Choose the strongest option available
A security key or passkey resists many phishing attempts because it is tied to the genuine service. An authenticator app generates time-limited codes without relying on mobile reception. Text messages are usually better than password-only access, but a phone number can be moved or intercepted.
Start with email, banking, cloud storage and the account that controls your password manager. Email often provides the reset route into everything else.
Set it up without locking yourself out
- Open the security settings from the service’s official app or address.
- Add the strongest factor you can use reliably.
- Create a second recovery route where the service supports one.
- Store recovery codes offline or in a protected password manager.
- Sign out and test the normal sign-in and recovery process.
Treat surprise prompts as hostile
Do not approve a login you did not start. Repeated prompts can be an attempt to wear you down. Deny the request, change the password from a trusted device and review active sessions.
Sources and review record
- National Cyber Security Centre: Guidance documents · accessed 11 July 2026.
- NCSC: Phishing guidance · accessed 11 July 2026.
This guide provides general information for the Republic of Ireland. Check the linked official guidance for your circumstances and current rules.