Password, MFA and account security

For all employees and individuals: replace old password rules with current NIST guidance, choose phishing-resistant MFA and passkeys, and recover fast when an account is compromised.

For: All employees and individuals who sign in to work or personal accounts, including office managers, payroll and finance staff, small business owners and IT administrators

  • 1.5 contact hours
  • 5 modules
  • 6 interactives
  • 3 job aids
  • Updated October 11, 2026

What you will be able to do

  • Identify how accounts are compromised, including credential stuffing, password spraying, phishing, malware, MFA fatigue, SIM swaps and recovery abuse, and recognize the warning signs of a takeover.
  • Create and manage passwords according to NIST SP 800-63B-4, using long passphrases, unique passwords for every account and a password manager.
  • Choose the strongest available MFA method, including passkeys and security keys, and respond correctly to unexpected prompts and requests for codes.
  • Protect email as the master account by securing recovery settings, and apply safe practices to shared and administrator accounts.
  • Respond to a suspected account compromise in the right order and report it to the right place: employer, bank, IC3, the FTC or IdentityTheft.gov.

Learn how accounts really get broken into, from credential stuffing and password spraying to push bombing and SIM swaps, and the specific defense that stops each one. You will apply NIST SP 800-63B-4 password guidance, set up a password manager, choose the strongest MFA an account offers, understand passkeys, lock down email recovery settings and handle shared and admin accounts safely.

This deep-dive course is for anyone who signs in to anything: staff at every level, small business owners who set their office's password rules, and administrators who manage shared or privileged accounts. It is short enough to finish in one sitting and practical enough to change your habits that day.

Old rules such as forced 90-day changes and mandatory symbols are out; length, uniqueness, password managers and phishing-resistant MFA are in. This course explains why, using current NIST and CISA guidance, and gives you an account security checklist, a phishing pocket card and an incident report template for when something goes wrong.

What you’ll be able to do Monday morning

  1. Move your work email password into your employer-approved password manager and replace any reused passwords.
  2. Turn on the strongest MFA your email offers, preferably a passkey or security key.
  3. Check your email for forwarding rules, connected apps and outdated recovery phone numbers.
  4. Deny and report any sign-in prompt you did not start, and never share a code with a caller.
  5. List the shared logins you use and move them into individual accounts or a shared vault.

Curriculum

5 modules · 20 lessons · about 1.5 contact hours

01How do accounts actually get broken into?Free preview16 min
  1. What is an account takeover, and why do attackers want yours?
  2. What are the main attack methods?
  3. How do you know an account may be compromised?
  4. Why do attackers target ordinary staff accounts, not just executives?
  • Matching activity: Which attack is behind this?

Diagram · In practice checklist · 3-question knowledge check

02What makes a password strong in 2026, and how do you manage dozens of them?16 min
  1. What does current NIST guidance say about passwords?
  2. How do you create a password you can actually remember?
  3. Why is a password manager the single biggest upgrade?
  4. What about passwords you must share, type often or set for others?
  • Spot the issue: Spot the outdated password rules

Diagram · In practice checklist · 2-question knowledge check

03Which kind of MFA should you use, and what are passkeys?17 min
  1. What is MFA, and why does it stop most account takeovers?
  2. What are passkeys, and why are they phishing resistant?
  3. How do you handle unexpected prompts and codes?
  4. What if you lose your phone or security key?
  • Branching scenario: The midnight prompts
  • Decision tree: Pick the strongest sign-in option

Diagram · In practice checklist · 3-question knowledge check

04Why is your email the master key, and how do you protect recovery, shared and admin accounts?16 min
  1. Why is email the account to protect first?
  2. How do you secure recovery settings?
  3. What are the rules for shared and admin accounts?
  4. How should organizations handle access when people join, move or leave?
  • Spot the issue: Audit a shared-account list

Diagram · In practice checklist · 2-question knowledge check

05What should you do when an account is compromised, or might be?16 min
  1. What are the first steps for a work account?
  2. How do you recover a personal account?
  3. How do you stay ahead of the next breach?
  4. How should you talk about a compromise with coworkers and family?
  • Self-assessment: How strong is your account security?

Diagram · In practice checklist · 2-question knowledge check

Final assessment: 17 questions, 80% to pass, then your certificate

Try it now, no account needed

The midnight prompts

A branching scenario from this course. Your choices are not saved.

Free sample activity

The midnight prompts

You are Fern, a dental office manager. It is late at night and your phone starts buzzing.

Inside the course

Practice activities

  • Matching activity1
  • Spot the issue2
  • Branching scenario1
  • Decision tree1
  • Self-assessment1

Job aids you keep

  • Account Security ChecklistChecklist
  • Phishing Checklist: Sign-Ins, Prompts and Codes (Pocket Card)Pocket card
  • Account Compromise Incident ReportTemplate

Credit and approval status

Certificate of completion

This course awards a certificate of completion for 1.5 contact hours of instruction. It has not been approved or accredited by IACET, any licensing board, any state agency or any other accreditor. It is general security awareness training aligned with public guidance from NIST and CISA. Check with your employer, licensing board or professional body whether this course can count toward your security-awareness training records or continuing education.

A pathway we are pursuing or may pursue is IACET accreditation of our course development process. No approval exists today; we will show an approval on this page only after it is granted.

Our full approvals list

Questions about this course

Who is this course for?

Everyone who signs in to work or personal accounts. It is especially useful for office managers and small business owners who set password rules, payroll and finance staff whose accounts attract fraud, and IT administrators who manage shared and privileged accounts. No technical background is needed.

Does this course count toward continuing education?

You receive a certificate of completion for 1.5 contact hours of instruction. The course is not currently approved or accredited by IACET, a licensing board or any other accreditor. Check with your employer or board whether it can count toward your training or continuing education records.

Is the advice to stop changing passwords every 90 days really current?

Yes. NIST SP 800-63B-4, finalized in 2025, says systems should not require scheduled password changes, and should force a change when there is evidence of compromise. Your employer's systems may still use older rules; follow your workplace policy and raise the question with IT.

How long does it take?

Plan on about 90 minutes, including five modules, interactive activities, knowledge checks and a 17-question final assessment with an 80% pass mark. You can pause and return at any time.

Will I need to install anything?

No installation is required to take the course. The activities and job aids help you set up a password manager, MFA and passkeys afterward, using tools your employer approves for work accounts.

Does the course teach hacking techniques?

No. It explains attack methods only at the level needed to recognize and prevent them. The focus is prevention, recognition, recovery and reporting.

This course is general education and account security awareness training from CE Courses Hub. It is not legal, technical or professional advice and does not replace your employer's security policies, your licensing board's rules, or advice from a qualified professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.