Guides

Part of Account security: requirements and practical steps for 2027

Account security changes 2027: facts and context

Account security decays on its own: the drift list, how to handle an announced change without being caught by a fake version, and what ages worst.

Nobody can tell you what your providers will change next year. What can be described is how account security decays, which is predictable, and how to handle an announced change without being caught by a fake version of it.

Your setup does not get worse because anyone attacked it. It gets worse because the world around it moved and nothing moved with it. The habits that stay current regardless of what any provider changes are collected in CISA's cybersecurity best practices.

What to take away

  • Security decays on its own. A configuration that was right two years ago is describing a life you no longer have.
  • Announced changes are a phishing opportunity. Act on them through the app, never through the message.
  • Life events, not calendar dates, are the triggers that matter.

The drift list

Everything here happens quietly and none of it produces an alert.

  • A phone number you gave up. Every account still using it for reset now sends codes to somebody else eventually.
  • An email address you stopped controlling. A former employer's address, a school address, a domain that lapsed.
  • A device you sold, lost, or handed on. Sessions and remembered devices frequently outlive ownership of the hardware.
  • An app you stopped using. Its permissions did not stop.
  • A person who left. A role, a shared password, or a page admin nobody removed.
  • A company that was acquired or closed. The access it holds transfers with the assets, under whatever policy arrives with the new owner.
  • A second factor method being retired. Providers do withdraw older methods, and the ones who do not act get moved to whatever the default is.
  • A new method arriving. Passkeys and similar options appear in accounts you have had for years, and nobody is going to enable them for you.

Read that list against your own accounts once a year and you have most of what a security review produces.

Handling a change your provider announces

Providers do change how sign-in works, and when they do you will hear about it in a notification, an in-app banner, or an email. That is exactly the moment when a fake version of the same message works best, because the real one has made you expect it.

Three habits cover it.

Never act from the message. Open the app or type the address you already use. A genuine change will be waiting for you there, and a fake one will not exist.

Do the setup before the deadline, not on it. Changes with an enforcement date produce a rush, and a rush is where mistakes live. Doing it early also means the fake versions arriving later are obviously irrelevant to you.

Keep a working way in during the transition. Register the new method while the old one still functions, confirm you can sign in with it, and only then remove the old one. Deleting a working method first is how people lock themselves out.

The general form of that first habit is the callback rule described in phishing scams. It applies to your own providers exactly as much as to strangers, and the fake version of a genuine announcement is the shape covered in CISA's guidance on recognizing and reporting phishing.

A wooden field gate closed with a chain, a small private sign fixed to the top rail
Photo: Padlock and barbed wire, Wikimedia Commons, CC BY-SA 2.0.

The events that should trigger a full pass

Time is a poor trigger. Circumstances are a good one.

  • Moving house or country. New number, new address, possibly a new set of services.
  • Changing job. Work identities disappear, and anything registered to them goes with them.
  • A separation or a dispute. Shared accounts, shared devices, saved sessions, and a person who knows your answers to everything.
  • A death in the family. Both the practical problem of reaching accounts and the decisions you should make about your own.
  • Becoming publicly visible. A new role, a piece of coverage, a growing audience. More material about you means more convincing approaches.
  • Any incident nearby. A breach at a service you use, or a friend's account being taken over.
  • A child getting their own device. A new set of accounts that will be linked to yours.

Each of these changes who holds access and what is publicly known about you, which are the two inputs to everything else.

The parts of your setup that age worst

Some things degrade faster than others and deserve attention first.

Recovery contacts age the fastest, because they are set once and reference addresses and numbers from an earlier life. Connected apps age next, because permissions accumulate and nothing prompts removal. Shared access ages badly in organizations, because people leave more often than anyone audits. Backup codes age quietly: codes printed years ago may have been superseded, and a set you cannot find is not a backup.

Passwords, oddly, age well. A strong unique password does not become weaker with time. What makes it a problem is reuse and breach, not age, which is why scheduled rotation for its own sake tends to produce weaker passwords rather than stronger ones.

The rest of the maintenance sequence, and the order to work through it, is in account security.

Re-doing this without it taking a weekend

The first pass is long. Subsequent ones are short if you leave yourself something to compare against.

Keep one plain note per important account: the recovery address and number, the second factor in use, where the backup codes are, what is connected, and the date. Next time you are not investigating, you are comparing. Anything different is either a change you made or a question worth asking.

Do the settings side at the same time, since platform redesigns move both, and the reasoning for that pairing is in privacy setting changes. Where the account is a social one, use the sequence in the social media account security audit rather than wandering through menus.

Common questions

Should I change my passwords every few months?

Not on a schedule. Change immediately if a service reports a breach, if the password is reused, or if you suspect anything. Otherwise a strong unique password can stay where it is.

My provider is retiring the method I use. What is the safe order?

Add the new method, sign in with it once to confirm it works, print fresh backup codes, then remove the old method. Never the other way round.

A message says my account will be closed unless I update my security. Is it real?

Treat it as false until you have checked through the app. Whether or not a genuine change exists, the message is not how you should find out, and a real deadline will still be there when you look.

How do I keep track of accounts I have forgotten about?

Your password manager's list is the honest inventory, and a pass through it once a year will find services you have not thought about since. Close what you do not use rather than leaving it dormant. The tooling side is covered in account security tools.

Does any of this change if I use a work-managed device?

Yes. Some of these controls are set by whoever administers the device, and personal accounts should be kept off it where you can. Assume anything you do there is visible to the organization.

More in Guides

Features

Account security: requirements and practical steps for 2027

Account security ordered by the way accounts are actually lost: the email account, the recovery route, second factors, sessions and connected apps.

Costs

Account security case studies: findings and lessons

Account security case studies for arrangements rather than individuals: shared logins, client access, a departure, and helping an older relative.

Reviews

Account security examples: what the cases show

Account security incidents written from inside them: the code, the stale recovery address, the reused session, and the moment each one turned.

Maintenance

Account security risks: warning signs and safer responses

Account security risk ranked by blast radius: the email account first, then the phone number, and the failures that involve no attacker at all.