The Order I'd Actually Fix My Digital Security In, If I Started From Scratch

Sep 09, 2025By Jay Kells
Jay Kells

The Order I'd Actually Fix My Digital Security In, If I Started From Scratch

A friend asked me recently where she should even begin with her online security. She'd read a few lists, felt overwhelmed by all of them at once, and ended up doing nothing at all for another six months. That's the real cost of a long checklist with no order to it. It's not that the advice is wrong, it's that when everything looks equally urgent, nothing actually gets done. So instead of giving her another list, I gave her an order, the same order I'd use if I were starting completely from scratch today.


Why the Order Actually Matters Here


Most security advice gets handed out as a flat list, turn on 2FA, use strong passwords, update your software, review your privacy settings, as if each item carries the same weight and can be tackled in any sequence. In practice, doing them out of order either wastes effort or leaves gaps that undo the whole point. Turning on two-factor authentication before sorting out weak, reused passwords protects the login step but does nothing for the password itself sitting exposed in a dozen other places. Reviewing privacy settings on social media before locking down your actual accounts is tidying the curtains while the front door's still open. The order isn't a small detail, it's most of what makes the difference between an afternoon that actually protects you and an afternoon that just feels productive.


Start With a Password Manager, Not Individual Passwords


This is where I'd always begin, and it's not close. Every other step on this list either depends on it or works better because of it. I've written before about why I finally switched to a password manager, and the short version is that trying to fix passwords one at a time, changing the obvious weak ones while leaving the rest, never actually gets finished. A password manager lets you fix all of them properly in one sitting, generating a long, unique password for every account and remembering it so you never have to. I use NordPass for this specifically because setting it up takes minutes, not a weekend, which matters when the whole point is removing excuses to put it off. Nothing else on this list is worth doing until this one's in place, because everything after it either builds on strong unique passwords or gets undermined by their absence.


Then Two-Factor Authentication, Starting With Email


Once passwords are sorted, this is next, and I'd resist the urge to switch it on everywhere at once. I'd start with email specifically, because a compromised email account is usually the fastest route into everything else you own, password resets, other logins, personal documents sitting in old messages. I've been through the excuses people make here myself, I used to make most of them, telling myself it would take too long or that my password was already strong enough on its own, and none of them held up once I actually sat down and did it. From email, I'd work outward to banking, then anywhere financial details are stored, then anything else that matters, rather than trying to do all of it in one sitting and losing momentum halfway through. Most services only ask for that second step occasionally rather than on every single login, so the ongoing cost turns out to be almost nothing once it's set up, even though it feels like it'll be a constant hassle beforehand. Twenty minutes on the accounts that matter most beats an afternoon that never gets finished because it felt too big to start.


After That, the Software Updates I Used to Click Away


This is the step I used to skip for the longest, mostly because update prompts always seem to land at the worst possible moment, usually right as I'm trying to actually use the device for something. What changed my mind wasn't a lecture about security patches, it was realising how many serious breaches trace back to a vulnerability that had already been fixed months earlier, publicly documented and everything, just never installed on the device that got hit. The people writing the fix had already done their part. I turn on automatic updates wherever the option exists now, for my operating system, my browser, and anything handling passwords or payments specifically, rather than relying on myself to remember to check manually. It's the least interesting step on this list and also one of the most effective, precisely because it closes doors that are already publicly known to be open rather than guarding against something theoretical that might happen eventually.

Person's hand with pen marking a checkbox on minimalist daily habit tracker sheet in natural morning light.


Only Then Do I Worry About the Smaller Stuff


Everything past this point matters, but it matters less urgently than the first three, which is exactly why it goes last rather than first. This is where I'd review old accounts I've forgotten I even have, since an account I haven't logged into in three years is still a live target if it still holds my details. It's also where I'd go through privacy settings on social media properly rather than skimming past them, since I've written before about why I stopped oversharing there in the first place. None of this is wasted effort, but doing it before the first three steps is solving a smaller problem while a bigger one sits untouched.


I'd rather someone did the first two properly and never got to the rest than tried to do everything at once and burned out after an hour. If you want the fuller version of what I'd actually walk through account by account, I've put it together in a free Safety Toolkit, and the NCSC has its own guidance on the basics if you want a second source to check any of this against before you start.