THE SHORT ANSWER
Use unique credentials, a trusted password manager where appropriate, and MFA supported by the service. Passkeys can reduce reliance on reusable passwords and resist many phishing patterns. Secure recovery methods because account recovery is part of authentication.
Different methods solve different problems
| Method | Purpose | Watch for |
|---|---|---|
| Password manager | Creates and stores unique passwords | Protect and recover the vault |
| MFA | Requires another factor | Not all factors resist phishing equally |
| Passkey | Uses public-key authentication instead of a reusable password | Service and recovery support vary |
| Recovery method | Restores legitimate access | Weak recovery can bypass strong login |
Evidence & context: Cybersecurity and Infrastructure Security Agency
Password reuse connects unrelated breaches
If the same secret protects several services, exposure at one service can threaten the others. Unique credentials limit that chain.
Protect the accounts that unlock everything else
- Primary email
- Password manager
- Cloud and identity administration
- Finance and payments
- Source code and hosting
- Recovery contacts and devices
Turn guidance into an owned business action
Choose one relevant account, system, data set or workflow. Record the owner, current control, most important failure, detection signal, response step and recovery dependency. Escalate specialist, legal or regulatory questions to qualified advisers for the applicable context.
Sources & further reading
- Phishing Guidance: Stopping the Attack Cycle at Phase One
Cybersecurity and Infrastructure Security Agency. Current defensive guidance on phishing resistance, MFA and organisational controls. Specific authentication choices depend on service support and risk.
- Authorization Cheat Sheet
OWASP Foundation. Security guidance emphasizing least privilege, deny-by-default behavior and authorization checks on every request. Implementation details depend on the application's threat model.
Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.
A correction, a counterexample or an experience worth sharing?
Join the conversation ↗