Why Two-Factor Authentication (2FA) Is Non-Negotiable

Passwords alone are no longer sufficient to protect your online accounts. Data breaches expose billions of credentials every year, and if your password is reused across sites — which is extremely common — a single breach can cascade into a full account takeover. Two-factor authentication (2FA) adds a second verification step, meaning stolen passwords alone aren't enough to get in.

How 2FA Works

After entering your password, you're asked to confirm your identity via a second method. The most common types include:

  • Authenticator App (TOTP): A time-limited 6-digit code generated by an app like Google Authenticator, Authy, or Microsoft Authenticator. This is the most secure commonly available method.
  • SMS Code: A one-time code sent to your phone via text message. Convenient but vulnerable to SIM-swapping attacks.
  • Hardware Security Key: A physical USB or NFC device (e.g., YubiKey) that you plug in or tap. The most secure option, ideal for high-value accounts.
  • Email Code: A code sent to your email. Only as secure as your email account itself.

Step-by-Step: Enabling 2FA on Key Accounts

Google / Gmail

  1. Go to myaccount.google.com
  2. Click Security in the left sidebar
  3. Under "How you sign in to Google," click 2-Step Verification
  4. Click Get Started and follow the prompts
  5. Choose your preferred method — we recommend an authenticator app or a Google Prompt on your phone
  6. Save your backup codes in a secure location

Microsoft / Outlook

  1. Go to account.microsoft.com/security
  2. Click Advanced security options
  3. Under "Two-step verification," click Turn on
  4. Follow the setup wizard — the Microsoft Authenticator app is recommended

Facebook / Instagram (Meta)

  1. Go to Settings & Privacy → Settings → Security and Login
  2. Find "Two-Factor Authentication" and click Edit
  3. Select an authentication method and complete the setup
  4. Download your recovery codes from the same menu

Apple ID

  1. On iPhone: Go to Settings → [Your Name] → Password & Security
  2. Tap Turn On Two-Factor Authentication
  3. On Mac: Go to System Settings → Apple ID → Password & Security
  4. Apple uses trusted devices and phone numbers for verification codes

Which Authenticator App Should You Use?

AppPlatformKey Advantage
AuthyiOS, Android, DesktopEncrypted cloud backup of tokens
Google AuthenticatoriOS, AndroidSimple, widely supported
Microsoft AuthenticatoriOS, AndroidBest for Microsoft accounts; push notifications
Aegis (Android only)AndroidOpen source, local encrypted backup

Important: Save Your Backup Codes

Every service that supports 2FA will offer backup recovery codes during setup. These are single-use codes that let you access your account if you lose your phone. Print them or save them in an encrypted file. Losing both your phone and backup codes means losing access to your account — potentially permanently.

Prioritise These Accounts First

  • Your primary email account (it's the key to resetting everything else)
  • Your bank and financial accounts
  • Your Apple ID or Google account
  • Any account storing sensitive documents or payment information
  • Your password manager

Even enabling 2FA on just your email and financial accounts provides a massive improvement in your overall security posture. Start there, then work through the rest systematically.