A plain-English guide to locking down your accounts with phishing-resistant multi-factor authentication and passkeys. No jargon, no SMS codes, no security background needed.
Free · Works for Microsoft 365, Google, Apple, and every account that matters
If an attacker gets into your email, they can reset the password on almost every other account you own: your bank, your payroll, your ad accounts, your customer records. The vast majority of business breaches start with one stolen or guessed password. A second factor is what stops a stolen password from becoming a stolen company.
Reused and breached passwords are bought and sold in bulk. Yours may already be circulating from a site you signed up for years ago and forgot about.
Even with your password in hand, an attacker cannot get in without the second factor that lives on your device. That is the whole point of MFA.
The data has been clear for years. The fastest, cheapest way for an attacker to get in is a stolen or reused password, and multi-factor authentication would have blocked most of those intrusions. It is now the baseline expectation for insurers, partners, and regulators alike.
If you do one thing for your security this quarter, make it this. Turn on a strong second factor everywhere it is offered, starting with your email.
Here is how a single compromised login cascades across a business.
A stolen login is often the attacker's first step inside. From one inbox they move sideways, find what matters, and deploy ransomware across the business. Most incidents start with a compromised account, not a movie-style hack.
The attacker sits quietly in your inbox, learns how you write and who pays you, then emails your client or your finance team as you and redirects a payment. BEC is one of the costliest crimes the FBI tracks.
Your email is the reset button for everything else. With it, an attacker walks into your bank, payroll, ad accounts, and password manager. One inbox becomes the keys to the company.
MFA breaks the chain at step one. Every one of these scenarios starts the same way: someone logs in as you with a password that was never meant to be enough on its own. An authenticator app or a passkey is the wall that stops a stolen password from ever becoming a stolen company.
SMS is better than no second factor. But if you are setting things up today, do it once and do it right, because text-message codes are the weakest option available.
An authenticator app generates a fresh six-digit code on your device every 30 seconds. Nothing travels over the phone network, so there is nothing to swap or intercept. It is free, takes two minutes to set up, and works offline. Popular options include Microsoft Authenticator, Google Authenticator, and Authy. If you use a password manager like 1Password or Bitwarden, it can hold these codes too.
Even stronger than any code is a passkey. It cannot be phished at all, and Microsoft, Google, and Apple all support it today. That is the next section, and it is the one to remember.
If you remember one thing from this page, make it this. A passkey is a cryptographic login tied to your device. You unlock it with your face, your fingerprint, or a small hardware security key. There is no code to type, so there is no code to phish or steal, and it simply will not work on a fake login page.
When you create a passkey, your device generates a matched pair of cryptographic keys. The private key never leaves your device. It lives in a protected area of the hardware (the secure enclave on Apple devices, the TPM on Windows, similar hardware on Android) and it is released only after you unlock it with your biometric or device PIN. The website only ever receives the public key, which is useless to a thief on its own. There is no shared secret, no password, and no code sitting in a database waiting to be breached.
Passkeys use an open standard called WebAuthn (part of the FIDO2 family) built on simple challenge-and-response:
A one-time random value that is only valid for this login attempt.
Face, fingerprint, or PIN. Your biometric never leaves your device or reaches the website.
The private key signs the challenge, bound to the real web address you are on.
It checks the signature against your public key. Match means you are in. Nothing reusable ever crossed the wire.
Whatever you do, do not rely on SMS text codes as your second factor. They can be SIM-swapped, intercepted, and phished in real time. Use a passkey where you can, an authenticator app where you cannot, and remove SMS everywhere a stronger method is offered.
There are two flavors, and the difference is about recovery versus assurance.
Stored in and synced across your devices by a provider such as iCloud Keychain, Google Password Manager, or a password manager like 1Password. If you lose a device, your passkeys are still available on the others. This is the right default for most people. The trade-off is that their safety now depends on the security of that platform account, so protect it with its own strong second factor.
Never leave the single device or hardware key they were created on. There is no cloud copy to compromise, which gives the highest assurance for high-risk accounts. The trade-off is recovery: if the device is lost and you registered no backup, you can be locked out, so always register a second key.
A hardware security key such as a YubiKey or a Google Titan key is a device-bound passkey in physical form. You tap or insert it to log in. For administrators, finance staff, and executives, whose accounts are the ones attackers hunt for, a pair of hardware keys (one to carry, one in a safe place as backup) is the strongest practical protection you can deploy today.
How to add one: in your account's security settings, look for "Passkey" or "Windows Hello / Face ID," choose to add it, and confirm with your biometric or device PIN. It takes under a minute. The setup wizard below walks you through it for Microsoft 365 and Google.
Reusing one password across accounts is the root cause of most takeovers: one site gets breached, and attackers try that same password everywhere else. A password manager fixes this by generating and storing a unique, strong password for every account, so a single leak can never cascade into your whole digital life.
Popular options include 1Password, Bitwarden, and the built-in Apple Passwords app. A good manager can also hold your authenticator (TOTP) codes and your MFA backup codes in one encrypted place, so your second factor and your recovery plan live somewhere you will actually find them. Put a passkey or an authenticator on the password manager itself, then let it carry the unique passwords for everything else.
Two lists. The first turns MFA on the right way. The second closes the tricks attackers use to get around it. Tap each item as you finish, then print or save the page as a PDF to circulate.
Pick the email you use for work. Tap each step as you finish it, and watch the bar fill.
On your phone, install Microsoft Authenticator (or Google Authenticator / Authy). It is free.
On a computer, go to aka.ms/mfasetup and sign in. This is your Microsoft "Security info" page.
Click "Add sign-in method," choose "Authenticator app," then "Work or school account." A QR code appears.
In the phone app tap the plus, choose "Work or school account," and scan the code on your screen. Approve the test prompt.
Set the authenticator app as your default sign-in method. If a phone-text method is listed, delete it so codes never go to SMS.
Back on the Security info page, add a "passkey" or "Windows Hello / Face ID" method. This is phishing-proof. Recommended.
On your phone, install Google Authenticator (or Microsoft Authenticator / Authy). It is free.
On a computer, go to myaccount.google.com/security and sign in.
Click "2-Step Verification." If it is off, turn it on. Then find "Authenticator app" and click "Set up."
In the phone app tap the plus, choose "Scan a QR code," and scan the code on your screen. Enter the six-digit code to confirm.
Under 2-Step Verification, remove "Voice or text message" so codes never go to SMS. Keep backup codes somewhere safe.
On the same page add a "Passkey" using Face ID, fingerprint, or a security key. This is phishing-proof. Recommended.
Your email is now protected with phishing-resistant MFA. Do this for every critical account, not just email: your bank, payroll, ad platforms, and password manager. Save your backup codes somewhere safe in case you lose your phone.
MFA is one layer. Remi™ gives you a free Personal Cyber Score across everything that is exposed about you online, in plain English, and shows you what to fix first. No credit card, no security background needed.
Enforcing MFA across every employee, every app, and proving it for compliance is what a Cythentic™ virtual CISO engagement handles. Stolen credentials are the number one way ransomware gets in, so identity is the first layer we lock down.