A safer start for online accounts: passwords and a second verification step
← Back to blog

A safer start for online accounts: passwords and a second verification step

Technology Informational article

Consider passwords, recovery and device access together without making account security unnecessarily complicated.

An appointment account may contain personal details and messages. Choosing an easy-to-remember password alone is therefore not a complete security approach. Think about the whole process, from signing in to recovering access, rather than one setting.

Use a different password for each account

Reusing passwords can allow a breach at one service to put other accounts at risk. A trustworthy password manager is one way to store strong, different passwords. Avoid putting them in group chats or open note files. Consider carefully whether automatic sign-in is appropriate on a shared device.

Enable a second factor

Turn on multifactor authentication where the service supports it. Learn which methods are offered and how recovery works. Keep recovery codes somewhere protected. If you did not request a code, or someone calls asking for it, stop and check your account through its official access route.

Review one important account first

Is the registered email current? Are old devices still connected? Can you access recovery information? Understand which changes will sign you out before making them. A recovery plan helps prevent a security improvement from accidentally locking you out.

Know the limits

No method offers absolute security. Updates, device locks and caution around unusual messages still matter. Do not send a supposed support agent your password or one-time code. Separate legitimate assistance from unexpected requests for credentials.

Sources and further reading

CISA — Use Strong Passwords

https://www.cisa.gov/secure-our-world/use-strong-passwords

CISA — Turn On MFA

https://www.cisa.gov/secure-our-world/turn-mfa