Between phishing emails, fake websites and data breaches that expose passwords, keeping your online accounts secure can feel like a full-time job.
The good news is that you do not need a degree in cybersecurity to make a meaningful difference. A few practical changes to the way you manage passwords, verify logins and browse the web can significantly reduce your risk.
Here are three simple ways to make your online accounts harder to hack.
1. Ditch password patterns and use a password manager
Many people use a familiar password pattern across multiple accounts. It might be a favourite word followed by a number, a child’s name with a birthday, or the same password with a different symbol added at the end.
Unfortunately, predictable patterns are easy for criminals and automated tools to test. Reusing the same password is even more dangerous. If one website suffers a data breach, attackers may try those stolen credentials on your email, banking, social media and cloud storage accounts. This is known as credential stuffing.
The safest approach is to use a different, randomly generated password for every account.
Security guidance from the Cybersecurity and Infrastructure Security Agency recommends passwords that are long, random and unique. Aim for at least 15 characters, with 16 or more being even better where the service allows it.
The challenge is remembering dozens of different passwords. That is where a password manager helps.
A password manager can:
- Generate strong, random passwords
- Store your passwords in an encrypted vault
- Autofill login details on trusted websites and apps
- Alert you to reused, weak or compromised passwords
- Help you avoid typing passwords into fake websites
You do not need to memorise every password. You generally only need to remember one strong master passphrase for the password manager itself.
Password manager options
Apple Passwords: If you use Apple devices, the built-in Passwords app can create, store and autofill passwords and passkeys. It can also alert you when passwords are weak, reused or found in known data leaks. See Apple’s Password app guidance.
Google Password Manager: For people using Chrome and Android, Google Password Manager is built into the Google ecosystem. It can save and autofill passwords across supported devices and includes a Password Checkup feature.
Bitwarden: Bitwarden is a popular cross-platform option that works across many browsers and operating systems. It offers password storage, password generation and two-step login features.
Whichever option you choose, protect the password manager itself with a strong master passphrase and two-factor authentication. Also save your recovery code somewhere secure. A password manager can improve your security considerably, but it becomes an important account that needs strong protection of its own.
A simple place to start
Do not try to change every password in one afternoon. Start with your most important accounts:
- Primary email
- Password manager
- Banking and payment accounts
- Google Workspace or other cloud services
- Social media accounts
- Online shopping and business software
Change each password to a unique, randomly generated password and allow the password manager to save it. Over time, you can work through the rest of your accounts.
2. Upgrade your two-factor authentication
A password is only one layer of protection. Two-factor authentication, also called 2FA, two-step verification or multi-factor authentication, adds another step to confirm that you are really the person signing in.
The second factor might be:
- Something you have, such as a phone, authenticator app or security key
- Something you are, such as a fingerprint or face scan
- A temporary verification code
With 2FA enabled, someone who obtains your password still needs the second factor to access your account. This can stop many attacks that would otherwise succeed.
The Australian Government’s cyber.gov.au guidance explains that multi-factor authentication is one of the most effective ways to protect your accounts, particularly email, financial, social media and cloud storage accounts.
Authenticator apps are safer than SMS where available
Receiving a verification code by text message is better than using no second factor at all. However, SMS codes can be exposed if a criminal takes control of your mobile number through a SIM-swapping scam.
Authenticator apps generate temporary codes directly on your phone or tablet. These codes typically refresh every 30 seconds and are not dependent on your mobile number receiving a text message.
One option is Proton Authenticator, which supports the setup, import and syncing of authentication codes across supported devices. Another option is Google Authenticator, a free and widely used authenticator app available for both iOS and Android. Other reputable authenticator apps are also available.
When setting up 2FA:
- Start with your primary email account.
- Enable it on your password manager.
- Add it to banking and payment services.
- Protect social media and cloud storage accounts.
- Store recovery codes somewhere secure.
- Never share a verification code with someone who contacts you unexpectedly.
Recovery codes are particularly important. If you lose your phone or replace it, they may be the only way to regain access to an account. Store them in your password manager or another secure location, but do not leave them in an unprotected text file or email inbox.
If an account only offers SMS verification, turn it on while checking whether stronger options become available later. Security keys and passkeys can provide additional protection for important accounts, especially business administrator accounts.
For businesses, 2FA should be part of the account setup process for every team member. It is also important to review administrator accounts regularly and remove access promptly when someone changes roles or leaves the organisation.
3. Enable Enhanced Protection in Google Chrome
Passwords and 2FA protect your accounts, but you also need to be careful about where you enter your login details.
Phishing websites are designed to look like legitimate services. A fake page might imitate your email provider, bank, payroll system or cloud software. If you enter your username and password, the information may go directly to a criminal.
Google Chrome includes Safe Browsing features that warn you about dangerous websites, downloads, extensions and social engineering attacks. Chrome offers two main protection levels:
- Standard Protection: Helps protect against known dangerous websites, downloads and extensions.
- Enhanced Protection: Provides more proactive warnings about known and potential new threats.
To enable Enhanced Protection in Chrome:
- Open Chrome.
- Select the three-dot menu in the top-right corner.
- Choose Settings.
- Select Privacy and security.
- Choose Security.
- Select Enhanced protection under Safe Browsing.
Google’s official Chrome guidance explains that Enhanced Protection can provide warnings about threats that Google has not previously identified. It can also warn you if a password has been compromised in a data breach.
Consider the privacy trade-off
Enhanced Protection sends more information to Google Safe Browsing than Standard Protection. Depending on the security check, this may include the website URL, a small sample of page content, extension activity and system information.
That additional information helps Google assess potential threats in real time. However, some people may prefer Standard Protection because it provides a different privacy balance.
There is no single setting that is perfect for everyone. Review the options and choose the level that suits your circumstances. For many people, the extra threat detection provided by Enhanced Protection is a worthwhile security improvement.
Chrome’s protection is not a replacement for good judgement. A warning can be missed, ignored or triggered after you have already shared information. Always check the website address before entering a password, particularly when you arrive through an email, text message or online advertisement.
The bottom line: your judgement is still your best defence
Password managers, two-factor authentication and browser security features do much of the technical work, but they cannot replace awareness.
Whenever a message creates urgency, pause before acting. Be especially cautious when someone asks you to:
- Click a link immediately
- Confirm your password
- Provide a verification code
- Approve an unexpected login
- Change bank or payment details
- Download an unfamiliar file
- Keep the request secret
Instead of clicking the link, open the official app or type the known website address into your browser. If the request appears to come from a colleague, supplier or customer, verify it using a separate, trusted communication method.
For a business, make this process easy for your team. Clear security policies, regular training and a simple way to report suspicious messages can prevent small mistakes from becoming serious incidents.
If you would like help reviewing your organisation’s account security, Cloud Computer Company can help. Our services include managed IT support, security best-practice guidance, Google Workspace security reviews and tailored user training.
You can also learn more about our Google Workspace health and security checkup, which can help identify risks, improve account protection and strengthen your organisation’s overall security posture.
Contact Cloud Computer Company to discuss practical security improvements for your business.
About Mathew Hoffman
Mathew Hoffman started his IT career in 1981 and has held senior roles with State Bank of NSW, Minet Australia, Wilhelmsen Lines and Rothmans of Pall Mall. His experience includes the technology environment surrounding the Sydney 2000 Olympics.
Since 2001, Mathew has provided IT consultancy services to small and medium businesses. He became an original Google Partner in 2008 and re-branded the business as Cloud Computer Company in 2017.
Based in Noosa, Mathew enjoys cricket, having played and coached in Sydney and on the Sunshine Coast. He also enjoys spending time with his family, visiting the beach and playing golf.





