The way most accounts get broken into isn't clever hacking — it's a password you reused, leaked from some other site's breach, then tried everywhere else. Fix that one habit and you close the biggest hole.

The three rules

  1. Never reuse passwords across important accounts.
  2. Longer beats complicated. A passphrase like correct-horse-battery-staple is stronger and easier to type than P@ss1!
  3. Turn on two-factor authentication everywhere it's offered — especially email and banking.

Use a password manager

You can't remember 100 unique passwords, and you shouldn't try. A password manager generates and stores them, so you only remember one strong master password.

💡

Protect your email first

Your email is the master key — password resets for everything go there. Give it the strongest password and two-factor before anything else.

If you've been in a breach

  • Check whether your email appears in known breaches.
  • Change the password anywhere you reused it.
  • Turn on two-factor on those accounts.
💡

Related

If an account's already been compromised, see what to do when your account is hacked.

Mistakes that quietly undo all your work

You can set up a manager and still leave a back door open. The usual slip-ups aren't obvious, which is exactly why they catch people out.

  • Reusing your master password somewhere else. The one password protecting all the others should exist nowhere but your head. If it's also your email login, you've merged your two most important accounts into one weak point.
  • A strong password on a weak email. Your email is the master key to everything, because that's where reset links land. Lock it down first, not last.
  • Storing 2FA codes in the same manager. Convenient, yes, but if someone gets into the vault they get both factors. Keep them separate where you can.
  • Small tweaks on an old password. Adding a 1 or a ! to a leaked password fools nobody. Attackers try those variations first.

A worked example: securing one account properly

Say you're fixing your online banking. Here's the full loop, start to finish, so you can see what "done properly" actually looks like:

  1. Open your password manager and use its generate button. Take a long random string, not something you thought up.
  2. Log into the bank, change the password, and let the manager save it. Don't type it in manually anywhere else.
  3. Turn on two-factor authentication in the bank's security settings. Pick an authenticator app over SMS if it's offered.
  4. Save the backup or recovery codes it gives you somewhere offline, like a note in a drawer.
  5. Log out and log back in once to confirm the new password and the second step both work.
💡

How to know it actually worked

When you log in fresh, you should be forced to enter the second factor. If it lets you straight in with just the password, 2FA isn't really on yet. Test it before you move on.

The realistic effort involved

People put this off because they imagine a lost weekend. It isn't. Setting up a manager takes fifteen minutes. After that you don't fix everything at once, you fix accounts as you naturally log into them over a few weeks. The five that matter most, email, bank, main shopping account, primary social account, and your phone or laptop account, are worth a focused hour up front. Free password managers cover most people fine, and paid tiers are usually a few pounds a month if you want family sharing or extras.

Written by Ashutosh Sharma

Frequently asked questions

What makes a password strong if length matters more than symbols?
Length beats complexity. A long string of random words or characters is far harder to crack than a short one crammed with symbols. Aim for something well past a dozen characters. A random three or four word phrase you can actually picture is stronger than P@ss1! and much easier on you if you ever have to type it.
Is it safe to let my browser save passwords instead of a manager?
It's better than reusing one password everywhere, so it's a fine starting point. The catch is that browser storage is usually only as protected as your device login, and it doesn't travel as cleanly across phones and laptops. A dedicated manager adds a separate master password and works everywhere, which is why it's the stronger long-term home.
What happens if I forget my master password?
For most managers, there's no reset, that's the trade-off for real security. If it's gone, the vault is gone. So write the master password down once and keep it somewhere physically safe, like a locked drawer or with important documents. Some managers also offer an emergency recovery kit, print it and store it offline the day you sign up.
How often should I actually change my passwords?
Routine forced changes every few months are largely out of favour now, they just push people toward weak, predictable variations. Change a password when there's a reason: a breach notice, a device you've lost, or a login you shared and want to lock down again. Otherwise a long, unique, unshared password can sit untouched for years.

People also ask