Why Habits Matter More Than Tools

Digital security products — antivirus software, firewalls, VPNs — get most of the attention, but data breach investigations consistently show that compromised accounts usually come down to human habits, not missing technology. Reused passwords, delayed software updates, and clicking unfamiliar links are far more common entry points than sophisticated hacking.

The good news is that the habits which prevent the vast majority of account compromises are well understood, free to adopt, and don't require any technical knowledge. What they do require is consistency.

“Security is always excessive until it's not enough.”

— Robbie Sinclair, Head of Security, Country Energy (widely cited in cybersecurity education contexts)

The Core Practices That Actually Protect Accounts

The following practices are grounded in guidance from cybersecurity organizations including the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST). Each one addresses a real, common vulnerability.

1

Use a unique password for every account, no exceptions.

When a site you use suffers a data breach, attackers immediately try those leaked credentials on other sites — a technique called credential stuffing. If you've reused a password, one breach becomes many. Unique passwords ensure that a compromise on one site stays contained.

Example: Someone who uses the same password for their email, bank, and a streaming service becomes vulnerable on all three the moment any one of those services is breached.
2

Enable two-factor authentication (2FA) on every account that offers it.

Two-factor authentication (2FA) requires a second form of verification — typically a code sent to your phone or generated by an app — in addition to your password. Even if someone has your password, they can't log in without that second factor. CISA consistently lists 2FA as one of the highest-impact steps an average user can take.

Example: Enabling an authenticator app on your email account means that a stolen password alone is not enough for an attacker to access your inbox.
3

Use a password manager to generate and store strong, unique passwords.

Most people reuse passwords because memorizing dozens of unique, complex ones is genuinely impossible. A password manager solves this by generating and storing them securely, so you only need to remember one strong master password. Understand how password managers work before committing to one.

Example: With a password manager, your banking password can be a random 20-character string you never need to type or memorize yourself.
4

Learn to recognize phishing attempts before you click.

Phishing — messages that impersonate trusted organizations to steal your credentials or install malware — is one of the most common methods used to compromise accounts. The ability to pause and evaluate a message before acting is a learned habit that pays off consistently.

Example: An email claiming your account is suspended with a link to 'verify your information' should trigger scrutiny: go directly to the website by typing its address rather than clicking the link.
5

Audit which apps and services have access to your accounts periodically.

Over time, apps you've connected to your Google, Apple, or social media accounts accumulate permissions — even after you stop using them. Unused connections are unnecessary risk. Reviewing and revoking unused access is a simple form of ongoing hygiene.

Example: Checking your Google account's 'Third-party apps with account access' page once or twice a year can reveal forgotten services you connected years ago that still have permission to read your data.
6

Keep your email account security especially strong.

Your primary email address is the recovery mechanism for almost every other account you own. If an attacker gains access to your email, they can trigger 'forgot password' resets on your bank, social media, and other services. It deserves your strongest password and 2FA.

Example: Using an authenticator app (rather than SMS text codes) for your email account provides stronger protection, since SMS codes can be intercepted through SIM-swapping attacks.

Quick Wins You Can Apply Today

You don't need to overhaul your entire digital life to meaningfully improve your security. These steps can each be completed in a few minutes and have an immediate effect.

high Turn on two-factor authentication for your email account right now — go to your account's security settings and look for '2-Step Verification' or 'Two-Factor Authentication.'
high Check whether any of your passwords have appeared in known data breaches by visiting haveibeenpwned.com and entering your email address.
high Download a reputable authenticator app (such as those offered by major tech companies) and link it to your most important account today.
medium Go to your primary email or social media account settings and review which third-party apps have access — revoke any you no longer use.
medium Change the password on any account where you know you've reused the same password as another service.

For a deeper look at protecting the devices those accounts live on, see our everyday device security habits guide. And if you're ready to find gaps across all your accounts at once, the digital safety audit checklist is a practical next step.

Public Wi-Fi Adds Another Layer of Risk

Logging into accounts over public Wi-Fi at a coffee shop or airport isn't automatically dangerous, but it does introduce risks worth understanding. See what's actually at risk on public Wi-Fi and when extra caution makes sense. As a general rule, avoid logging into sensitive accounts like banking on networks you don't control.

Common Weak Points Worth Knowing

Even people who follow good password habits often overlook a few areas that attackers actively exploit.

80%+

Of breaches involving weak or reused passwords

Verizon's Data Breach Investigations Report has consistently found that a large majority of hacking-related breaches involve stolen or weak credentials.

99.9%

Of account compromise attacks blocked by MFA

Microsoft's security research has indicated that multi-factor authentication (MFA) can block the vast majority of automated account attacks.

Security questions are one example. Most answers — mother's maiden name, first pet, hometown — can be found through social media or public records. Learn safer alternatives to security questions that don't rely on guessable personal facts.

Social media oversharing is another overlooked risk. Details that seem harmless in isolation — your birthday, employer, neighborhood — can give scammers enough to guess passwords, answer security questions, or craft convincing phishing messages. See what personal details to keep off social media for specifics. You might also check which social media privacy settings matter most.

A Note on SMS-Based Two-Factor Authentication

Receiving 2FA codes via text message is significantly better than having no second factor at all. However, text-based codes can be intercepted through SIM-swapping — a scam where an attacker convinces your phone carrier to transfer your number to a device they control. Where accounts allow it, an authenticator app provides stronger protection than SMS codes.