Passwords are something most of us use every day, yet they remain one of the weakest parts of our online security. I’ve lost count of how many times I’ve heard someone say, “I use the same password everywhere because it’s easier to remember.”
That approach is understandable. Most people have dozens of online accounts and were never given a practical way to manage them. The good news is that you don’t need to memorise a collection of complicated passwords or cover your desk in sticky notes. Passphrases, password managers and multi-factor authentication can make your accounts safer without making your life harder.
Why Passwords Still Matter
Your email, social media, banking, shopping and streaming accounts may all rely on passwords as their first line of defence.
If an attacker obtains one of those passwords, the effect can extend beyond a single account, particularly if you have reused it elsewhere.
Strong password habits will not prevent every cyberattack, but they can make it considerably harder for one stolen password to become a much larger problem.
Why the Old Password Advice Was Wrong
For years, people were told that a strong password should look something like this:
P@55w0rd!2026
It contains uppercase and lowercase letters, numbers and symbols, but it is still based on the word “password.” It is also difficult to remember, easy to mistype and likely to end up written on a sticky note.
Adding predictable character substitutions does not automatically make a password strong. Length, uniqueness and unpredictability are more useful than trying to satisfy a complicated formula.
Instead of trying to memorise a short jumble of characters, consider using a passphrase.
What Is a Passphrase?
A passphrase is a longer password created from several words and a number.
For example:
Passport-Lantern-Island-Suitcase37
This travel-themed example is longer and easier to remember than a short, complicated password.
Do not use this exact passphrase. It has been published online and should only be treated as an example.
Create your own passphrase using words that are unusual together. Avoid famous quotations, song lyrics, common expressions or obvious sequences.
You should also avoid building the entire phrase around personal information that someone could discover through social media. Your birthday, hometown, favourite destination, pet’s name or favourite sporting team might feel memorable, but they may also be predictable.
Never Reuse Passwords
Password reuse is understandable. When people are expected to remember dozens of logins, using one familiar password can feel like the only realistic option.
Unfortunately, it also creates a serious weakness.
Imagine using the same password for:
- Your email
- Social media
- Online shopping
- Streaming services
- Banking
If one service suffers a data breach, attackers may try the exposed email address and password on other websites. This is commonly known as credential stuffing.
A unique password for every account helps contain the damage. If one password is exposed, it should not unlock anything else.
One password should protect one account. Nothing more.
Let a Password Manager Do the Hard Work
Whenever I recommend using a unique password for every account, the obvious question is:
“How am I supposed to remember all of them?”
The honest answer is that you shouldn’t have to.
That is the job of a password manager.
A password manager stores your login details and can generate long, unique passwords for each account. Instead of memorising every password, you primarily need to protect and remember the password or passphrase used to access your manager.
Depending on the product, a password manager may also:
- Generate strong passwords
- Autofill login details
- Synchronise passwords across devices
- Identify weak or reused passwords
- Warn you about potentially compromised credentials
Using a password manager removes one of the main reasons people reuse passwords: the difficulty of remembering them all.
Best Free Password Managers
You don’t necessarily need to pay for a password manager. Several free options can help everyday users replace reused passwords with unique ones.
Bitwarden
If you want a dedicated password manager, Bitwarden is my preferred free option.
Bitwarden publishes its source code for public inspection and provides password generation, secure storage and autofill capabilities. Its password manager is available across browser, mobile and desktop applications. bitwarden.com
For many people, it provides the essential tools needed to stop reusing passwords without requiring a paid subscription.
One of the reasons I recommend Bitwarden is its built-in passphrase generator. Rather than struggling to come up with a memorable password yourself, Bitwarden can generate one for you. Simply select Passphrase when creating a password, choose how many words you want, pick a separator such as a hyphen (-), and optionally enable capitalisation and numbers if the website requires them. It’s a simple way to create strong passwords that are much easier to remember than a random string of characters.
Built-In Password Managers
For non-technical users, the easiest choice may be the password manager already built into the device or browser they use.
Common options include:
Apple Passwords can create and save strong passwords, autofill credentials and warn about reused, weak or exposed passwords.
Google Password Manager stores passwords in a Google Account, makes them available across signed-in devices and includes a password-checking feature.
Microsoft Password Manager is built into Edge and includes password generation, synchronisation and monitoring features.
If you already live within one of these ecosystems, its built-in manager may be the simplest place to begin.
Apple Passwords, Google Password Manager, and Microsoft Password Manager also include password generators, but they generally create random combinations of letters, numbers, and symbols rather than full passphrases. While these passwords are extremely strong, some people find passphrases easier to remember and type when needed.
What About Browser Password Managers?
You will sometimes hear cyber security professionals recommend against storing passwords in a browser.
Dedicated password managers can provide additional features and greater flexibility across different browsers, devices and operating systems. However, I think it is important to be practical.
Using a browser-based password manager is far better than reusing the same password across multiple websites.
If the realistic choice is between:
- Unique passwords stored in Chrome, Edge or Apple Passwords
or
- One memorable password reused across email, shopping, banking and social media
then the password manager wins.
Perfect security should never become the enemy of good security.
The best password manager is ultimately one you trust, understand and will use consistently.
Do You Need to Change Your Password Every Month?
Usually, no.
For years, workplaces required password changes every 30, 60 or 90 days. People often responded by making small, predictable changes:
Summer2025!Winter2025!Summer2026!
That may satisfy a password-expiry system, but it doesn’t necessarily produce stronger passwords.
Current guidance says verifiers should not require periodic password changes unless there is evidence that the password has been compromised.
You should change a password when:
- You believe someone else has obtained it
- A service reports a relevant data breach
- You accidentally shared it
- It is weak or predictable
- You have reused it on another account
Otherwise, focus on creating a long, unique password and protecting the account with another authentication method where possible.
Add Multi-Factor Authentication
Even a strong password can be stolen through phishing or another form of account compromise.
Multi-factor authentication, usually shortened to MFA, requires another form of verification in addition to the password. Depending on the service, that could involve an authenticator app, security key, passkey or verification code.
MFA gives an attacker another barrier to overcome if your password is stolen. NIST encourages users to avoid relying only on passwords when other authentication methods are available.
Start with the accounts that could cause the most damage if compromised:
- Banking
- Social media
- Cloud storage
- Password manager
Your email account is particularly important because it may be used to reset passwords for many of your other services.
A Simple Password Strategy Anyone Can Use
You don’t need to rebuild your entire digital life in one afternoon.
Start with these five steps:
- Choose a password manager you will actually use.
- Protect it with a strong, unique master passphrase.
- Replace reused passwords, beginning with your email and financial accounts.
- Allow the manager to generate a different password for every account.
- Enable MFA wherever it is available.
If you discover that you have reused the same password across many accounts, don’t panic. Start with the most important accounts and gradually work through the rest.
Every reused password you replace is one less opportunity for an attacker.
Final Thoughts
Strong passwords don’t need to be impossible to remember, and they don’t need to be written on sticky notes attached to your monitor.
A memorable master passphrase, a password manager and multi-factor authentication provide a practical way to secure dozens of accounts without memorising dozens of passwords.
Built-in password managers may not satisfy every cyber security professional’s idea of a perfect solution, but they can still help everyday users make a major security improvement.
The next time you are tempted to reuse a password, remember:
One password should protect one account. Nothing more.
References
- NIST: How Do I Create a Good Password?
- NIST SP 800-63B: Authentication and Authenticator Management
- Bitwarden: Password Manager
- Apple Passwords App
- Google Password Manager
- Microsoft Password Manager in Edge
Further Reading: Cyber Security Awareness Series
If this incident taught me anything, it’s that cyber security isn’t about being perfect, it’s about being prepared.
- Why Does My Text Message Say “Unverified”? Australia’s New SMS Scam Protection Explained
- ATO Tax Scams: How to Spot One and What to Look Out For– Tax season is when Australians are most vulnerable to scams, and scammers know it.
- “Hi Dad, I Dropped My Phone”: How a Simple Text Stole $3600 And Why This Scam Is Exploding – A complete breakdown of the “Hi Dad / Hi Mum” text message scams
- The Toll Scam Text Message That Hit Me Inside the Tunnel– A practical guide to recognising and avoiding toll‑text message scams.
- Social Media Privacy Reset – A step-by-step guide to tightening your social media privacy settings.
- Think Before You Click – How to recognise suspicious links, messages, and online traps before you fall for them.
- Strong Authentication Made Simple – A clear breakdown of MFA, why it matters, and how to set it up properly.
- Everyday Device Protection – Simple settings and habits that harden your phone and laptop against common threats.
- Travel Cyber Security Tips – How to stay secure on public Wi-Fi, in airports, hotels, and while exploring abroad.
- Introducing Everyday Cyber Security – The origin of the series and the philosophy behind making cyber security accessible.



