Password & Account Security Checklist
The habits that matter, in order of how much they protect you. Print it, work through it once, and it stays done.
BFCBrilliance · bfcbrilliance.com/tools/password-generator
Do these first
- Put a password manager on every device you use
- Turn on two-factor authentication for your email before anything else
- Change any password reused across more than one account
- Check your email address on a breach-notification service
- Set recovery codes aside somewhere offline
- Review which apps and services can sign in with your Google or Apple account
The accounts to secure in this order
- Email - every other reset flows through it
- Password manager itself
- Banking and payments
- Phone carrier account - the weak point in SMS two-factor
- Cloud storage and photo backups
- Social accounts tied to your real name
- Anything holding a saved card
What actually helps
- Sensible default length
- 16 characters
- For your most important accounts
- 24 characters
- Letters and digits only
- use 32 characters
- Matters most
- unique per account
- Matters next
- length
- Matters least
- exotic symbols
- Rotate on a schedule?
- No - only when there is a reason
- Strongest second factor
- app or hardware key, not SMS
Recovery notes (keep this sheet somewhere safe)
- Password manager
- Recovery kit stored at
- Two-factor backup codes at
- Emergency contact
- Date last reviewed
The one rule that beats all the others
A unique password per account matters more than how clever any single one is. Reuse is what turns one company's breach into someone reading your email, and no amount of length or symbols protects against it.