Two things that prevent most account compromises
Unique passwords and a second factor stop the large majority of ordinary account takeovers, and both are free to do.
Most account compromises are not sophisticated. They are credential stuffing: a password exposed in one service's breach, tried automatically against hundreds of others. It works only when the same password is reused, which is why uniqueness matters more than complexity.
A password manager makes uniqueness practical, because nobody remembers hundreds of distinct passwords. Reputable options exist at no cost, including ones built into operating systems and browsers, and the improvement comes from using one at all rather than from which.
A second factor stops the attack even when a password is known. An authenticator app or a hardware key is meaningfully stronger than codes by text message, because a text can be intercepted by a number transferred away from you — but a text-message code is still far better than nothing.
Priority order if this is being done gradually: email first, because it can reset everything else; then financial accounts; then anything holding identity documents.
Still have a question?
Describe what you are trying to work out and a member of the team will answer, or direct you to the office that makes the decision.