Start by securing your email and financial accounts: access to them can expose sensitive information or help unlock other services. Turn on multifactor authentication (MFA), use a long, unique password for every account, keep your devices and software updated, and treat suspicious messages as potential phishing. The exact settings labels and sign-in options vary by provider.
What security settings should I change on my accounts?
Work through these protections first on email, financial, and healthcare accounts, then apply them to other important services. Menu names differ, but security controls are generally found in account or profile settings under a heading such as Security or Password and security.
- Enable MFA wherever the service offers it.
- Choose the strongest supported MFA method you can use reliably.
- Set a unique, random password for each account and manage those passwords with a password manager.
- Turn on automatic software updates where practical for the devices and software you use to access accounts.
- Recognize and report phishing instead of responding to suspicious requests or prompts.
How to turn on MFA
MFA—also called two-factor authentication or two-step verification—requires an additional proof of identity beyond a password. CISA advises turning it on for every account or app that offers it. Its general setup guidance is to open account or profile settings, locate the security area, enable MFA, and select one of the methods that the service supports. CISA’s MFA setup guidance explains the process.
Start with email because it may be used to reset passwords for other accounts. Next, secure financial and healthcare accounts, followed by other services where losing access or exposing information would matter. Do not assume that a method or menu available on one service is available on another.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
Which MFA method should I choose?
Prefer a phishing-resistant option when the service supports it and it works with the devices you use. CISA identifies FIDO/WebAuthn as phishing-resistant and recommends planning toward it. If it is not available, CISA discusses number matching as a stronger interim option than an ordinary mobile push approval. Any MFA is better than leaving an account protected only by a password. See CISA’s guidance on MFA methods.
Compare the choices the account actually offers:
- Phishing resistance: FIDO/WebAuthn is the strongest choice identified in CISA’s guidance.
- Compatibility: Confirm that the account supports the method and that it works with your devices.
- Practical use: Choose an option you can use consistently rather than disabling MFA because the method is inconvenient.
- Access consequences: Consider what happens if you lose access to the authenticator or physical key. Recovery procedures depend on the provider, so consult that service’s instructions.
A compatible hardware security key is one possible FIDO/WebAuthn option. Check that the account supports the key standard before buying; no single key should be assumed to work with every service.
Rank #2
Use strong, unique passwords with a password manager
CISA’s 2024 consumer tip sheet recommends passwords that are at least 16 characters long, random, and different for every account. A password manager can generate and remember them, avoiding the temptation to reuse one password or make small variations on it. Read CISA’s Secure Our World tip sheet for its password guidance.
Keep account-access software updated
Enable automatic updates where practical for the operating system, browser, and other software you use to access accounts. Updates can address software flaws that might expose files or accounts. CISA includes updating software among its core online-safety actions and advises, “Don’t delay software updates.” Updates complement MFA and strong passwords; they do not replace those account protections. See CISA’s Secure Our World guidance.
Free tools Windows power users keep installed
One-click scans. No signup required.
Recognize and report phishing
Be cautious with messages that create alarm, promise something implausibly attractive, request personal information, or urge you to download a file. An attacker may try to capture your credentials or trick you into approving a sign-in. Avoid engaging with suspicious requests; use the service’s established reporting option or follow its instructions for reporting phishing. CISA includes recognizing and reporting phishing among its core online-safety actions at Secure Our World.
Quick Recap
Rank #4
Make the changes in a sensible order
- Secure your email account with a unique password and MFA, choosing the strongest supported method you can use.
- Repeat those changes for financial and healthcare accounts, then other important services.
- Use a password manager to replace reused or easily guessed passwords with random, unique ones of at least 16 characters, following CISA’s 2024 guidance.
- Enable automatic updates for the software and devices used to sign in, where practical.
- Report suspicious messages rather than following links, downloading unexpected files, or approving sign-in prompts you did not initiate.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

