Thinking Beyond the Password
We spend hours choosing strong, unique passwords for our countless online accounts. We use password managers to keep them straight. But what happens when the password isn't the problem? You might lose your phone, change your number, or forget the answer
to a security question you set years ago. Suddenly, you're locked out of your own digital life. Account recovery is often an afterthought, but it’s one of the most critical components of your security setup. A single point of failure—like only having one recovery email address—is a risk you can’t afford. The goal is to build a layered defence, giving you multiple, independent ways to prove your identity and get back into your accounts securely. Think of it like having more than one key to your house. You might keep one in your pocket, one with a trusted family member, and another in a lockbox. Each serves as a backup if another is lost.
The Classic Duo: Email and Phone
The most common recovery methods are a secondary email address and a phone number. For most people, these are the first and often only lines of defence. A password reset link sent to a backup email is standard practice. Likewise, a one-time code sent via SMS is a popular method for two-factor authentication (2FA) and recovery. While convenient, relying solely on these has risks. If your backup email account is compromised, a hacker can easily take over every account linked to it. Phone numbers are also vulnerable to 'SIM-swapping' attacks, where a criminal convinces your mobile provider to transfer your number to their device, giving them access to your recovery codes. A Google study showed that adding a recovery phone number can block a significant number of automated attacks and phishing attempts, making it a valuable layer. However, it should not be your only layer. It's best used in combination with other, more secure methods.
The Modern Safeguard: Authenticator Apps
Authenticator apps like Google Authenticator, Microsoft Authenticator, or Authy represent a major step up in security from SMS-based codes. These apps generate time-sensitive, six-digit codes on your device, which are required to log in. Since the code is generated on your device and not sent over a network, it's not vulnerable to SIM swapping. The main challenge arises when you lose or replace the device hosting the app. This is why it’s crucial to use the app’s own backup features. Many authenticator apps now offer cloud backups, allowing you to restore your codes on a new device. Without this backup, losing your phone could mean losing access to every account secured with that app. When setting one up, always enable the cloud sync or backup option and ensure it’s protected by a strong password.
The Gold Standard: Physical Security Keys
For your most critical accounts—like your primary email, bank, or password manager—a physical security key is the ultimate failsafe. These are small USB, NFC, or Bluetooth devices that you use to verify your identity. When prompted, you simply insert the key into your computer or tap it on your phone. Because it requires physical possession, it's considered one of the strongest forms of multi-factor authentication and is highly resistant to phishing. Setting one up is straightforward, but it's essential to have a plan for losing it. The best practice is to register at least two keys for each important account. Keep your primary key on your keychain and store the backup key in a secure location, such as a safe at home or with a trusted family member. This redundancy ensures that losing your main key is a minor inconvenience, not a catastrophe.
Your Offline Emergency Kit: Recovery Codes
When you enable multi-factor authentication on many services, you're often given a set of one-time use recovery codes. These codes are a lifeline designed specifically for when you lose access to all your other recovery methods. Think of them as a 'break glass in case of emergency' option. It is absolutely critical that you save these codes somewhere safe and, most importantly, offline. Do not save them in your email drafts or as a note on your phone. Print them out and store them in a locked file cabinet, a safe, or with important documents. You can also save them in an encrypted file on a USB drive stored securely. Labelling them clearly for each account is essential. These codes bypass the normal authentication process, so they must be guarded as carefully as a password.











