Five Things You Can Do Today to Protect Your Financial Life Online

As financial advisors, we talk a lot about protecting your portfolio — diversification, risk tolerance, long-term planning. But there is another kind of risk that is easy to overlook until something goes wrong: the risk that someone gains access to your accounts, your identity, or your money through your phone or laptop.

Online scams and fraud target people of every age. But the financial damage is not distributed equally. In 2024, the FBI found that Americans over 60 filed more fraud complaints than any other age group — and lost more money, averaging $83,000 per victim.

That is not because older adults are less careful. It is because they tend to have more accumulated wealth, are targeted more deliberately by criminal operations, and, when something does go wrong, have fewer years to earn back what was taken.

The good news? Many attacks succeed not because they are especially sophisticated, but because basic protections were never put in place. You do not need to be a tech expert. You can start with five important things.

1. Make Sure Your Devices Are Up to Date

This one sounds too simple to be important, but it is critical.

Many hacks exploit a known weakness in your phone's or computer's software — often a flaw the manufacturer has already fixed and released a patch for. If you have not installed the update, the door is still open.

What to do:

  • iPhone: Settings → General → Software Update

  • Android: Settings → System → Software Update

  • Mac: Apple menu → System Settings → Software Update

  • Windows: Start → Settings → Windows Update

If an update is waiting, install it today. Then turn on automatic updates so your devices stay current without you having to think about it.

2. Change Your Email Password

Your email account is the master key to your digital life. If someone gets into your email, they may be able to request password resets for other accounts you own — including your bank, brokerage, and investment portal — and lock you out of them. It is one account that deserves your strongest protection.

Many people have had the same email password for years or use a version of a password they use elsewhere. Neither is safe.

What to do:

Go to your email account's security settings and change your password. Use a long, unique passphrase — for example, three or four unrelated words combined with a number and a symbol:

PurpleTrain!Coffee42

If you need to write the new password down, store it somewhere secure at home — not in your phone or an email draft. Better yet, if you use a password manager, let it generate and securely save the password for you.

The important thing is that your email password is long, unique, and not used anywhere else.

3. Get a Password Manager — And Actually Use It

This is one of the biggest changes most people can make. It is also one we hear the most resistance about, so let us address that upfront: a password manager might feel complicated to set up, but once it is working properly, it can make your digital life dramatically simpler.

A common mistake is using the same password — or a few variations of it — everywhere. The moment one of those accounts is breached, every other account using the same password may be exposed too.

A password manager is a secure digital vault. You remember one strong master password to open it. The manager remembers a different, long, random password for every other account you have — and fills them in automatically when you log in.

What to do:

Choose a reputable password manager. Options include:

  • Bitwarden

  • 1Password

  • Dashlane

  • LastPass

Download one through the App Store, Google Play, or the provider's official website. Create an account and set a strong master password using the passphrase method above.

Once it is set up, work through your financial and other important accounts over the following week, replacing reused passwords and saving each new one in the manager as you go.

We also recommend setting up your password manager as a browser extension, which makes it easier to autofill passwords securely.

4. Lock Your Devices — Every One of Them

A lost or stolen phone without a secure lock screen can provide access to your email, bank accounts, and other sensitive information. Yet many people still skip this basic step or rely on an easily guessed PIN.

What to do:

  • Enable Face ID, fingerprint authentication, or a 6-digit PIN on your phone.

  • Set your screen to lock automatically after 1–2 minutes of inactivity.

  • On your laptop, require a password when it wakes from sleep.

This takes only a few minutes and provides an important layer of protection if your device ever ends up in the wrong hands.

5. Turn On Two-Factor Authentication

Even a strong password can be stolen — through a data breach, phishing email, or other means that have little to do with how careful you are. Two-factor authentication, or 2FA, adds another layer of protection.

When you log in, you enter your password as usual. Then you verify your identity a second way, often with a code sent to or generated by your phone. Even if someone has your password, that second step can prevent them from getting into your account.

Start by turning on 2FA for your email account. Then consider using an authenticator app, such as Google Authenticator or Microsoft Authenticator. Authenticator apps generate codes directly on your device and generally provide stronger protection than text-message codes.

Most importantly, enable 2FA on your financial accounts too. Check the security settings for your bank, brokerage, and advisor portal and turn on the strongest form of authentication each offers.

A Word on Scams

The technical protections above matter enormously — but so does knowing how criminals try to get around them.

Scams targeting consumers today range from phishing emails impersonating your bank or the IRS to phone calls claiming there is a problem with your Social Security number. Increasingly sophisticated scams may even use AI voice technology to sound like a family member in distress.

What nearly all of them have in common is urgency. They are designed to make you act before you have time to think.

One of the most effective defenses is simply to slow down. If something feels off, hang up. Do not click the link. Do not provide personal information. Instead, verify the request through a phone number or website you look up yourself.

The FTC's free Pass It On resources are also a helpful reference for learning about common scams.

The Three Habits That Make It Last

Once you have done the initial setup work, staying safer online comes down to three basic habits:

  • Update promptly. When your phone or computer tells you there is an update, install it. Do not keep postponing it.

  • Never reuse passwords. One account, one unique password, saved in your password manager. Let the manager generate passwords for you.

  • Verify before you click or respond. Suspicious email? Do not click. Suspicious call? Hang up. Go directly to the company's website or call a number you find yourself.

One More Thing: Freeze Your Credit

A credit freeze can prevent someone from opening a new line of credit in your name. Even if a thief has your Social Security number, a freeze makes it much harder to open a credit card or take out a loan using your identity.

Freezing your credit is free, and you can temporarily lift the freeze whenever you need to apply for credit. To fully protect yourself, place a freeze with each of the three major credit bureaus: Equifax, Experian, and TransUnion.

We Are Here If You Have Questions

We are not cybersecurity professionals — we are financial advisors. But that means we care about protecting everything you have built, not just the investments in your portfolio.

If you receive a suspicious email, get a call that does not feel right, or think something may have gone wrong with one of your accounts, call us — and call your bank. We would much rather answer a question about a suspicious text than help you recover from a wire transfer that should not have happened.

You can also turn to these trusted resources for more information:

  • FTC Pass It On: ftc.gov/PassItOn — plain-language guides to common scams, free to print and share

  • ReportFraud.ftc.gov: report a scam to the FTC, or call 877-382-4357

  • IdentityTheft.gov: step-by-step recovery guidance if your identity is stolen

  • AARP Fraud Watch Network: free resources for everyone; helpline at 1-877-908-3360

  • Maryland Identity Theft Unit: oag.maryland.gov; 410-576-6491


Online Security FAQs

What are the most important things I can do to protect my financial accounts?

Start with five basics: keep your devices updated, use a strong and unique email password, use a password manager, lock all your devices, and turn on two-factor authentication (2FA) for your email and financial accounts.

Why is my email password so important?

Your email is often the gateway to your other accounts. If someone gains access to it, they may be able to reset passwords for your bank, brokerage, and other financial accounts. Your email password should be long, unique, and never reused anywhere else.

What makes a strong password?

Longer is generally better. Consider a passphrase made from several unrelated words, numbers, and symbols. Most importantly, use a different password for every account.

Do I really need a password manager?

A password manager makes it much easier to use a different, strong password for every account without having to remember them all. You remember one strong master password, and the manager securely stores the rest.

What is two-factor authentication?

Two-factor authentication, or 2FA, requires a second form of verification in addition to your password. That means a stolen password alone may not be enough for someone to access your account. Whenever possible, turn on 2FA for your email, bank, brokerage, and other important accounts.

Are software updates really that important?

Yes. Updates frequently include fixes for known security vulnerabilities. Turn on automatic updates when possible and install updates promptly when your phone, computer, or tablet alerts you that one is available.

How can I tell if an email, text, or phone call is a scam?

Be especially cautious when a message creates a sense of urgency, asks you to send money or provide personal information, or tells you to click a link immediately. If something feels off, stop and verify it independently. Go directly to the organization's official website or call a number you look up yourself.

What should I do if I receive a suspicious message from my bank?

Do not click links or call phone numbers provided in the suspicious message. Instead, contact your bank using the number on your card, statement, or the bank's official website.

What is a credit freeze, and should I have one?

A credit freeze restricts access to your credit file, making it much harder for someone to open a new credit card or loan in your name. It is free and can be temporarily lifted when you need to apply for credit. You will need to freeze your credit separately with Equifax, Experian, and TransUnion.

What should I do if I think my identity or financial information has been compromised?

Act quickly. Contact your bank, financial institutions, and financial advisor, change affected passwords, and review your accounts for suspicious activity. You can also report fraud to the FTC and use IdentityTheft.gov for step-by-step recovery guidance.

Where can I learn more about scams and identity theft?

Trusted resources include the FTC's Pass It On program, ReportFraud.ftc.gov, IdentityTheft.gov, the AARP Fraud Watch Network, and the Maryland Attorney General's Identity Theft Unit.

Next
Next

How to Use Health Insurance, an FSA, and an HSA to Pay for Fertility Treatments