Your Google account is not just another login. It is the single key to your email, your documents, your photos, your files, your search history, and—on Android—even your contacts, text messages, and location history. Treat it as a ‘sensitive account’ and you are only beginning to describe what is behind that one sign-in.
The hard truth is that a password you hastily created years ago is not enough on its own. Even that single key may be due for an upgrade, and relying on it exclusively leaves a wide door open. Securing your Google account is really about building multiple layers so that a single mistake or leak does not hand an attacker everything at once.
The following guide, originally published in February 2020 and most recently updated in October 2026 by Computerworld, walks through 12 concrete steps to tighten your Google account security. Take about ten minutes to work through them, and you will have far more confidence that your data stays under your control. Below, I have expanded each step with the practical context you need to actually understand what you are changing and why.
#1 Check up on your Google account password
Everything starts with the password itself, and it is worth answering a few blunt questions about it. Is it based on your name, a partner’s or child’s name, your birthday, or your street address—anything someone could figure out by a quick search about you? Does it revolve around a common word or an easily guessable pattern? Is it short, fewer than eight characters? And do you reuse it, or a slight variation of it, across other apps, websites, or services?
If the answer to any of those is yes, the fix is straightforward: change it immediately, ideally to something long and complex that avoids personal details, common words, patterns, and anything else you use elsewhere. A reliable password manager makes this dramatically easier, whether you lean on the free Google Password Manager or a more fully featured third-party option that can generate and store unique passwords for every account.
#2 Give your Google account a second layer of protection
Even the strongest password can eventually be cracked, so the single most effective upgrade you can make is enabling two-factor authentication. This adds a second form of verification on top of your password, and it should ideally require a physical object that only you carry.
The simplest effective form is a prompt or a code generated on your phone. For those who want stronger hardware-based protection, Google supports a button pressed on a physical key—either a USB- or Bluetooth-based dongle or a security feature built into your phone, sometimes marketed under the name ‘passkey.’ There is also an option to have codes delivered by text message, but that method is relatively easy to hijack and is generally not advisable.
Whatever path you choose, that second layer makes it enormously harder for anyone to reach your account even if they somehow obtain your password. If you have not set it up yet, Google’s 2-Step Verification page is where you get started.
#3 Make sure you are prepared to prove your identity
If Google detects suspicious activity, it can require you to verify your identity before letting you sign back in. The problem is that the recovery information on file may be out of date or missing entirely if you have not reviewed it in a while—or ever.
Open Google’s account security site and look under the ‘How you sign in to Google’ section. You should see two options there: a recovery phone and a recovery email. If the value next to either one is not current and correct, click it and update it right away. These are the lifelines Google uses to confirm you are you when something looks wrong, so they must actually reach you.
#4 Give yourself a selfie-centric failsafe
Security is a constant game of ‘what if,’ and this step covers the scenario where your normal recovery methods simply do not work. As of August 2026, Google offers a way to verify your identity for an individual, non-company-connected account using a selfie video—a short several-second clip of you looking at the camera and turning your head in different directions.
The idea is to record an initial selfie video now, which takes about two minutes, so that if you are ever locked out you can submit a new selfie video and let the system match it against your original to confirm your identity. To set it up, go to the video verification page within Google account settings on any device with a camera and follow the prompts. Google walks you through recording the video and confirms once it is saved and active.
This is only a last-resort pathway, kicking in when your other sign-in methods fail, but it can be the difference between recovering your account and losing it entirely.
#5 Get by with a little help from your friends
Alongside selfie verification, Google now lets you authorize a trusted friend or family member to confirm your identity for you. This feature is called Recovery Contacts, and it is quick to set up.
Start on the official Google Recovery Contacts settings page, confirm your password to authenticate, and then click the button to add a new recovery contact. The person you choose must accept the request within a week before they become active.
Once set up, the mechanism works like this: after you fail to sign in, Google lets you select the contact, and a random number appears on your screen. At the same time, your contact sees three different numbers on their own device. To complete authentication, they pick the number that matches what you are relaying to them, which only works if they are genuinely in contact with you—confirming the request was actually triggered by you.
Importantly, your contact never gains access to any of your Google account data. They simply provide an extra pathway to prove your identity in a worst-case lockout. Note that this feature is available only on an individual Google account, not a company-managed Workspace account, since a Workspace admin can already help facilitate account recovery in that situation.
#6 Review the third-party services with access to your account
Whenever you set up an app that interacts with Google—on your phone, your computer, or within a Google service like Gmail or Docs—that app is granted some level of access to your data. Depending on the situation, that access can range from a few activities in one service to everything in your Gmail, Calendar, or Drive, and in some cases to everything across your entire account.
It is far too easy to click through the permission prompts without thinking, so take a moment to review exactly which apps can see which data. Visit Google’s third-party app access overview and scan the list of connected services. If you spot anything you no longer use or do not recognize, click its line and then remove it.
Trusted apps are fine to keep connected, but the goal is to revisit this list regularly and keep it as tight as possible. Every app with access is another potential entry point.
#7 Review the devices with access to your account
Beyond apps, you have almost certainly signed into your Google account on a variety of physical devices over the past months and years. Once a device is signed in at the system level, it often stays connected and able to reach your account—even long after you have stopped using it.
You can close that loop by visiting Google’s device activity page. Any device listed there that you no longer use or do not recognize can be signed out immediately: click the three-dot menu icon within its box and end the session. Clearing out old or unfamiliar devices removes stale access you may not have realized was still open.
#8 Look over app permissions on your phone
On Android, certain system-level permissions can effectively control access to areas of your Google account data, because services like Google Contacts and Google Calendar sync that data between your phone and the cloud. That makes your phone’s permission settings directly relevant to your Google account security.
To review them, open the Security & Privacy section of your phone’s system settings and find the line labeled ‘Permission manager.’ Depending on your device, you may need to tap ‘Privacy controls’ first. If you cannot find it, search your settings for the phrase ‘permission manager.’ From there, you can see which apps are authorized for each permission type and revoke access from any app where that level of access does not seem necessary.
#9 Look over extension permissions in your browser
On the desktop, browser extensions can add useful capabilities to Chrome or another browser—but they can also expose your privacy. An extension might request access to anything from your complete browsing history to your system clipboard, and it can often read and change data on the sites you are viewing, either across all sites or only specific ones.
This is not inherently bad if the extension is reputable and asks only for what it needs. But even well-intending developers sometimes request broader access than their software requires. An extension that merely enhances Gmail or lets you save articles for later could end up with visibility into everything you do in your browser, potentially exposing the sensitive data kept inside your Google account to external parties for no good reason.
To check this, type chrome:extensions into your Chrome address bar, or find the equivalent extensions management page in another browser. For each extension, open its ‘Details’ or ‘Options’ and inspect the ‘Permissions’ and especially the ‘Site access’ section. If an extension only needs a specific site but is set to ‘On all sites,’ change it to ‘On specific sites’ so it can only see a limited list of URLs.
Keep in mind that many extensions genuinely need broad access to work, so adjust these settings cautiously. If tightening an extension breaks it, you can always return and loosen it again. Firefox users should note that Firefox does not support this level of granular permission control, so if an extension there accesses more than you are comfortable with, your main option is to uninstall it entirely.
#10 Get rid of any mobile apps and browser extensions you do not need
While you are reviewing third-party add-ons, take stock of everything installed on both your phone and your computer and consider how much of it you still actually use. The fewer open windows you leave on your Google account, the better—and if you are not using something, there is no reason to keep it connected.
Uninstalling abandoned apps and removing unused extensions is a simple way to shrink your attack surface without any trade-offs. It is the digital equivalent of locking a door you were already forgetting was open.
#11 Set up or confirm your virtual Google will
Planning for the worst is never pleasant, but just as you would arrange for your physical and financial affairs, a virtual will for your Google account makes things far easier for your loved ones if you are ever gone. For company-managed Google Workspace accounts, an organization can take control of an account when its user is no longer able to access it. For an individual account, no such automatic system exists.
Google’s Inactive Account Manager fills that gap. Open it and you can set how many months must pass without any sign of activity before Google acts, along with the email addresses and phone numbers it should use to confirm with you during that period. You can then provide the email addresses of people you want to be notified once your inactive period begins.
You can also specify exactly which areas of your account those contacts may access, leave them a message, and optionally set up a broad autoreply to anyone who emails you once the inactive period starts. Even if you have done this before, revisit it periodically to confirm the contacts and the specific account areas are still accurate.
For the last piece, click each listed contact’s email address and choose ‘Edit apps & services.’ That screen shows everything from Contacts and Calendar to Google Chat, Google Photos, and location history, letting you see what is currently selected and add or remove areas. A common gotcha: newer account features often are not pre-selected because they did not exist when you last reviewed the options, so you may need to manually check them to ensure they would be shared.
#12 Think about Google’s Advanced Protection Program
The final step is not for everyone, but it can be decisive for certain users. For anyone at higher risk of a targeted attack, Google offers an elevated security tier called the Advanced Protection Program, aimed at business leaders, IT admins, activists, journalists, and others who are in the public eye and more likely to be targeted.
The program imposes heavy-duty restrictions to make your account extremely hard to breach, with the core requirement being a physical security key the first time you sign in on any new device. That means in addition to your password, you need an approved key—either one built into your phone or a standalone dongle—to reach your email, documents, or other areas.
There are real trade-offs. You generally cannot connect most third-party apps to your account, including those that need access to Gmail or Drive, which can create friction—such as signing into an Android TV device or using most third-party email clients with Gmail. If you ever get locked out, the recovery process is more involved and can take multiple days. Only you can decide whether that added inconvenience is worth the extra assurance.
To enroll, visit Google’s Advanced Protection Program website. With a personal account you can set yourself up in minutes; with a paid Workspace account, your plan administrator must enable Advanced Protection for the organization first. The enrollment flow will quickly tell you whether it is already available for your account, and if not, you can reach out to your admin to ask.
What This Means for You
The big takeaway is that Google account security is a layered system, not a single password. Each of these steps closes a different door: a strong, unique password blocks the obvious attacks; two-factor authentication stops most credential theft; current recovery options ensure you can get back in when Google flags trouble; the selfie video and Recovery Contacts cover the scenario where your normal methods fail; and trimming connected apps, devices, and extensions removes stale access that attackers could exploit.
For most people, steps one through ten are the core work, and they take only about ten minutes to complete. The Advanced Protection Program is worth considering only if you are specifically at higher risk of being targeted, since it adds real friction to daily use. The Inactive Account Manager is a sensible ‘set it and forget it’ step that protects your loved ones, though it is an uncomfortable thing to think about.
The one habit that ties it all together is periodic review. Set a yearly reminder to revisit these settings, and apply the same discipline to other areas like your Android security settings if you use an Android device. The goal is to get into a place where you do not have to think about your Google account security again for a long while.
How to Get It
All of these settings live inside your Google account, accessible from any browser by signing in and navigating to myaccount.google.com. The password page, 2-Step Verification page, account security page, third-party app access overview, device activity page, video verification page, Recovery Contacts page, and Inactive Account Manager are all reachable from there, and the Advanced Protection Program has its own dedicated site. On Android, the Permission manager lives in your phone’s Security & Privacy settings, and on the desktop, extension management is reached through chrome:extensions in Chrome or the equivalent menu in another browser.
Nothing here requires a software update or a new version—these are account and device settings that are available to any Google user today. The only feature with a specific rollout note is the selfie video verification, which Google made available for individual accounts as of August 2026.
Source: Computerworld
Over to you: Have you already turned on two-factor authentication on your Google account, or is that still on your to-do list?



