The Three Habits That Stop Most Attacks
If you only ever do three things, do these: use a password manager, turn on a second factor, and keep your devices updated. Together they stop the large majority of real-world attacks.
Security advice can feel endless — a bottomless list of settings, apps, and warnings. So let's cut it down to what actually matters. If you do nothing else from this entire course, these three habits will protect you from the large majority of attacks that hit normal people. Everything else is a refinement on top.
Habit 1: Use a password manager
The reason accounts get broken into is almost never a genius hacker guessing your password. It's that the same password you use everywhere already leaked from some unrelated website, and an automated tool is now trying it on your email, your bank, and your shopping accounts. This is called credential stuffing, and it works because most people reuse passwords.
A password manager fixes the root cause. It creates a long, random, unique password for every account and remembers them all, so a leak from one site can't unlock the others. You remember one strong master password; it handles the rest. This one change breaks the most common attack there is.
We go deeper in Passwords and password managers, and you can compare current picks on the passwords guide.
Habit 2: Turn on a second factor (2FA)
Two-factor authentication means that even if someone does get your password, it isn't enough on its own. Logging in also requires a second proof — a code from an app, a tap on your phone, or a passkey — that the attacker doesn't have.
You don't need it on everything. Put it on the accounts that would hurt most to lose: your primary email first (it's the master key), then banking, then anything with your money or identity attached. See Two-factor authentication and passkeys for the how and the why.
Habit 3: Keep your devices updated
Those update notifications you keep dismissing are mostly security patches. When a flaw is discovered, attackers rush to exploit it — and updates are how the hole gets closed. A device that's months behind on updates is running with locks that are known to be pickable.
The fix is almost effortless: turn on automatic updates for your phone, computer, and browser, and let them install themselves. It's the highest-value habit for the least ongoing work.
Pick the one habit you're weakest on and start it today — don't try to do all three at once. If you're not sure which, the Security Scorecard will point straight at it.
Why these three, in this order
They map onto how attacks actually unfold. A password manager stops the leaked-password attack that starts most break-ins. A second factor is the backstop for when a password slips through anyway. Updates close the technical holes that let malware take hold. Each one covers a different failure, and together they overlap into a net that automated attacks rarely get through.
None of them require expertise, and none of them demand daily attention once set up. That's the whole idea: durable protection you configure once, not vigilance you have to sustain forever.
Answering the usual objections
People hesitate on these three habits for the same handful of reasons every time, so let's clear them up.
- "What if I forget my master password?" You choose it, you can write it down somewhere safe until it sticks, and most managers offer recovery options. One password to remember is far safer than a dozen you reuse.
- "Isn't putting all my passwords in one place risky?" The vault is heavily encrypted, and the real-world alternative — reusing a few passwords everywhere — is far riskier. Concentrated and encrypted beats scattered and repeated.
- "2FA sounds like a hassle at every login." In practice you approve it rarely, because devices you trust stay trusted. A few extra seconds now and then is a small price for an account that survives a leaked password.
- "Updates always break something." Occasionally an update changes a feature, but the security fixes inside are closing holes attackers are actively using. Waiting leaves you exposed during the exact window they're hunting in.
Notice the pattern in every answer: a small, one-time inconvenience weighed against a large, ongoing risk. That trade almost always favors doing the habit. And you don't have to take all three on faith at once — start with the one that protects you most, feel how little friction it actually adds, and the next two get easier.
If it helps, think of these three as a single routine rather than three separate chores: pick a password manager, and turning on 2FA and automatic updates follows naturally as you get set up. One focused afternoon puts the whole foundation in place, and from then on it mostly runs itself while you get on with your life.
Key takeaways
- A password manager gives every account a unique password, breaking the most common attack.
- A second factor protects you even when a password leaks — start with email, then money.
- Automatic updates close known security holes with almost no ongoing effort.
- Do the weakest one first; you don't have to fix everything the same day.
Quick quiz
A couple of quick questions to lock in what you just read. Nothing is saved — pick an answer to see if you got it.
-
Which three habits stop most attacks?
A password manager for unique passwords, two-factor authentication (especially email and money), and the pause-before-you-act habit.
-
Why is two-factor authentication so valuable?
A second factor blocks the vast majority of automated attacks even if your password leaks.
-
What defeats the manipulation behind most phishing?
Most attacks rely on rushing you. Slowing down to verify defeats them.
Keep going
Subscribe for new lessons and a printable security checklist.