Using online services safely
Pages
Page 6 of 10
Securing your users’ accounts

Cloud services are usually designed so that users can log into them from anywhere, provided they have access to the internet. As such, you need to take steps to be confident that the user logging in is really who they say they are, and not an attacker.
If your organisation sets up user accounts for work, you should make sure that tips 1, 2 and 3 described below are applied. This will make it difficult for an attacker to gain access to these accounts and the service(s) connected to them. Options for logging into cloud services with these secured accounts are commonly available, such as ‘Sign in with Google’ and ‘Sign in with Microsoft’. You should allow your users to log into their work services using these options.
Similarly, if users have to create their own accounts for a service, they should also apply tips 1, 2 and 3, so please ensure you share them with your staff (and provide additional support if required).
-
Tip 1: Use two-step verification (2SV)
Turn on two-step verification (also known as two-factor authentication or 2FA) for all user accounts, where this option is available. 2SV requires two different methods to ‘prove' your identity when logging in. This is usually a password, plus one other method (such as a code sent to a phone, or by using an authentication app). Turning on 2SV instantly makes it much harder for an attacker to access an account, even if they know the password.
The NCSC has produced additional guidance about which 2SV method is right for your organisation. In addition, our Cyber Aware pages contain up-to-date links to the instructions on how to set up 2SV across popular online services such as Gmail, Facebook, X (Twitter), LinkedIn, and Outlook.
-
Tip 2: Use unique passwords for each account
We recommend that you use a unique password for each online account. This means that if one of your passwords is discovered, a criminal only has access to a single account (opposed to all the accounts that use the same password).
Creating different passwords for all of your accounts (and remembering them) is hard. This is where a password manager can help. A password manager (or a web browser) can store all your passwords securely, so you don’t have to worry about remembering them. This allows you to use unique, strong passwords for all your important accounts. You only need to remember one ‘primary’ password (or provide a biometric, such as your fingerprint or face ID) in order to keep all your other ones safe. The NCSC has produced detailed guidance on using password managers, including saving passwords in your browsers.
-
Tip 3: Don’t create guessable passwords
If you use single sign-on and/or a password manager, the number of passwords you have to create and remember is vastly reduced. This will usually mean that you’ll only need to remember:
- The PIN or password for your device
- The password to your staff account (for email and single sign-on)
- The ‘primary' password used to access your password manager
For these passwords that you have to remember, you need to make sure they are not easy for someone else to guess. A good rule is 'make sure that somebody who knows you well couldn't guess your password in 20 attempts'. This means avoiding the most common online passwords and information about yourself that attackers may easily discover. For example, you should avoid basing passwords on birthdays and anniversaries, or names of your family, pets, or favourite sports teams.
A good method to create a ‘long and strong’ password (that you can actually remember) is to combine three random words. If you are worried about forgetting these passwords, you may write them down as long as you can keep them safe and private.