Turn on two-factor authentication (2FA / MFA) for Gmail, your Apple Account, and every bank login the household uses. CISA's rule is simple: even if someone steals the password, they still need the second step. Start with email — a hijacked Google Account is often the reset path for everything else — then Apple, then the bank app you already use. Prefer Google prompts or an authenticator app over SMS; text codes can fail in a SIM-swap. This is not an antivirus purchase. Microsoft Defender is a valid buy-nothing choice for many Windows PCs.
Why email, Apple, and banks first
CISA tells people to turn on MFA for email, banks, online purchases, and social accounts, because a stolen password is not enough if the second check is required. Email is the household's recovery mailbox. If someone gets into Gmail, they can request password resets elsewhere. Apple Account 2FA protects iCloud, Find My, and Sign in with Apple. Banks protect money. Do those three before shopping or streaming apps. Pair 2FA with a unique password per site — see password manager vs browser saved passwords. If that mailbox showed up in a leak, check whether the email was in a data breach and change the password after 2FA is on.
How 2FA methods compare
Authenticator apps, prompts, and passkeys are stronger everyday choices than SMS for a U.S. household.
| Account | Where to look | Prefer this second step |
|---|---|---|
| Gmail / Google Account | Google Account → Security & sign-in → Turn on 2-Step Verification | Google prompts (or a passkey / security key); authenticator app as backup; SMS last |
| Apple Account | Settings → [your name] → Sign-In & Security, or account.apple.com → Upgrade Account Security | 6-digit code on a trusted device (or trusted phone number) |
| Bank | The bank app or website you already use → Security / Sign-in / Privacy | Authenticator app if the bank offers it; SMS is weaker |
CISA lists common methods as a code by text or email, an authenticator app that refreshes a code about every 30 seconds, or biometrics such as a fingerprint or face. Google recommends prompts over SMS and notes that text or call codes can be vulnerable to phone-number hacks. Passkeys and hardware security keys are stronger against phishing than a typed code.
How to turn on 2-Step Verification for Gmail
Google 2-Step Verification adds a second check so a stolen password is not enough to open the account.
- Open your Google Account.
- Tap Security & sign-in.
- Under "How you sign in to Google," select Turn on 2-Step Verification.
- Follow the on-screen steps.
If you use a work, school, or other organization account, these steps may not work; Google says to ask the administrator. After it is on, Google recommends Google prompts if you are not signing in with a passkey. Prompts arrive as a Yes/No notification on an Android phone signed into that Google Account, or on an iPhone with Gmail, Google Photos, YouTube, or the Google app signed in. Tap Yes only if you requested the sign-in. Set a backup that is not SMS: Google Authenticator or another code app, plus printed backup codes stored offline. Never share a verification code. Google will not call you to verify a code. SMS or voice codes still add a layer, but Google warns they can be vulnerable to phone-number hacks — the same risk as a stolen phone number / SIM-swap. Passkeys and security keys are the stronger anti-phishing option when the household is ready.
How to turn on two-factor authentication for Apple
Apple two-factor authentication is an extra layer so you are the only person who can use the Apple Account, even if someone else knows the password. On a new device or the web, Apple asks for the password plus a six-digit code shown on a trusted device or sent to a trusted phone number. After the first sign-in, that device should not keep asking unless you sign out, erase it, or must change the password.
On iPhone, iPad, or Mac
- Open Settings (iPhone/iPad) or System Settings (Mac).
- Tap [your name], then Sign-In & Security.
- Turn on two-factor authentication and follow the onscreen instructions.
On the web
- Go to account.apple.com and sign in.
- You may need an email code or security questions.
- Tap Upgrade Account Security and follow the onscreen instructions.
Apple says most accounts already use 2FA, and some features (including Apple Pay and Sign in with Apple) require it. If the account was created with 2FA, Apple says that extra protection cannot be removed. If you only just turned it on, Apple allows lowering account security within two weeks of enrollment. Keep a device passcode (or Mac login password) and use Face ID / Touch ID where the device supports it — that is device lock, not antivirus.
How to turn on 2-step / MFA at your bank
Bank apps do not share one menu, so there is no single Chase or Bank of America click-path to copy here.
- Open the bank app or website you already use — not a link from a text or email.
- Look under Security, Sign-in, or Privacy (wording varies).
- Turn on two-step verification, 2FA, or MFA if it is offered.
- Prefer an authenticator app over SMS when the bank offers it. SMS 2FA can fail in a SIM-swap, because the thief receives the text on the stolen number.
- If the bank does not offer MFA, treat that as a gap: do not invent steps. Use a long unique password, keep 2FA on the email that can reset the bank login, lock the phone, and ask the bank why MFA is missing — CISA's advice is to enable MFA where it exists and ask when it does not.
Do not type a bank password or code on a page you reached from a "your account is locked" text. That is a different problem from missing MFA.
Save backup codes and never share a code
Backup codes, trusted devices, and a password manager keep the household from getting locked out after a lost phone. Print or download Google backup codes and store them offline (not in the same Notes app as the password). Do not give codes to anyone who calls, texts, or emails claiming to be Google, Apple, or the bank. Google states it will not call you to verify a code. If the phone is gone, use backup codes or a trusted device — then review what to do if someone stole your phone number.
FAQ
How do I turn on 2-Step Verification for Gmail?
Open your Google Account → Security & sign-in → Turn on 2-Step Verification, then follow the prompts. Google recommends prompts over SMS. Keep backup codes.
How do I turn on two-factor authentication on iPhone?
Go to Settings → [your name] → Sign-In & Security and turn on two-factor authentication. Or sign in at account.apple.com and choose Upgrade Account Security. Apple then uses your password plus a six-digit code on a trusted device or trusted number.
Is SMS 2FA safe enough for a bank?
It is better than a password alone, but it is the weaker option. Google and CISA both treat authenticator apps (and, for Google, prompts or passkeys) as stronger than text codes. SMS can fail in a SIM-swap. Use the bank's authenticator option when it exists.
What if my bank does not offer two-factor authentication?
That is a real gap, not something this guide can invent a menu for. Keep a unique password, turn on 2FA on the email that recovers the bank login, and ask the bank why MFA is not offered.
Do I need to buy antivirus to turn on 2FA?
No. 2FA is an account setting. Microsoft Defender can be enough for many home PCs. Turning on 2FA does not require a paid suite.
Should I use an authenticator app or text messages?
Use the authenticator app (or Google prompts / a passkey) when you can. CISA describes authenticator apps as generating a new code about every 30 seconds. SMS is the fallback, not the first choice.
If you still want a paid suite
Turning on 2FA does not require a new antivirus. Microsoft Defender is a valid buy-nothing choice for many Windows households. Habits that actually help are 2FA on email, Apple, and banks; unique passwords; and never sharing a code. If the household later wants multi-device paid protection, use only these on-site paid links: TotalAV, Norton, Bitdefender, McAfee, Avast.