You almost certainly have "set up real account security" sitting on a to-do list somewhere, untouched for a year or two. Not because it's hard — because it never seems to end: unclear where to start, how long it takes, or when you finally get to cross it off. That changes tonight. What follows isn't philosophy, it's a route: a concrete sequence for one sitting, with a time estimate on every step. Grab your phone and your laptop and work through it as you read.

Ninety minutes, give or take, in three blocks. By the end of the evening you'll have an encrypted password vault, two-factor authentication turned on for everything that matters, and a printed backup plan for the day your phone ends up at the bottom of a lake. This isn't a one-time heroic effort — it's a foundation that needs almost no attention afterward.

What you need before you start

Five minutes of prep saves an hour in the middle. You need: phone and computer within reach at the same time, access to your email (your master account — the key that unlocks everything else), a piece of paper and a pen — an actual physical sheet, not a phone note — and one calm, unhurried hour. If it's 11:50 pm and you're up early tomorrow, push this to a weekend evening, but pick an actual time slot, not "sometime." A task with no date doesn't exist.

Hour one: the vault and the master password

Install a password manager — there are solid free and open-source options with good track records that sync between your phone and your computer. Put it on both devices right now; that's two minutes.

Then comes the single most important moment of the whole evening: the master password. It's the one password you'll ever need to hold in your head, and it has to be both long and memorable at once. Here's a method that works: pick four or five random, unrelated words and string them together with a couple of digits and symbols mixed in. Not a song lyric, not a birthday with an exclamation mark — genuinely random. Twenty-plus characters built this way can't be brute-forced in any practical time frame, and a human can still memorize it after a handful of repetitions.

Don't write the master password in a notes app, in an email to yourself, in a file on the desktop. It lives only in your head and on that piece of paper, which you then put somewhere physically safe — not out in plain sight, but not somewhere you'll forget either. This is the one exception to "never write down a password": without it, the vault stays locked even to you.

Now build a habit: every time you log into something and see that same old password you've had since college, replace it with one the manager generates, right in the moment. Don't try to churn through all two hundred accounts tonight. Over a month or two, everything you actually use gets updated, and the abandoned accounts you never touch again simply don't matter.

Our record: this is exactly the compartmentalization principle behind Maat — no single failure should be allowed to bring down the whole. A unique password per account turns one breached forum from a catastrophe into an isolated, forgettable incident.

Hour two: 2FA, in the right order

A password is one door. Two-factor authentication is a second one behind it, and it's the single thing most likely to stop an account takeover even after a password has already leaked in some breach elsewhere. The order you enable it in matters, because not every account carries the same weight.

Start with email. It's the master key — through it, almost anything else can be reset, your bank included. Open your email provider's security settings, find two-step verification, and turn it on. Fifteen minutes.

Next, your bank and anything touching money — cards, brokerage accounts, payment apps. Then move through the rest of what matters: cloud storage, social accounts, work logins. Three to five minutes each if you go one at a time without getting distracted.

Wherever a service offers a choice — a code by text message or a code from an authenticator app — pick the app. SMS codes are far better than nothing, but in rare, targeted attacks they can be intercepted through a SIM-swap. An app generates the code locally on your device, with no phone carrier in the middle, and that closes the gap. If a service offers a physical security key, that's the next tier up, but don't wait for it — turn on whatever's available today and upgrade later.

Backup codes: don't close the tab yet

When you enable 2FA, almost every service shows you backup recovery codes — a short list of one-time keys for the day your phone is lost, broken, or stolen. This is the step people skip most often, because it feels like a formality. It isn't one — without it, a lost phone locks you out of your own email and bank just as thoroughly as it would lock out an attacker.

Write those codes on that same piece of paper, next to the master password, and store it in one safe physical place — not a screenshot on the phone you might be the one to lose. Five minutes per account, but it's exactly this step that turns your security setup into real sovereignty instead of self-imprisonment. You can always get back in yourself — just not instantly, and not over the internet.

Do this today

Don't wait for "a full evening to do everything." Right now, in twenty minutes: install a password manager on your phone, come up with a master password made of four random words and write it on paper, then turn on two-factor authentication for your email through an authenticator app, and save the backup codes on that same sheet.

That closes the single most dangerous door — the one everything else can be reset through. Everything else on this list gets done over the coming week, one account at a time. But these twenty minutes aren't "someday." They're now.