Protect Your Accounts with Two-Factor Authentication
The single most effective step you can take to protect an account even if your password is stolen, with step-by-step setup for major platforms.
Two-factor authentication↗ (2FA) asks for a second piece of proof beyond your password when you sign in. That way, even if your password is somehow stolen, an attacker still can't get into your account. Setup takes a few minutes and it's one of the single most effective security steps you can take.
How does it work?
Authentication combines different types of proof: something you know (a password), something you have (your phone, a security key↗), and something you are (a fingerprint, your face). Adding a second factor means a single stolen password is no longer enough.
Start with your most critical accounts
You don't need to enable it everywhere at once, start with email, online banking, and social media. Your email is the key to your other accounts (password reset links go there), so protect it first.
Which method is more secure?
- Passkey↗ or hardware security key: the most phishing↗-resistant option available.
- Authenticator app: generates a code on your phone that refreshes every 30 seconds; works offline and is safer than SMS.
- SMS code: better than nothing, but vulnerable to SIM-swap fraud. Prefer an app-based method when you can.
Step-by-step setup
Google / Gmail account (Android and iPhone)
From the Google app or your browser: Google Account → Security → "2-Step Verification" → follow the on-screen steps. Adding an authenticator app (e.g. Google Authenticator) is recommended.
Apple ID (iPhone)
Settings → [your name] → "Sign-In & Security" → turn on "Two-Factor Authentication".
Instagram, Facebook, X and similar apps
Usually found under Settings → Account/Security → "Two-factor authentication". Choose "Authenticator app" as the method where available.
Keep your recovery codes safe
When you turn on 2FA, you're given backup↗/recovery codes, save them somewhere secure, such as a password manager↗. If you lose your phone, these codes let you back into your account. Where possible, set up a second verification method too (a backup email or a second device).
Pair it with a strong password
Two-factor authentication doesn't replace a strong, unique password, it complements it. Using both together makes your accounts far more resilient.
Related reading

