1) use Keepass [1] and sync (via Dropbox or Google Drive) from your PC to your smartphone. It is free and remebere that LastPass had been compromised already.
2) Do not bother with adblocker - instead use properly configured Chrome with javascript OFF by default, and ON only on trusted sites, use incognito mode, set your own DNS and 204 and some other settings, also use Decentraleyes extension and switch off remote fonts etc.
3) Use DNSCrypt whenever possible - on your home router if you can, and on RaspberryPI acting as a router when traveling.
4) Block malicious hosts, trackers, advertising etc via /etc/hosts/ Block all Facebook server entirely. Block Gravatar and other trackers. Keep your own blacklist and whitelist.
This is better then adblock extensions in browser because it can block tracking and advertising also on your tablets and iPhones.
Try using dnsmasq for caching and splitting DNS so queries for Apple and Google and AmazonAWS servers are geo-smart and the rest of queries goes to DNSCrypt server in Iceland.
5) set up your own VPN (you can get VPS for that starting at 10$ per year) possibly with Strongswan IKE and use it on your mobile phone always ON. Your server should also use DNSCrypt and perhaps also act as your private DNS server.
6) Use Fastmail[2] and make use of email aliases. Fastmail have tons of various domains so I have set up alias me@nospammail.net and can use disposable addresses like first@me.nospammail.net, second@me.nospammail.net etc.
You will know who leaked your email address. You can block certain addresses easily.
7) Set text alerts for your card transactions over certain limit.
8) On Google, Microsoft and other important accounts set Pushover[3] email address for security alerts. You will be receiving immediate alerts via push on your phone
[1]: https://en.wikipedia.org/wiki/KeePass
[2]: https://www.fastmail.com/
[3]: https://pushover.net/