Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Protect your email in two steps

Secure the account you use to regain access to other important services.

Users of financial servicesAbout 5 minutes of reading + 3 questions
Start with the example Need to act now?

What you will learn

  • Enable an additional sign-in check.
  • Create a password you do not use elsewhere.
  • Recognise when you need account recovery.

Practice example

Would you approve this sign-in?

A notification on your phone
Would you approve this sign-in?

A request asks you to approve an email sign-in. You are not using your email, and the request keeps appearing.

Fictional training example.
Show the example explanation
You did not start the sign-in
Do not approve it simply to dismiss the notification.
The request keeps appearing
Repetition is not a reason to approve it. Open your account security settings independently of the message.

Why start with email?

Email often helps you reset passwords for other accounts. Someone with access to your inbox could read private messages, reset other passwords or impersonate you. That is why this guide starts with email security.

Enable an additional sign-in check

For specific controls, open Google, Microsoft, Apple and other account settings, including recovery codes and reviewing other sign-ins.

Two-factor authentication (2FA) adds a check alongside your password. It reduces the risk of unauthorised access, but cannot prevent every attack.

  1. Open your provider’s official account website and security settings.
  2. Follow its instructions to enable 2FA. Depending on the service, the method may use an authenticator app, a security key or a code on your phone.
  3. Keep recovery codes somewhere secure that you can access without that email account.
  4. Do not approve sign-ins you did not start or share codes with other people.

Our 2FA guide explains how to choose a method, store recovery codes and respond to an unexpected approval request.

Set a separate password

Use a long password that you do not use for any other account. Three random, unrelated words can make it easier to remember. Avoid names, dates and details from your public posts, and follow the service’s requirements. A password manager can help create and store different passwords. Read more in our strong-password guide.

Change your password through the service’s official settings, not through a link in a message. If the password has already been exposed, follow the password replacement and account-protection steps.

If you notice an unfamiliar sign-in

Reject a request you did not start. Open your account independently of the notification and review recent activity. If you exposed your password, change it wherever else you used it. If you can no longer sign in, follow the account recovery guide.

If money or banking access is at risk, contact your bank immediately through an official channel. For a work account, notify your internal IT or security support team.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

You receive an approval request for a sign-in you did not start. What do you do?

Why does this matter? An extra approval protects an account only when you approve your own sign-ins. Repeated alerts can pressure you into granting access to someone you did not intend to let in.

  1. Approve it to stop the notifications.

    Approval could allow someone else to sign in. Your approval may be the very step the attacker needs; approving to silence a request therefore changes account access.

  2. Reject it and check activity through the official account.Correct answer

    This avoids authorising an unfamiliar sign-in and lets you investigate. Official settings let you check account activity without using the contact that raised your suspicion.

  3. Send the code to someone claiming to be support.

    Do not share the code with another person. The code can be the final step in someone else’s sign-in, so claiming to be support does not make sharing it safe.

You use the same long password for email and a shop. What is the best change?

Why does this matter? A password exposed by one shop can be tried against your email. Email access matters particularly because it often provides recovery routes for other accounts.

  1. Give email its own long password.Correct answer

    A separate password limits the consequences of a breach at another service. Different passwords break the link between the accounts: the exposed shop password is no longer also the email password.

  2. Add the same character to both passwords.

    The passwords would still be identical across both accounts. Making the same change in both places retains the problem: one exposed value still offers a route into the other account.

  3. Keep both because they are long enough.

    Length does not address the risk of reuse. Length makes guessing harder, but does not help when someone already knows the whole password from a data breach.

You have enabled 2FA and received recovery codes. Where do you keep them?

Why does this matter? Recovery codes need to be both secret and available when the normal sign-in method fails. Public storage, or storage only inside the same account, undermines that purpose.

  1. In a public note so they are easy to find.

    Anyone who sees the codes could misuse them. A backup code may substitute for the second factor during recovery, so a public note can create a route into the account.

  2. Only in a message to the same email account.

    Losing access to that account could also lock you out of the codes. This creates a loop: you need the code to get in, but can only obtain the code after getting in.

  3. Somewhere secure that I can access if I lose email access.Correct answer

    Protect the codes and plan access that does not depend on the account you need to recover. You prepare a recovery route that does not depend on resolving the very problem that made recovery necessary.

No registration. Your answers are not sent; the result is just for you.

Remember

A separate password and 2FA work together. Only approve sign-ins you started yourself.

How 2FA works

References

Sources and further reading

The account-protection baseline follows the Serbian National CERT guidance on two-factor authentication, its publication on compromised email and the UK NCSC account-security guidance.

Official provider instructions for enabling an additional sign-in check are available for Microsoft / Outlook, Google / Gmail, Apple / iCloud, Yahoo and BT. Password-change instructions are available for Outlook, Gmail, iCloud, Yahoo and BT, and Google provides compromised-account instructions. Labels and available options may change.

Content last reviewed