I’m going to tell you something you already know but have been ignoring: that password you’ve been using since 2015 is a security disaster waiting to happen. The one that’s your dog’s name plus your birth year? Yeah, that one. Hackers figured out that pattern about a decade ago.
But here’s the good news — fixing your password situation isn’t as painful as you think. Let’s walk through what actually matters and skip the paranoia-inducing stuff that doesn’t.
The Only Password Rule That Really Matters
Forget everything you’ve heard about needing uppercase, lowercase, numbers, and the blood of a unicorn. The single most important thing is this: use a different password for every account.
When a company gets breached (and they all do eventually), hackers take those stolen email/password combinations and try them everywhere else. Same password for your email and your bank? Congratulations, you’ve just made a criminal’s day.
The solution is stupidly simple: get a password manager. I recommend Bitwarden (free) or 1Password (worth the $36/year). These tools generate random passwords, remember them for you, and auto-fill them when you need them. You only memorize one master password. Done.
Two-Factor Authentication: Your New Best Friend
Two-factor authentication (2FA) means that even if someone steals your password, they still can’t get in without a second verification — usually a code sent to your phone or generated by an app.
Enable this on everything important:
- Email (this is the big one — your email can reset every other password)
- Banking and financial accounts
- Social media
- Any account with your credit card stored
Skip the SMS text codes if you can — they’re better than nothing but can be intercepted. Use an authenticator app like Google Authenticator, Microsoft Authenticator, or Authy instead. Takes five minutes to set up, works forever.
The Three Accounts You Need to Secure Right Now
If you’re overwhelmed, start with these three. Secure them today, and you’ve eliminated about 80% of your risk:
- Your primary email — This is the skeleton key to your digital life. Strong unique password plus 2FA, no exceptions.
- Your bank or primary financial account — Self-explanatory. Check if your bank offers additional security features like login alerts.
- Your phone’s account (Apple ID or Google) — Your phone knows everything about you. Protect the account that controls it.
Once those are locked down, work through your other accounts at a pace that doesn’t make you want to throw your laptop out the window.
What to Do If You Think You’ve Been Compromised
If you get a suspicious email about a login you didn’t make, or you notice weird activity on an account:
- Change the password immediately (from a different device if possible)
- Enable 2FA if you haven’t already
- Check for any changes to recovery email addresses or phone numbers
- Review recent account activity for anything you didn’t do
Most account takeovers happen because people ignore the warning signs. Don’t be that person.
When to Call in Backup
If you’re a business owner managing accounts for your company, employees, or clients, the stakes are higher than your personal Netflix getting hijacked. At On Your Side Technologies, we help organizations audit their security practices and implement protections that actually work — without turning your office into a bureaucratic nightmare.
But whether you work with us or handle it yourself, the takeaway is the same: password manager, two-factor authentication, and start with your three most critical accounts. That’s it. That’s the whole game plan.
Your future self — the one who doesn’t have to spend a weekend recovering hacked accounts — will thank you.
Want to talk it through? I keep a few virtual coffee spots open each month — grab one while they’re available → Book a virtual coffee
Photo by Glenn Carstens-Peters on Unsplash





