The goal is not to memorize dozens of complicated strings. It is to prevent one stolen password from opening every important account while ensuring the owner can still get back in after a lost phone, forgotten master password, or emergency.
Use a reputable password manager built into the device or chosen deliberately. It can create and store unique passwords, fill them only on matching sites, and synchronize them across approved devices.
Secure the accounts that control everything else
Start with email, Apple or Google account, phone carrier, banking, primary social accounts, and the password manager itself. Email is critical because many services send recovery links there. The mobile carrier matters because phone numbers can be used for verification.
Change reused passwords on these priority accounts first. Do not try to fix 80 accounts in one afternoon.
Choose and configure a password manager
- Review the manager already available on the phone or computer.
- Protect the device with a strong passcode and biometrics where appropriate.
- Create a long, unique master password if the manager requires one.
- Save one low-risk account and practice filling it.
- Confirm how the vault is backed up and recovered.
- Sign out of a test account, then sign back in using the manager.
Do not give a helper permanent vault access merely because they assisted with setup.

Make every account password unique
Let the manager generate long random passwords. Unique matters more than inventing a clever pattern. Adding a site name to the same base password still creates a predictable family of credentials.
When a site forces a memorable password, use a long passphrase unrelated to public facts. Avoid names, birthdays, addresses, pets, and phrases visible on social media.
Add multifactor authentication
MFA requires another proof after the password. Prefer a passkey, security key, or authenticator app when the service supports it; text codes are still better than password-only access but can be vulnerable to phone-number takeover.
Never read a one-time code to an unexpected caller. A genuine employee should not need the code that authorizes your login or payment.
| Method | Strength | Recovery consideration |
|---|---|---|
| Passkey | Strong and phishing-resistant on supported services | Keep account/device recovery current |
| Security key | Strong physical factor | Register a spare and store it separately |
| Authenticator app | Stronger than SMS in many cases | Back up or transfer before replacing phone |
| Text message | Widely available | Protect carrier account and SIM |
| Email code | Depends on email security | Secure email with its own MFA |
Store recovery codes safely
Many services issue one-time recovery codes. Print or write them clearly and store them in a secure physical location separate from the primary device. Do not photograph them into an ordinary photo library or email them to yourself.
Record which account each code belongs to and the date generated. When new codes are issued, destroy the obsolete set.
A paper record can be part of the plan
For some people, a locked paper record at home is safer than reused passwords or loose sticky notes. It should not travel with the device or sit beside the computer. Record the service name and recovery instructions, and decide carefully whether to record full passwords.
The plan should match real risks: who enters the home, whether evacuation is possible, and who may need legitimate access.
Give a trusted person a role, not ownership
Choose whether anyone should have emergency access. Some password managers support delayed or designated access; legal estate plans can also name a digital executor. Explain the scope and keep consent documented.
A helper should never change recovery email, phone, or password to their own information without explicit authorization. The owner should receive every security alert.
Recognize a phishing login
Do not sign in through an unexpected email or text link. Open the known app or type the official address. Check the domain, not just the logo. Password managers add protection because they usually refuse to fill credentials on a mismatched domain, but they are not infallible.
Ignore calls claiming an account is compromised while demanding remote access, money, or a code. End the call and contact the company independently.
Review after a breach or device change
Change the affected password, revoke unknown sessions, review recovery details, and check recent activity. If the password was reused, change every reuse. Before replacing a phone, transfer authenticator accounts and verify recovery methods.
Quarterly, review the six priority accounts, software updates, backup access, and trusted-person plan. A strong system is one the owner can explain and recover without improvisation.