You don’t have to be a computer expert to make life a whole lot harder for scammers.
Someone gets into your Facebook account.
Someone tries to reset your email password.
Your bank texts you about a purchase you didn’t make.
Or you get a letter thanking you for applying for a credit card you most definitely did not apply for.
This is generally the point when people decide they should probably get serious about online security.
Unfortunately, that’s a little like buying a fire extinguisher while the kitchen is on fire.
The better time is before somebody gets in.
And here’s the good news: You don’t need to understand hacking, encryption or whatever they’re doing in those movies where someone types furiously for 11 seconds and announces, “I’m in.”
Most of us can dramatically improve our security with a handful of pretty simple changes.
The goal isn’t to make yourself impossible to hack. That’s not a realistic promise.
The goal is to put enough locks on the doors that when a criminal comes rattling the handles, yours aren’t the easiest ones on the block.
Here are eight places to start.
1. PROTECT YOUR EMAIL FIRST
YOUR EMAIL IS THE MASTER KEY
If you only secure one account today, make it your email.
Why?
Think about what happens when you forget a password.
Facebook sends a reset link to your email.
Amazon sends one to your email.
Your shopping accounts, utilities and dozens of other services do the same thing.
If a criminal controls your email, they may be able to use it to reset passwords on other accounts. The Federal Trade Commission specifically warns that email can become the weak link because password-reset messages frequently go there.
So start here.
Change your email password to something long and unique — meaning you aren’t using the same password anywhere else.
Then turn on multi-factor authentication, which we’ll get to next.
And make sure the recovery phone number and backup email attached to the account are still yours.
That old Yahoo address you haven’t opened since 2011 probably shouldn’t be responsible for rescuing your digital life.

2. TURN ON MULTI-FACTOR AUTHENTICATION
A PASSWORD SHOULDN’T BE THE ONLY THING STANDING BETWEEN A CROOK AND YOUR ACCOUNT
Multi-factor authentication goes by several names:
MFA.
Two-factor authentication.
2FA.
Two-step verification.
They all mean roughly the same thing: Your password alone isn’t enough to get into the account.
After entering your password, you have to prove it’s really you in another way.
Maybe you enter a code.
Maybe you approve the login on your phone.
Maybe you use an authenticator app, passkey or physical security key.
That’s incredibly valuable because if somebody steals your password, they still have another locked door in front of them. The FTC and CISA both recommend MFA as an important additional layer of account protection.
Turn it on first for your most important accounts:
Email. Banking. Credit cards. Facebook and other social media. Amazon and other shopping accounts.
When you’re given a choice, authenticator apps, passkeys or security keys generally provide stronger protection than a code sent by text. But don’t let perfect be the enemy of good: CISA’s guidance is essentially that stronger MFA is preferable, but any MFA is better than none.
One more thing:
Never give someone your verification code.
Not somebody claiming to be from the bank.
Not “Facebook support.”
Not the nice gentleman on the phone who says he needs the six-digit number you just received to secure your account.
That code is frequently the very thing standing between the scammer and your money or account. The FTC warns consumers not to share those verification codes.
If somebody asks you to read one back to them, hang up.
3. STOP REUSING PASSWORDS
ONE STOLEN PASSWORD SHOULDN’T UNLOCK YOUR WHOLE LIFE
Let’s say your favorite obscure shopping website gets hacked.
That’s bad.
But you used a different password there, so the damage is limited.
Now let’s say you used the same password for:
Your email.
Facebook.
Amazon.
Your credit card.
And your bank.
That’s considerably worse.
Criminals know people reuse passwords. A stolen username-and-password combination can be tried on other sites.
That’s why every important account should have its own password. The FTC specifically recommends not reusing passwords across accounts.
Yes, I know what you’re thinking.
“How in the world am I supposed to remember 63 different passwords?”
You’re not.
Which brings us to Step 4.
4. USE A PASSWORD MANAGER
BECAUSE “FLUFFY123” HAS HAD A GOOD RUN
A password manager stores your passwords so you don’t have to remember every single one.
That allows you to create long, unique passwords for different accounts instead of relying on the same three passwords you’ve been rotating since the George W. Bush administration.
Many phones and browsers already offer built-in password-management tools, and there are dedicated password managers as well. The FTC recommends password managers as a way to create and keep track of passwords.
You will still need to protect the password manager itself very carefully.
Use a strong, unique master password.
Turn on MFA for it.
And don’t put the master password on a Post-it note stuck to the laptop labeled:
PASSWORD.
We’re trying to make progress here.

5. FREEZE YOUR CREDIT
PUT A PADLOCK ON NEW CREDIT ACCOUNTS
This is one of the best identity-theft protections available, and an astonishing number of people don’t use it.
A credit freeze restricts access to your credit reports.
Why does that matter?
Because when somebody tries to open a new credit card or loan in your name, the lender generally wants to look at your credit report first.
If your credit is frozen, that creates a major roadblock for an identity thief trying to open a new account using your information. The FTC calls a credit freeze one of the best protections against someone opening new accounts in your name.
And here’s the part many people don’t know:
It’s free.
Free to place.
Free to lift.
It doesn’t hurt your credit score, and the freeze stays in place until you remove it.
To fully freeze your credit, you’ll need to do it separately with all three major credit bureaus:
Equifax
Experian
TransUnion
If you’re planning to apply for a new credit card or loan, you can temporarily lift the freeze and put it back afterward.
Think of it as locking the front door.
You can still open the door when you want somebody to come in.
You’re just making it considerably harder for a stranger to let himself in.

6. SET UP YOUR RECOVERY OPTIONS NOW
DON’T WAIT UNTIL YOU’RE LOCKED OUT
Go to the security settings for your important accounts and check the recovery information.
Is the phone number correct?
Is the recovery email still active?
Did you set it up 12 years ago using a work email from a company that no longer exists?
Fix that now.
Some services also give you recovery or backup codes when you turn on multi-factor authentication.
Those can save you if you lose your phone or can’t use your normal authentication method.
If you’re given recovery codes, store them somewhere safe.
Not in a publicly accessible document.
Not in an email titled MY FACEBOOK BACKUP CODES.
And probably not in the phone case attached to the phone whose loss would require you to use them.
The goal is to have a backup plan before you need the backup plan.
7. TURN ON ALERTS AND PAY ATTENTION TO THEM
LET YOUR ACCOUNTS TATTLE
Your bank and credit-card company may be willing to tell you almost immediately when something happens.
Let them.
Look through your account’s notification settings.
Depending on the company, you may be able to get alerts for things like:
Purchases.
Large transactions.
Online purchases.
Password changes.
New logins.
Money transfers.
These alerts don’t prevent every crime, but they can help you spot suspicious activity quickly.
And don’t ignore security emails saying someone logged into your account from a new device.
Sometimes that’s just you signing into a new phone.
Sometimes it isn’t.
Check.
8. STOP CLICKING THE LINK
YOU ARE ALLOWED TO GO AROUND
Here’s one of the easiest security habits you can develop:
When an unexpected email or text says there’s a problem with an important account, don’t use the link in the message to fix it.
Your bank texts:
SUSPICIOUS ACTIVITY! CLICK HERE!
Don’t click there.
Open the bank’s app yourself.
Or type the bank’s address into your browser yourself.
Or call the number printed on the back of your card.
Same goes for Amazon, Facebook, PayPal, your email provider and practically everything else.
Phishing messages are designed to make you panic and act before you think. The FTC warns that phishing scams commonly use unexpected messages and links to steal information.
Slow down.
Go around the message.
If the warning is legitimate, the problem will still be waiting for you when you log into the real account.
And if a message says your account will be permanently closed in the next 11 minutes unless you IMMEDIATELY CLICK HERE?
That is an excellent time to become suspicious.
YOU DON’T NEED A FORTRESS. YOU NEED LOCKED DOORS.
There is no magic setting that makes identity theft, hacking and scams disappear.
But look at what you’ve accomplished with these eight steps.
Your email — the key to many of your other accounts — has stronger protection.
One stolen password no longer unlocks everything.
A criminal who does get your password still has to get past MFA.
Your credit reports are frozen, making it harder to open new credit in your name.
Your recovery information is ready before an emergency.
Your accounts can alert you when something suspicious happens.
And you’re no longer blindly clicking links every time an alarming text tells you the sky is falling.
That’s a lot of protection without learning a single line of computer code.
Cybersecurity doesn’t have to mean becoming the person in the movie staring at six monitors in a dark room.
For most of us, it starts with something much less exciting:
Lock the doors. Stop giving everybody the same key. And don’t open the door just because somebody knocks really loudly.