Skip to main content
All lessons
Lesson 2Accounts & Identity pathway

Protect Your Accounts

Unique. Layered. Recoverable.

Highlighted wordsare glossary terms — tap one for a plain-language definition.

Good digital hygiene means building a few protective habits that stay useful even as the technology changes. For accounts, the whole idea fits into three words. Unique: important accounts don't share a password. Layered: use the strongest practical sign-in the service offers. Recoverable: keep a safe way for you — the real owner — to get back in.

One account. One lock.

Reusing a password means a break-in somewhere unimportant can become a problem somewhere that matters. Criminals use automated systems to try stolen email-and-password combinations on other websites — this is called . So a password exposed at one company can threaten your other accounts if you reused it. The fix isn't heroic: it's one lock per door.

  • Give every important account a credential used nowhere else.
  • Where a service offers a , consider it instead of relying only on a reusable password.
  • Adding a “1” or “!” to the end does not make it a different password.
  • Start with email, banking, and your — then work outward.

Long. Unique. Never reused.

Password strength is mostly about length and uniqueness, not about forcing in an uppercase letter, a digit, and a symbol. Composition rules push people toward predictable patterns, and calendar-based changes every 30, 60, or 90 days mostly produce a bumped number on the end. Current NIST guidance asks services to drop both, and to screen new passwords against lists of previously breached ones instead.

  • If you create a password yourself, make it long and unique — aim for at least 15 characters.
  • A passphrase of several unrelated words is easy to remember and long by nature.
  • Change a password when there's a reason — suspected compromise, a breach notice, or a policy that requires it — not on a schedule.
  • Skip security questions where you can, or answer them with random text stored in your password manager.

What a password manager actually does

A password manager generates and stores different passwords for your accounts so you do not have to memorize dozens of unrelated passwords. For most accounts, letting a reputable manager generate a long, random, unique password is easier and safer than inventing one yourself. It also fills passwords only on the matching website, which quietly catches some lookalike pages.

  • Look for one that works across your devices and generates unique passwords.
  • It should support secure sync, on the vault itself, and passkeys where available.
  • Check that its recovery options make sense to you before you rely on it.
  • The best one is the one you will realistically use every day.

What is a passkey?

A passkey lets your device prove that you are authorized to enter an account without requiring you to type a reusable password into the website. You may unlock a passkey using your fingerprint, face, device PIN, or another device-level method. Passkeys are designed to resist many common attacks, because the important credential is tied to the legitimate service rather than something you type into a convincing fake login page. Passwords haven't disappeared — most of us live in a mixed environment of passwords, password managers, passkeys, authenticator apps, device approvals, security keys, and SMS codes.

  • Hygi Habit: if an important account offers a passkey, don't dismiss it just because it's unfamiliar — read what the service is offering and decide whether it suits you.
  • Keep a screen lock on any device that holds passkeys.
  • Set up a second sign-in method so a lost device doesn't lock you out.
  • A passkey is not just another password — there is nothing reusable to type or hand over.

The MFA ladder: pick the strongest practical rung

Strongest practical protection: passkeys or / security keys — these are designed to resist phishing because authentication is connected to the legitimate service. Strong: authenticator apps and secure device-approval methods — substantially more protection than a password alone, though manually entered one-time codes can still be stolen through phishing. Better than a password alone: SMS/text — real protection compared with password-only login, but more vulnerable than phishing-resistant methods. If a stronger practical method is offered, consider using it.

  • Turn on the strongest option each service actually supports.
  • Never turn SMS codes off if the alternative is password-only sign-in.
  • Manually typed authenticator codes are strong, but they are not phishing-resistant.
  • No method makes an account unhackable — layers reduce risk substantially, and that's the goal.

A verification code is a key.

A code sent to you is for you to enter — not for a stranger to collect. Say you get a call claiming to be from your bank, and during the call a six-digit code appears on your phone; the caller asks you to read it aloud. That is the moment to stop. Do not provide the code. End the incoming communication and contact the bank yourself using a number or app you already trust. Pause. Leave the message. Verify.

  • Only enter a code into a page or app you opened yourself.
  • No legitimate representative needs you to read a code back to them.
  • If a login-approval prompt appears and you did not start a login, do not approve it just to make it stop.
  • Repeated unexpected prompts () usually mean someone has your password — change it from a trusted device.

Your master key account

Your primary email account may be used to reset passwords for many other services. That makes it one of the most important accounts to protect. Your primary email password should never be reused anywhere else.

  • Give it a unique credential, and add a passkey if the provider offers one and it suits you.
  • Turn on the strongest MFA it supports.
  • Keep the recovery phone and recovery email current, and save any recovery codes it offers.
  • Read unexpected sign-in alerts instead of dismissing them — check the account through the app, not the alert's link.

The Hygi Five-Door Reset

You don't have to secure every account today. Start with five accounts that would matter most if someone else gained access, and run each through Unique, Layered, Recoverable.

These checkboxes stay on this device. Never type an account name, password, passkey, verification code, or recovery code into Hygi.

0 of 15 checks done

  1. 1. Primary email

    The inbox that resets everything else.

  2. 2. Primary bank

    Day-to-day money.

  3. 3. Investment or retirement account

    Hard to unwind if lost.

  4. 4. Password manager or main credential system

    The vault that holds the rest.

  5. 5. One account that matters most to you

    Cloud photos, a health portal, insurance, main social media, a business or utility account — your call.

Brought to you by NorthBridge

Unfamiliar term? Open the Digital Safety Glossary