Advanced level

Once everything else is done.


15.1 Passkeys wherever they are available

When your important services offer a passkey, use it. Passkeys rely on cryptographic authentication bound to the specific service, which makes them resistant to many classic forms of phishing.

15.2 Physical security keys

For particularly sensitive accounts, some platforms let you use a FIDO-compatible physical key.

password / username
        +
physical key
        +
Touch ID / PIN if applicable

CISA counts FIDO methods and security keys among phishing-resistant MFA solutions. For a typical user, though, it is not the first thing to buy.

Start with:

  1. unique passwords
  2. a password manager
  3. 2FA
  4. passkeys
  5. securing the phone and the recovery accounts

Those measures already deliver a considerable security gain.

Every recommendation links back to official documentation.