at this again once a year, or when anyone in the household gets a new phone.