SECURE YOUR ACCOUNTS

Choose the account. Follow the steps. Lock it down.

Practical, step-by-step security guidance for the accounts that matter most. You do not need to be a cybersecurity expert to follow the instructions.

BEFORE YOU BEGINSecure the accounts that protect everything else.

Your email, phone and recovery accounts can sometimes be used to regain access to other services. Protect the accounts with the greatest impact first.

The goal is not simply to turn on security settings. The goal is to understand what protects the account, make the appropriate changes and then verify that the protection is actually active.

What should I never share?
Never give anyone your password, OTP, PIN, recovery code, recovery phrase or private key. Legitimate support should not require these secrets.
Why verify after changing a setting?
A setting can appear to have been changed without giving you the protection you expected. Return to the account's security area and confirm that the feature is active.
01 · ACCOUNT SECURITY

What actually makes an account secure?

Account security is not one setting. It is a collection of protections that work together to reduce the chance of unauthorized access and limit the damage when something goes wrong.

SECURITY PRINCIPLEProtect access, recovery, connected devices and permissions.

An account can have a strong password and still be exposed through weak recovery methods, an unfamiliar active session or unnecessary third-party access.

EXAMPLE

Your email account may not contain money directly, but if it can be used to reset your banking, social-media or other important accounts, protecting that email account becomes especially important.

WHAT TO DOStart with your highest-impact accounts.

Identify the accounts that control money, identity, communication, recovery or access to other services. Secure those first.

02 · CORE SECURITY LAYERS

Six protections worth checking.

Work through these one at a time. Understand the purpose of each protection, make the change and then verify the result.

01

Strong, unique passwords

KEY IDEAA password should protect one important account rather than several accounts at once.

Important accounts should not share the same password. A password manager can make unique passwords easier to create and manage.

EXAMPLE

Using one password for email, banking and social media means one compromised password can create several account problems.

WHAT TO DO

Create a unique password for important accounts and store it securely.

Learn more about password security
Why this matters
These protections address different ways an account can be accessed, recovered, monitored or misused. Together they create a stronger security posture than relying on one setting alone.
02

Multi-factor authentication

KEY IDEAA password is not the only layer that can protect an account.

Enable MFA where available and use a stronger authentication method where the service supports one.

EXAMPLE

If someone obtains your password, an additional authentication factor can provide another barrier to account access.

WHAT TO DO

Open the account's security settings and confirm that MFA is enabled and working.

Learn more about MFA
Why this matters
These protections address different ways an account can be accessed, recovered, monitored or misused. Together they create a stronger security posture than relying on one setting alone.
03

Recovery methods

KEY IDEAAccount recovery can become another route into the account.

Check that recovery email addresses, phone numbers, backup codes and other recovery methods are current and under your control.

EXAMPLE

An old phone number or recovery email that you no longer control can create problems when you need to recover the account.

WHAT TO DO

Review every recovery method and remove or replace information you no longer control.

Learn more about recovery methods
Why this matters
These protections address different ways an account can be accessed, recovered, monitored or misused. Together they create a stronger security posture than relying on one setting alone.
04

Devices and active sessions

KEY IDEAYour account should not remain accessible from devices or sessions you do not recognize.

Review the devices and sessions connected to the account and investigate anything unfamiliar.

EXAMPLE

An unfamiliar browser session, phone or computer may indicate that someone else has accessed the account.

WHAT TO DO

Review active sessions regularly and sign out of devices or sessions you no longer trust.

Learn more about active sessions
Why this matters
These protections address different ways an account can be accessed, recovered, monitored or misused. Together they create a stronger security posture than relying on one setting alone.
05

Connected applications

KEY IDEAThird-party access can remain active even when you are no longer using the service.

Review applications and services that have access to the account and remove permissions you no longer need.

EXAMPLE

An old application may still have permission to read information or perform actions on your behalf.

WHAT TO DO

Review connected applications and revoke access that is unnecessary or unfamiliar.

Learn more about connected apps
Why this matters
These protections address different ways an account can be accessed, recovered, monitored or misused. Together they create a stronger security posture than relying on one setting alone.
06

Security alerts

KEY IDEAEarly notification can give you an opportunity to respond before a problem becomes worse.

Enable appropriate login and security notifications so unusual activity is easier to notice.

EXAMPLE

A notification about a new login from an unfamiliar device may be the first indication that something needs investigation.

WHAT TO DO

Turn on relevant security alerts and pay attention to unexpected notifications.

Learn more about security notifications
Why this matters
These protections address different ways an account can be accessed, recovered, monitored or misused. Together they create a stronger security posture than relying on one setting alone.
03 · SECURITY SECRETS

Some information should stay under your control.

Account security also depends on knowing what information should never be handed to another person, even when the person claims to be helping you.

SECURITY WARNINGNever share passwords, OTPs, PINs, recovery codes, recovery phrases or private keys.

Someone who has one of these secrets may be able to access an account, approve an action or take control of assets.

If someone asks you to reveal a security secret so they can “verify,” “unlock,” “restore” or “protect” your account, stop and verify the request through an independent official channel.

What about customer support?
Legitimate support processes may ask you to confirm information through approved procedures, but your password, OTP, PIN, recovery phrase and private key should remain under your control.
04 · SEE THE DIFFERENCE

One account. Two very different security approaches.

Good security is easier to understand when you compare what happens when important protections are missing with what happens when they are properly maintained.

WITHOUT PROTECTION
Reused password
Recovery information is outdated
Unknown sessions remain active
Unnecessary applications retain access
Security alerts are ignored
WITH PROTECTION
Unique password
Recovery methods are current
Active sessions are reviewed
Unnecessary access is removed
Important security alerts are noticed
Understand → Change → Verify → Maintain
05 · ACCOUNT SECURITY LIBRARY

What do you want to secure?

Choose the type of account you want to protect. Detailed guides will walk you through the relevant security and privacy settings.

Messaging

Protect conversations, linked devices and account recovery methods.

View available guides
VERIFYUse the guide for the specific service.

Security settings are not identical across platforms. Follow the instructions for the service you are actually using.

Social media

Protect your account access and control how much personal information you expose.

View available guides
VERIFYUse the guide for the specific service.

Security settings are not identical across platforms. Follow the instructions for the service you are actually using.

Phone & device accounts

Protect the accounts that control access to your phones, computers and connected devices.

View available guides
VERIFYUse the guide for the specific service.

Security settings are not identical across platforms. Follow the instructions for the service you are actually using.

Crypto accounts & wallets

Protect crypto exchange accounts and self-custody wallets without ever exposing your private credentials.

View available guides
VERIFYUse the guide for the specific service.

Security settings are not identical across platforms. Follow the instructions for the service you are actually using.

Password managers

Protect the service that may hold the keys to many of your other accounts.

View available guides
VERIFYUse the guide for the specific service.

Security settings are not identical across platforms. Follow the instructions for the service you are actually using.

Cloud storage

Protect documents, photographs, backups and other information stored online.

View available guides
VERIFYUse the guide for the specific service.

Security settings are not identical across platforms. Follow the instructions for the service you are actually using.

06 · VERIFY THE RESULT

Don't stop after changing the setting.

A security change is only useful if the protection is actually active and the account remains under your control.

IN SIMPLE TERMS

Don't assume that because you clicked a button, your account is now protected exactly as expected.

WHAT TO DOVerify the protection.

Return to the account's security settings. Confirm MFA, recovery information, active sessions, connected applications and security notifications where applicable.

SECURITY PRINCIPLEDon't trust the appearance of security. Verify the protection.

This is the same principle that guides everything on VERIFY BEFORE YOU TRUST.

SECURITY WARNINGSomething already looks wrong?

If you discover an unfamiliar device, unexpected login, changed recovery information or another sign of possible compromise, do not treat it as an ordinary security check.

I think my account is compromised →
APPLY WHAT YOU LEARNED

Turn account security into a repeatable habit.

Security is not a one-time activity. Accounts change, devices change, applications are connected and recovery information can become outdated.

How often should I review my accounts?
Review important accounts whenever something significant changes, such as getting a new phone, changing a recovery method, connecting a new application or noticing an unexpected security alert. Periodic reviews are also useful for high-impact accounts.
What if I am not sure what needs attention first?
Start with the accounts that could cause the greatest harm if compromised: accounts connected to money, identity, communication, recovery or other important services.
THE VERIFY BEFORE YOU TRUST PRINCIPLEVERIFY BEFORE YOU TRUST.

A familiar service, professional-looking security page or reassuring message is not proof that an account or request is safe. Understand what you are being asked to do, verify the important details and then act.

Not sure what needs attention first?

Use the Security Assessment to identify practical weaknesses and decide which areas of your digital security deserve priority.

Run my Security Assessment →
Need help beyond the guide?

If you cannot safely resolve an account-security problem yourself, use the appropriate official support channel or request professional assistance.

Never give your passwords, OTPs, PINs, recovery phrases or private keys to someone simply because they claim they can help.

Request Professional Help →

VERIFY BEFORE YOU TRUST.