Enable one or two-foundation verification wherever possible, have fun with strong, novel passwords, and remain aware on phishing efforts