1. Map access before changing settings
Write down the email or phone number connected to the account, the devices that are still signed in and the people with access. For an organisation, identify the administrative owner as well. This prevents a security improvement from becoming an accidental lockout.
Open settings from the official app or an address you entered yourself. A message that creates urgency and asks for a password, code or login through a link may be phishing.
2. Use a unique password
Choose a long password that is not used anywhere else. A password manager can generate and store a different one for every service. Uniqueness matters because a breach on one website should not unlock your social accounts.
- Never send a password in a message or shared document.
- Change it promptly if you entered it on a suspicious page.
- Protect the email account that receives reset links.
3. Enable two-step verification and plan recovery
Two-step verification adds a check after the password. Depending on the service, it may use an authenticator app, security key or code. Options differ, so choose a method suited to your devices and follow the platform’s current documentation.
Save recovery codes in a protected place separate from the phone. Confirm that a changed or lost number will not block every route back into the account.
4. Review sessions and connected apps
Check the login history or device list. Sign out sessions you do not recognise and remove connected apps you no longer use. On a team account, prefer individual roles when available instead of circulating one shared login.
If a session looks suspicious, preserve useful details, change the password from a trusted device, then check the recovery email and contact details.
5. Create a quarterly security check
Review devices, recovery methods, administrators and login alerts every few months, and after a lost phone, staff change or breach warning. Menu labels change, so look for security, login, devices or account centre and confirm the steps in official help.
Your checklist
- The recovery email is protected.
- The password is unique and safely stored.
- Two-step verification is on and recovery codes are saved.
- Devices, sessions and connected apps have been reviewed.
Frequently asked questions
Which two-step verification method should I use?
An authenticator app or security key avoids relying only on SMS, but start with a method you can maintain and recover correctly.
What if I think my account was hacked?
From a trusted device, use the official recovery route, secure the linked email, change the password and sign out unknown sessions. Never send anyone your codes.
Must I change every password regularly?
Change a password promptly when it is compromised, reused or shared. The priority is a unique password protected by a second step.
Sources & method
This guide turns institutional recommendations into practical steps. Features and remedies vary by country, account and service version.
Editorial responsibility: Alexis R., World Web Certified. Suggest a correction.
