The standard advice goes something like this:
Use a unique, randomly generated password for every account. Enable MFA everywhere. Never reuse anything. Treat every login like it's protecting your life savings.
This advice is technically correct.
It is also, for most people, a fast path to giving up entirely.
Security burnout is real. When the guidance is so demanding that following it perfectly feels impossible, people don't follow it at all. They reuse one password everywhere, skip MFA because it's annoying, and cross their fingers. That outcome is far worse than the one the guidance was trying to prevent.
The problem isn't that the advice is wrong. The problem is that it was written for organizations managing thousands of accounts across enterprise infrastructure, not for a person trying to protect their email and their Netflix login with the same amount of mental energy.
There's a better way to think about this.
The Three Tiers
Not all accounts are equal. The risk of losing access to your Reddit account isn't the same as the risk of losing access to your bank. Treating them identically doesn't make you more secure. It makes you exhausted.
Think of it like a property you own. Your house is where you live. Your identity, your valuables, everything that would be genuinely devastating to lose. Your basement is still yours, still matters, but it's less visible day to day. Your shed out back holds things you'd miss if they were gone, but losing it wouldn't upend your life.
Your digital accounts work the same way.
Here's a framework that reflects how risk actually works.
Tier 1: Your Critical Loss Zone (The House)
This is who you are online. Compromise here is genuinely serious and potentially very difficult to recover from.
What belongs here:
Email (especially your primary address)
Banking and financial accounts
Your Apple ID or Google account
Government services (IRS, SSA, healthcare portals)
Your password manager itself
The standard here is non-negotiable:
A unique, strong password for every account. No exceptions.
A password manager to generate and store them.
MFA turned on everywhere it's available. An authenticator app is better than a text message, but a text message is still far better than nothing.
Recovery options reviewed and current.
The reason this tier gets the full treatment isn't paranoia. It's because a breach here cascades. Someone in your email can reset every other password you have. Someone in your Google account has your contacts, your photos, your location history, and potentially your payment information. The blast radius is enormous.
This is also the tier where the "use a password manager" advice actually makes sense, because the complexity is real and the stakes justify the setup cost.
Tier 2: The Aggregation Risk Zone (The Basement)
This tier is less obvious, which is part of what makes it worth thinking about carefully.
What belongs here:
Social media accounts (Facebook, Instagram, LinkedIn)
Shopping accounts with saved payment methods
Healthcare portals and insurance accounts
Work accounts and professional tools
Any account that holds a meaningful amount of personal information
The risk here isn't always direct. It's aggregation. A single social media account might not feel sensitive. But your Facebook profile, combined with your LinkedIn, combined with your Amazon order history, combined with your healthcare portal, tells a very complete story about who you are, where you live, what you own, and what your life looks like.
Attackers know this. Data brokers know this. The value of Tier 2 accounts isn't always what's in them. It's what they reveal when combined.
The standard here:
Unique passwords, ideally managed. At minimum, don't reuse Tier 1 passwords here.
MFA on social media and anything with saved payment methods.
Periodic review of what's actually in these accounts and whether it needs to be.
You don't have to be as rigorous here as Tier 1. But you do have to be thoughtful.
Tier 3: The Low-Stakes Zone (The Shed)
This is where the standard guidance quietly falls apart for most people, and where a little honesty goes a long way.
What belongs here:
Forums and community sites (Reddit, hobby forums, local groups)
Newsletter signups and content subscriptions
Free tools you use occasionally
Any account where you've shared nothing sensitive and losing access would be mildly inconvenient at most
Here's the thing NIST won't tell you: shared passwords in Tier 3 are fine.
Not shared with Tier 1. Not shared with Tier 2. But a password you use across a handful of low-stakes accounts where you've posted nothing personal and saved no payment information? That's a reasonable tradeoff. The risk is low. The recovery cost if something goes wrong is low. And preserving your mental energy for the tiers that actually matter is a legitimate security strategy.
The goal isn't perfect hygiene everywhere. The goal is protecting what actually needs protecting, without burning out in the process.
Why This Works Better Than the Standard Advice
The conventional guidance optimizes for a world where every account is equally valuable and every person has unlimited patience for security friction. Neither of those things is true.
The tiered model works because it matches the level of effort to the level of actual risk. It gives you a clear answer to the question "how careful do I need to be about this?" without requiring you to apply maximum effort to everything.
It also makes the non-negotiables easier to hold. When you're not exhausted from treating your Reddit login like a nuclear launch code, you have more capacity to actually protect your email and your bank.
That's not a compromise. That's good security thinking.
One More Thing
The tiers aren't permanent. An account can move.
If you add a saved payment method to a site that used to be Tier 3, it moves up. If you start using a work email for sensitive communications, it moves up. The framework is a way of thinking, not a fixed classification system.
Review it occasionally. Adjust as your digital life changes. And if you're not sure where something belongs, err toward the higher tier until you've thought it through.
Quick Reference
If you want to print this out or save it somewhere, here's the whole framework on one page.
The House (Tier 1) | The Basement (Tier 2) | The Shed (Tier 3) | |
|---|---|---|---|
What it is | Your identity online | Accounts that reveal a lot about you | Low-stakes, low-exposure accounts |
Examples | Email, bank, Apple ID, Google account | Social media, shopping, healthcare | Forums, newsletters, hobby sites |
Password rule | Unique, strong, in a password manager | Unique, ideally managed | Shared password is acceptable |
MFA rule | Always, no exceptions | On social media and saved payment accounts | Not required |
If compromised | Serious. Hard to recover. | Significant, especially in combination | Inconvenient. Recoverable. |
