Why this matters
Your email, bank and work accounts hold the keys to your money, identity and business data. Most account takeovers use stolen or reused passwords, so a short review of your most important accounts dramatically lowers your risk.
What you'll need
- A list of your most important accounts
- Your mobile phone
- Optional: a password manager
Step-by-step instructions
Step 1
List your most important accounts
Start with the accounts that would cause the most harm if someone else took control.
- Primary email accounts
- Banking and myGov
- Microsoft 365 or Google Workspace
- Social media and online shopping
Step 2
Give each account a unique passphrase
Replace reused or short passwords, starting with email. A password manager makes this practical.
Step 3
Turn on multi-factor authentication
Look for "Two-step verification", "2FA" or "MFA" in each account’s security settings. An authenticator app is stronger than SMS codes.
Step 4
Update recovery details
Check that the recovery phone number and backup email are current and belong to you. Attackers often change these to lock you out.
Step 5
Review active sessions and connected apps
Most services list the devices that are signed in and the third-party apps with access. Sign out anything you do not recognise and remove apps you no longer use.
Step 6
Turn on sign-in alerts
Enable email or app notifications for new sign-ins so you find out quickly if someone else gets in.
Summary
Unique passwords, MFA and current recovery details on your key accounts close the doors attackers use most often. Repeat this review every six months.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.