How to enable 2FA on all your business accounts (in 30 minutes)
Two-factor authentication blocks 99% of account takeover attempts. The 30-minute walkthrough to enable it on every account that matters.
- A smartphone for an authenticator app
- A password manager — ideally 1Password or Bitwarden
Step by step
- 01
Install an authenticator app
Use an app, not SMS. SMS 2FA is broken by SIM-swap attacks. Best options: 1Password (if you already pay for it), Authy (free, multi-device), or Google Authenticator.
- 02
Start with the email account
Your email is the master key — most password resets go there. Gmail: myaccount.google.com → Security → 2-Step Verification → set up. Add the authenticator AND a backup code printout.
- 03
Then your password manager
1Password / Bitwarden settings → Security → 2FA. Without this, your password manager IS the single point of failure.
- 04
Then financial accounts
Stripe, your bank, PayPal, Wise. All support authenticator-based 2FA. Stripe also supports hardware keys — use one if you handle real money.
- 05
Then social + cloud accounts
Meta Business, Google Ads, TikTok Business, AWS, Cloudflare, GitHub, Notion. Hijacked ad accounts cost businesses thousands per incident.
- 06
Save backup codes
Every service gives you 8-10 one-time backup codes. Print them or save in your password manager as a Secure Note. Without these, losing your phone = locked out forever.
- 07
Buy a hardware key for your most critical accounts
YubiKey ($50) for your email + bank + AWS. Hardware keys are the only 2FA method phishing-resistant against modern attacks.
We set up domains, email, SSL, security and integrations so nothing breaks.
Book a tech call