Why I Treat Two-Factor Authentication as Non-Negotiable
Why I Stopped Trusting Passwords Alone
A password on its own is just one lock on one door, and passwords leak more often than people realise, through data breaches, phishing pages, and reused logins on sites that get hacked somewhere else. Two-factor authentication adds a second check, so a stolen password by itself isn't enough for someone to get into your account. It's the single change I recommend most often, because it closes off the easiest way in. I've lost count of how many times I've seen someone's password turn up in a breach they'd never even heard of, sold on somewhere they'll never see, and the thing that saved the account wasn't a stronger password, it was the second step a stolen password alone couldn't get past.

What Two-Factor Actually Buys You
Turning it on means a leaked password becomes far less dangerous, since whoever has it still needs the second piece, usually a code on your phone or an app-based approval. Setting it up properly takes a few minutes per account, and most services walk you through it the moment you turn it on in your account settings, so there's no separate guide you need to track down first. If I'm setting things up while I'm out and about, I'll usually have NordVPN running too, just so the connection itself isn't the weak link.
The Different Ways 2FA Actually Works
Not every version of two-factor is equally strong, and it's worth knowing the difference. A text message code is better than nothing, but it's also the weakest option, since a number can be hijacked through a SIM swap if someone convinces your provider to move it to a new device. An authenticator app that generates a rotating code is a solid step up, since the code never travels over the phone network at all. The strongest option is a physical security key, a small device you plug in or tap, though that's usually more than most people need for everyday accounts. My rule of thumb is simple: use an app-based code where it's offered, fall back to text messages where it isn't, and don't let the search for the perfect option stop you turning on the one that's actually available.
The Accounts I Never Leave Without It
Email comes first, because it's usually the account a scammer can use to reset everything else. After that I'd prioritise banking, anything storing payment details, and social media, since a hijacked account there gets used to target people who trust you. If you only have time to protect a handful of accounts, start with those. I'd also add anything tied to your wider identity, like a cloud storage account holding photos or documents, since that's often the one people forget about until it's the one that gets used against them.
Where a Password Manager Fits In
Two-factor works best alongside strong, unique passwords, and that's where a password manager like NordPass earns its place, generating and storing a different password for every account so you're never reusing one that's already been exposed somewhere else. It also makes the second step less of a hassle, since you're not juggling passwords from memory. Most password managers can store your backup codes too, which saves you hunting through old emails the one time you actually need them.
What I'd Do If I Lost My Phone
This is the question I get asked most once someone's actually turned two-factor on, and it's a fair one. Most services give you backup codes the moment you set it up, a short list of one-time codes you can use to get back in if your phone's lost, broken, or just out of battery. I'd screenshot them, print them, or save them somewhere that isn't the phone they're backing up, since a backup code stored only on the device you've lost isn't much use to you. If you skipped that step when you set an account up, it's worth going back and generating a fresh set now, before you actually need them rather than after.
My Honest Advice If You're Still on the Fence
It feels like an extra step until the day it saves you, and by then you'll wonder why you waited. If you want a wider look at what I use day to day, my Safety Toolkit lists the tools I actually rely on, and I've also written about the phishing tricks I keep seeing that make stolen passwords so common in the first place. If anything about this feels confusing, feel free to get in touch and I'll walk you through it. None of it takes long, and once it's set up you barely notice it's there, right up until the day it quietly stops something worse from happening.
