Module 2

Passwords, Authentication and Account Security

Strengthen accounts with better password habits, MFA, passkeys and safe recovery planning.

Learning Objectives

  • Create strong, unique passwords.
  • Use a password manager safely.
  • Enable and manage multi-factor authentication (MFA).
  • Understand passkeys and credential stuffing risks.

Why This Matters

Compromised accounts are one of the most common entry points for cyber incidents.

Good identity hygiene is one of the highest-value defensive controls for both home and business users.

Plain-Language Explanation

A strong password is long and unique for each service. Password managers reduce reuse and human memory errors. MFA adds another verification step, making account takeover harder even if a password leaks. Passkeys use device-based cryptographic authentication and can reduce phishing risk when implemented correctly.

Practical Examples

  • Enable MFA on email, banking and social media accounts first.
  • Store recovery codes in a secure offline location.
  • Review old unused accounts and close what is no longer needed.

Common Mistakes

  • Reusing passwords across multiple services.
  • Keeping MFA only on low-value accounts.
  • Ignoring unusual sign-in alerts.

Security Checklist

Module checklist progress0%

Short Knowledge Check

Question 1: Why is password reuse dangerous?

If one site is breached, attackers try the same credentials elsewhere (credential stuffing).

Question 2: What should be prioritised for MFA?

Email and administrator accounts first, then other high-impact accounts.

Question 3: Are passkeys a replacement for all security controls?

No. They are strong, but still need device security, recovery planning and account monitoring.

Key Takeaways

  • Unique passwords and MFA greatly reduce account takeover risk.
  • Password managers improve both security and usability.
  • Recovery planning is part of account security, not an afterthought.
← PreviousModule 2 of 10Next →