The One Security Step I'd Tell a Complete Beginner to Start With
The One Security Step I'd Tell a Complete Beginner to Start With
People ask me this more than almost anything else, where do I actually start if I haven't done any of this before and the whole subject feels overwhelming. There's a long list of things worth doing eventually, but if someone's never touched any of it and I only get to recommend one thing, I always say the same thing, turn on two-factor authentication on your email account today. Not a password manager, not an antivirus product, not a VPN. Just that one thing, on that one account, before anything else.
Why I Don't Start Beginners With a Password Manager
It seems like the more obvious starting point, weak or reused passwords are such a common problem that fixing them feels like it should come first. But a password manager is a bigger commitment for someone brand new to this, you're changing how you log into everything at once, learning a new piece of software, and moving dozens of accounts over in one go, and that's a lot to take on in one sitting if you're already feeling out of your depth. Two-factor authentication on a single account is a five minute job that doesn't ask you to change any habits yet, it just adds one extra step to a login you're already doing, and that smaller first win tends to be what actually gets people to keep going rather than giving up halfway through a bigger project. I've watched people abandon the whole idea of improving their security after getting overwhelmed trying to do everything on day one, and I'd rather see someone finish one small thing than start five big ones and finish none of them.
What Two-Factor Actually Means, In Plain English
I try to strip the jargon out of this completely when I'm explaining it to someone for the first time. Right now, getting into your account probably just means typing a password. Two-factor authentication adds a second check on top of that, usually a code that gets sent to your phone or generated by an app, so that a password alone isn't enough to get in anymore. Someone would need your password and your phone to break in, rather than just your password, and that second requirement is what stops the vast majority of account takeovers, because most of them rely on nothing more than a stolen or guessed password working on its own.
The One Account I'd Tell You to Protect First
Email gets my vote every time, and it's not close. Almost every other account you own, banking, shopping, social media, can be reset through your email address if someone forgets a password or wants to break in another way. That makes your email account the master key to everything else, and it's the one place where a compromise doesn't just cost you that one account, it potentially costs you all of them at once. If someone gets into your email, they don't need to guess your banking password, they just click "forgotten password" on your bank's login page and read the reset link straight out of your inbox. If you've got five minutes and one account to protect today, that's the one, and everything else can genuinely wait until another day.
What Actually Happens When You Turn It On
Most email providers walk you through this in their security settings, usually under a heading like "two-step verification" or "two-factor authentication." You'll be asked to add a phone number or set up an authenticator app, and from then on you'll see an extra prompt each time you log in from a new device. It feels like friction at first, an extra ten seconds you didn't have to spend before, but it becomes routine within a few days and you stop noticing it entirely. Most people I've walked through this tell me afterwards it took less time than they expected, and that the hardest part was simply deciding to start, not anything technical about the process itself. The one thing I always tell people to do at this stage is save the backup codes it offers you somewhere safe, because that's the part people skip and the part that causes real trouble later if you ever lose access to your phone.

You Don't Need to Fix Everything Today
This is the bit that seems to relieve people the most once I say it out loud. You don't need a password manager, an antivirus subscription, and a VPN all sorted by tomorrow, and trying to do all of it at once is usually why people give up before finishing any of it. Get email protected first, then move on to whatever feels most urgent whenever you're ready, next week, next month, it genuinely doesn't matter as long as it happens eventually. Security isn't a single afternoon of effort, it's a handful of small habits built up gradually, and the beginner who does one thing properly is in a far better position than the person who half-starts everything and finishes nothing. I've written before about the fuller order I'd actually work through everything else in once that first step is done, and about the different kinds of two-factor authentication if you want to understand which option is strongest once you're past the beginner stage.
If you take nothing else from this, take this, two-factor authentication on your email account, today, before you close this tab. It's the single highest-value five minutes you can spend on your own security, and it doesn't require understanding anything else on this site first. Once that's done, my free Safety Toolkit walks through what I'd genuinely tackle next in whatever order makes sense for you, and the NCSC has its own beginner-friendly guidance on two-factor authentication if you want a second explanation before you start.
