How to create and manage strong passwords

What makes a password strong (and what weakens it)
A strong password comes down to two things: length and unpredictability. Length matters most. Each additional character multiplies the number of possible combinations an attacker has to try, so a long passphrase beats a short string of random symbols almost every time. As a rough guide, aim for at least 12 characters, and ideally 16 or more for accounts that protect sensitive data or money. Unpredictability is the second pillar. A password loses its strength the moment it follows a pattern a machine can guess. Attackers rarely sit and type guesses by hand. They use software that runs through millions of common words, names, dates, and simple substitutions in seconds. So a password like 'Motdepasse2024!' looks complex to a human but is trivial for a cracking tool that already knows people love to swap letters for numbers and stick the year on the end. What weakens a password, then, is anything predictable: dictionary words, keyboard runs like 'azerty', personal information such as a birthday or a pet's name, and reuse across sites. A password is only as safe as the least secure place you have used it. If one service is breached and you reused that password elsewhere, every account sharing it is exposed. The strongest approach combines real length with genuine randomness, and crucially, a different password for every account.
Common password mistakes to avoid
Most password problems are not exotic hacking feats but ordinary habits repeated at scale. The single biggest mistake is reuse. When the same password protects your email, your bank, and a forum you joined years ago, a leak from that forgotten forum can hand an attacker the keys to everything. A close second is relying on personal details. Your date of birth, your children's names, your favourite football club, or your postcode are often findable on social media, and they are the first things guessing tools try. Another frequent error is making tiny tweaks. Changing 'Summer1' to 'Summer2' when prompted for a new password barely slows anyone down. Writing passwords on a sticky note under the keyboard or in an unprotected note on your phone also removes any benefit a strong password gave you. People also tend to trust that complexity rules make them safe. A site demanding one capital, one number, and one symbol nudges everyone toward the same predictable shapes, so 'Password1!' is depressingly common. Finally, sharing passwords over email, chat, or by simply telling a colleague leaves a trail that lingers long after the need has passed. Avoiding these mistakes does not require technical skill, just a shift in habit: unique passwords, no personal data, and a safe place to store them.
How to create passwords you can actually remember
If you only need to remember a handful of passwords yourself, the passphrase method works well. Instead of a short, cryptic string, string together several unrelated words into a phrase that is long but memorable, for example four random words that paint an odd little picture in your mind. The randomness of the word choice is what gives it strength, so avoid famous quotes or song lyrics, which cracking dictionaries already contain. To make a passphrase even stronger, mix in a number or symbol somewhere and vary the capitalisation in a way that means something to you but not to anyone else. The key insight is that you should only ever need to memorise a very small number of passwords by hand: the one that unlocks your device, and the master password for your password manager. Everything else can be long, random, and stored. This is liberating, because it means the passwords you do memorise can be genuinely strong without the temptation to reuse them. A useful test: if you can picture the phrase in your head after saying it three times, it is memorable enough; if it looks like a word an attacker might expect, start again with less obvious words.
Why a password manager is worth using
Nobody can remember a unique 16-character random password for dozens of accounts, and that is exactly the problem a password manager solves. A password manager is a secure, encrypted vault that generates, stores, and fills in your passwords for you. You remember one strong master password, and the tool handles the rest. This changes the maths entirely. Because you no longer need to recall each password, every one of them can be long and completely random, which is precisely what makes them hard to crack. It also removes the temptation to reuse passwords, since the manager happily creates a fresh one for each site. Beyond storage, most managers help spot weak or repeated passwords across your accounts and warn you when a service you use has appeared in a known data breach. Autofill is a quiet security benefit too: because the manager only offers to fill credentials on the genuine website it saved them for, it helps protect against phishing pages that imitate a real login screen. The one habit a password manager demands is that your master password is strong and never reused elsewhere, because it protects everything inside. Treat it with the care you would give the key to your home.
Choosing and setting up a password manager
When choosing a password manager, look for a few practical qualities rather than marketing claims. It should encrypt your vault so that even the provider cannot read your passwords, offer apps for the devices you actually use, and support two-factor authentication on the account itself. Both well-regarded standalone managers and the ones built into modern browsers and operating systems can be reasonable choices; what matters most is that you use one consistently. Setting up is straightforward. Start by creating a strong, unique master password, ideally a long passphrase you have never used anywhere else, and store a recovery method somewhere safe. Then begin migrating your accounts gradually. Rather than trying to change everything in one sitting, update passwords as you log into each service over the coming weeks, letting the manager generate a new random one each time. Prioritise your most important accounts first: email, banking, and anything tied to work or finances. Your email deserves special attention because it is often used to reset the passwords of other accounts, making it a master key of its own. Once a password is saved in the manager, you can forget it entirely, which is the point.
Adding two-factor authentication for extra protection
Even a strong, unique password can be stolen through a convincing phishing page or a data breach. Two-factor authentication, often shortened to 2FA, adds a second layer so that a stolen password alone is not enough to get in. The second factor is usually a temporary code from an authenticator app, a code sent to your phone, or a physical security key you plug in or tap. Of these, an authenticator app is generally more secure than codes sent by text message, because SMS can be intercepted or redirected through phone-number takeover. Physical security keys offer the strongest protection and are worth considering for your most sensitive accounts. Turn on 2FA everywhere it is offered, starting again with your email, banking, and work accounts. Keep in mind that 2FA is only as reliable as your backup plan. When you enable it, save the recovery codes the service provides in your password manager or another safe place, so that losing your phone does not lock you out permanently. The small friction of entering a second factor is a fair trade for a barrier that stops the vast majority of account takeovers dead.
Keeping your passwords safe over time
Good password security is not a one-off task but an ongoing habit. The old advice to change every password every few months has fallen out of favour, because it tends to push people toward weaker, predictable variations. The modern approach is to change a password only when there is a reason to: if a service reports a breach, if you suspect someone has seen your credentials, or if a security check flags a password as weak or reused. Most password managers include a health check that highlights exactly these cases, so review it periodically. Stay alert to breach notifications, and act promptly when one arrives by changing the affected password and any place you might have reused it. Be cautious about where you type your passwords. Only log in on trusted devices, be wary of public or shared computers, and always check you are on the genuine site before entering credentials, since even a small typo in a web address can lead to a lookalike page. Finally, keep your devices and apps updated, because security fixes often close the very gaps attackers rely on. Consistent small actions keep your accounts safe far better than occasional dramatic overhauls.
Password habits for teams and shared accounts
Passwords get harder to manage the moment more than one person is involved, which is common in workplaces with shared tools, social media accounts, or supplier portals. The first rule is to avoid sharing passwords through email, chat, or spoken word, because those methods leave copies scattered around and offer no way to revoke access later. Instead, use a team or business password manager that lets you share access to a vault entry without revealing the password itself, and remove someone's access instantly when they change roles or leave. Wherever possible, give each person their own login rather than sharing a single account, so that actions can be traced and access managed individually. For the genuinely shared accounts that cannot be split, keep the list of people who have access short and review it regularly. When someone leaves the team, treat it as a trigger to change any shared passwords they knew. Encourage colleagues to enable two-factor authentication on shared services, and agree in advance who holds the backup codes. Finally, lead by example and make the secure path the easy path. When strong password practices are built into how the team works, security stops being a chore and becomes routine.
Example
Quick comparison of password approaches
| Approach | Strength | Best for |
|---|---|---|
| Reused short password | Very weak | Nothing; avoid entirely |
| Memorised passphrase (4+ random words) | Strong | Master password and device unlock |
| Random password from a manager | Very strong | Every individual online account |
| Password plus authenticator app (2FA) | Very strong | Email, banking, work accounts |
| Shared vault entry (team manager) | Strong and controllable | Shared team and business accounts |
FAQ
How long should a password be? Aim for at least 12 characters, and 16 or more for important accounts like email, banking, and work tools. Length matters more than complex symbols, so a long passphrase of several random words is both strong and easier to handle.
Is it safe to store all my passwords in one manager? Yes, provided your master password is strong and unique and you enable two-factor authentication on the manager itself. A reputable password manager encrypts your vault so that even the provider cannot read your passwords. The convenience lets you use a different strong password for every account, which is far safer than reusing a few memorised ones.
Do I still need to change my passwords regularly? Not on a fixed schedule. Change a password when there is a real reason: a reported breach, a suspicion someone has seen it, or a health-check warning that it is weak or reused. Forcing routine changes tends to produce weaker, predictable variations.
What is the difference between SMS codes and an authenticator app for 2FA? Both add a second layer beyond your password, but an authenticator app is generally more secure than a code sent by text message. SMS can be intercepted or redirected if someone takes over your phone number. A physical security key is stronger still and worth considering for your most sensitive accounts.
How should a team share a password safely? Use a team or business password manager that shares access to an entry without revealing the password, and remove access instantly when someone leaves. Avoid sending passwords by email or chat. Where possible, give each person their own login, and change any shared passwords when a team member departs.
Read next
Get structured security awareness guidance for you and your team.