A password is only one part of account access. Recovery may depend on an email inbox, a phone number, a trusted device, an authenticator, a security key, backup codes, a recovery contact, identity checks, or an administrator. If those dependencies live on the device that was lost, damaged, evacuated without, or locked out, a secure account can become unavailable to its legitimate owner.

The answer is not a printed list of every password in an evacuation bag. The safer approach is a recovery map: protect accounts strongly, understand each provider’s legitimate fallback paths, avoid one-device dependency, and store only the minimum recovery material in controlled locations.

This checklist is for preparing your own household accounts. It does not help bypass another person’s account, device lock, organizational controls, or legal authority.

A closed notebook and a sealed envelope on a clean desk beside a laptop, nothing readable on either.
Recovery codes are useless in the place you can't get into. Write down where yours live while you still have access.

Protect the accounts that reset everything else

Prioritize accounts by dependency, not brand:

  1. primary email used for resets;
  2. password manager or credential vault;
  3. mobile carrier account and phone number;
  4. device-platform account;
  5. financial and payment accounts;
  6. work, school, health, insurance, and government services;
  7. cloud storage and backups;
  8. communication and social accounts that could impersonate the owner.

Draw arrows between them. If the password manager requires email, email requires the phone, and the mobile-carrier account requires a code sent to that same phone, the household has a circular dependency. The map should record provider names and recovery methods, not live secrets.

Complete the recovery checklist while access is normal

For each priority account:

  • confirm the recovery email belongs to the household, is still accessible, and is protected independently;
  • confirm the recovery phone number is current;
  • remove unknown or obsolete recovery methods, sessions, devices, and forwarding rules;
  • enable MFA using the strongest practical method offered;
  • generate provider-issued backup codes when supported and store them under controlled access;
  • register a second legitimate factor, recovery contact, trusted device, or security key when the provider permits it;
  • understand whether generating new backup codes invalidates old ones;
  • record the official account-recovery starting point without copying the secret into the same map;
  • note whether an employer, school, family organizer, or service administrator controls recovery;
  • review alerts and notifications so a recovery change will be noticed.

Do not test recovery by intentionally locking the account or removing the only working factor. Confirm settings while signed in, then use provider-supported checks that do not risk losing access.

Use a password manager without creating a new single point of failure

CISA and NIST recommend password managers because they help create and retain long, unique credentials. Before placing the household’s accounts in one, evaluate:

  • how the vault is encrypted and synchronized;
  • which devices and operating systems are supported;
  • whether MFA is available for the vault;
  • how emergency or family access works;
  • what happens if the master credential is forgotten;
  • what recovery requires and what the provider cannot recover;
  • whether a local vault needs its own backup schedule;
  • how exports are protected and securely removed after a migration;
  • how another authorized household member would begin recovery.

Do not assume every password manager can or should recover the master password. A design that prevents provider recovery may improve confidentiality while increasing lockout risk. Document that tradeoff before adoption. Never put the only vault-recovery secret inside the vault it unlocks.

Separate factors across failure domains

Two factors on one phone may still provide strong everyday authentication, but they do not create continuity when that phone is gone. Where a service permits it, consider a layered set:

Recovery element Everyday role Continuity risk to address
authenticator or passkey on primary device convenient strong access device lost, damaged, or uncharged
second registered device or hardware key alternate legitimate factor must be secured and periodically checked
provider backup codes limited emergency access high-value secrets; may be single-use or replaced
recovery email or phone provider fallback can become a takeover route if weak or obsolete
trusted recovery contact human fallback where supported contact changes, availability, social engineering
organizational administrator managed-account recovery policy, working hours, identity verification

The exact hierarchy is provider-specific. A security key that works for one account may not replace a phone for another. A recovery contact may help reset an account without seeing its contents. Read the current official instructions before recording assumptions.

Create an offline recovery map

The map may include:

  • account purpose and provider;
  • masked username or email where necessary;
  • official support or recovery route;
  • factors enrolled, described by type rather than secret value;
  • location category for sealed backup codes or keys;
  • trusted contact or administrator role;
  • last review date;
  • what should happen if the phone number changes;
  • what must be revoked after a device is lost.

Do not include complete passwords, full financial account numbers, private keys, seed phrases, or unsealed backup codes in a broadly accessible binder. Use the offline credentials guide to separate the map from the most sensitive material.

Plan the first hour after losing a device

Before the loss, write a short response sequence:

  1. Check immediate personal safety and confirm whether the device is merely misplaced.
  2. Use the operating system’s official lost-device feature from a known device if it was enabled in advance.
  3. Lock or mark the device lost when appropriate; understand that remote actions may wait for connectivity.
  4. Contact the carrier through a verified channel if the phone or SIM may be misused.
  5. Secure primary email, password manager, financial accounts, and any account showing suspicious activity.
  6. Revoke the missing device or session through official settings when the consequence is understood.
  7. Replace affected MFA methods and generate new backup codes after access is restored.
  8. Review alerts, forwarding, recovery details, purchases, and sessions.
  9. Notify employer or school IT immediately for a managed device or account.
  10. Record actions, times, and provider case numbers.

Erasing a device remotely may protect data but can affect tracking, evidence, or recovery. Follow the current platform, employer, insurer, and law-enforcement instructions for the actual situation. Do not confront a suspected thief.

Account recovery is also a phishing moment

An attacker can exploit the urgency of a lost phone. Treat unsolicited “device found,” “account locked,” “fraud department,” and “support” messages as untrusted until independently verified.

  • Navigate through a known app or manually entered official address.
  • Do not read a one-time or backup code to a caller.
  • Do not approve a push notification you did not initiate.
  • Do not install remote-control software for an incoming support contact.
  • Do not move money to a “safe account.”
  • Do not search for support and assume the first advertisement is legitimate.
  • Do not provide a recovery key to prove ownership; the key may be the access itself.

FTC guidance emphasizes reviewing recovery details, signing out unknown devices, changing compromised passwords, and enabling 2FA after retaking a hacked account.

Include disability, caregiving, and estate continuity

A recovery plan should work for the people who will use it. Consider visual, hearing, dexterity, memory, language, and cognitive access needs; reliance on a caregiver; and whether a device contains assistive-technology settings or communication tools.

Use provider-supported family, legacy, delegate, or emergency-access features when available. A caregiver’s practical knowledge does not automatically grant legal access. Estate documents, organizational policy, and applicable law may control access after incapacity or death. Keep the household’s digital roles aligned with the family communication plan.

Review after every dependency change

Update the map when the household changes:

  • phone number or carrier;
  • primary email;
  • password manager;
  • trusted device or security key;
  • recovery contact;
  • employer, school, bank, insurer, or health portal;
  • family or caregiving role;
  • device platform;
  • provider recovery policy.

Also schedule a quarterly review. Confirm dates and factor types without exposing the secrets during a group meeting. Replace stale sealed material through the provider and securely destroy superseded copies where appropriate.

Minimum viable recovery plan

Today, secure the primary email, verify its recovery information, enable MFA, record the official recovery route, and create one independent fallback permitted by the provider. Then repeat for the password manager, carrier, device account, and financial services. Use the MFA phone-loss guide for factor-specific continuity and the digital continuity hub for the full household system.

Sources reviewed

  • CISA: Use a Password Manager to Create and Remember Strong Passwords
  • NIST: How Do I Create a Good Password?
  • Federal Trade Commission: How to Recover a Hacked Email or Social Media Account; Use Two-Factor Authentication; How to Protect Your Phone From Hackers

Sources reviewed July 14, 2026. Provider recovery features and security settings change frequently. Follow the current official instructions for the exact account and device, and use organizational recovery for managed systems.