PASSWORD SECURITY: HOW TO PROTECT YOUR ACCOUNTS
A password is one of the main barriers between you and an account, device or service that you do not want another person to access.
Good password security is not about creating a complicated password and then forgetting about it. It is about using credentials that are difficult to guess, not reusing them across important accounts, protecting them from phishing and compromise, and making sure the rest of the account security system is strong.
The central principle is simple:
ONE EXPOSED PASSWORD SHOULD NOT BECOME THE KEY TO YOUR DIGITAL LIFE.
1. WHAT IS A PASSWORD?
A password is authentication information used to help establish that you are authorised to access an account or service.
It may be combined with other protections such as MFA, passkeys, security keys or device authentication.
A password is therefore not merely a word you type. It is a security credential.
Treat it accordingly.
2. WHAT MAKES A PASSWORD STRONG?
A strong password should be difficult for an attacker to guess or obtain through common attack techniques.
Useful characteristics include:
- Sufficient length
- Uniqueness
- No predictable personal information
- No common or widely used password
- No obvious sequence or pattern
- No reuse across important services
Length matters because a longer credential can provide a much larger search space than a short one.
3. PASSWORDS AND PASSPHRASES
A passphrase is a longer password-like credential that may use several words or another memorable structure.
For example, a long memorable phrase can be easier to remember than a short string of random characters.
The important principle is not whether a password looks complicated.
The important questions are:
Is it long enough? Is it unique? Is it unpredictable? Can I protect it safely?
4. WHY PASSWORD REUSE IS DANGEROUS
Imagine you use the same password for:
- Social media
- Shopping
- Banking
- Work
If one service suffers a breach and your password is exposed, an attacker may try that same credential against your other accounts.
This is called credential stuffing.
One compromised service can therefore become the starting point for attacks against completely different services.
5. PASSWORD SPRAYING IS DIFFERENT
Credential stuffing uses known username-and-password combinations.
Password spraying works differently.
An attacker may try one or a few commonly used passwords against many accounts instead of trying many passwords against one account.
This can help attackers avoid some account-lockout controls.
The lesson is important:
Do not assume that a password is safe simply because nobody knows your exact username-password combination yet.
Use a unique, sufficiently strong credential.
6. YOUR PRIMARY EMAIL IS ESPECIALLY IMPORTANT
Your primary email account may be connected to password resets for many other services.
If an attacker controls your email, they may be able to request or intercept recovery messages for other accounts.
Protect your primary email with particular care:
- Unique password
- Strong MFA
- Secure recovery methods
- Reviewed sessions and devices
- Current recovery information
- Security notifications
Your email may function as part of the recovery infrastructure for your digital identity.
7. DO NOT BUILD PASSWORDS FROM PUBLIC INFORMATION
Avoid using information that another person could discover through social media, conversation or public records.
Examples include:
- Your name
- Date of birth
- Phone number
- Child's name
- Pet's name
- Favourite team
- Business name
- Home location
- Common nickname
A password can feel personal while actually being predictable.
8. PASSWORD MANAGERS
A reputable password manager can help you create and store different credentials for different services.
This is useful because remembering a unique password for every account can be difficult.
A password manager itself becomes an important account, so protect it carefully.
Where supported:
- Use strong authentication.
- Enable MFA.
- Understand recovery options.
- Keep your devices protected.
- Avoid sharing the vault or master credential.
The goal is to reduce password reuse without creating a new weak point.
9. BROWSER-SAVED PASSWORDS
Browsers can offer password storage and autofill features.
These can be convenient, but understand what account or device protects the stored credentials.
On a shared or compromised device, stored credentials may become a risk.
Use device locks, account security and appropriate browser protections.
Before allowing a browser to save a sensitive credential, understand who can access that device profile.
10. NEVER SHARE YOUR PASSWORD
Someone may say:
“I am support.”
“I need your password to fix the problem.”
“Give me the password so I can verify your account.”
Do not surrender your password simply because someone claims to be authorised.
Use the organisation's official support process instead.
Your password is authentication information, not proof that another person deserves access to it.
11. WATCH FOR PHISHING
A strong password cannot protect you if you voluntarily enter it into a fraudulent login page.
Before entering a password:
- Check the actual domain.
- Confirm that you opened the service intentionally.
- Be cautious with links in unexpected messages.
- Prefer the official application or a known address.
- Be suspicious of urgency and threats.
A professional logo, familiar name or convincing page is not proof that the login page is genuine.
12. FAKE PASSWORD-RESET MESSAGES
Attackers may send messages such as:
“Your password will expire today.”
“Your account has been locked.”
“Confirm your password immediately.”
The message may contain a link to a fake login page.
Instead of following the message:
Open the official service yourself.
Then check whether the account actually requires attention.
13. PASSWORDS AND MFA WORK TOGETHER
A strong password reduces the chance that a credential can be guessed or reused successfully.
MFA provides another authentication layer if the password is stolen.
The two protections solve different parts of the problem.
For important accounts, use a strong unique password together with strong MFA where supported.
Do not interpret MFA as permission to become careless with passwords.
14. WHEN SHOULD YOU CHANGE A PASSWORD?
Change a password when there is a meaningful reason, such as:
- You believe it has been exposed.
- You entered it into a suspicious website.
- You shared it with another person.
- You receive a credible breach notification.
- Someone may have accessed the account.
- The password was reused and another service was compromised.
After suspected compromise, changing the password should be part of a wider review rather than the only action.
15. WHAT TO DO IF YOUR PASSWORD WAS STOLEN
Act promptly.
- Open the official service yourself.
- Change the password.
- Review active sessions and sign out unfamiliar ones where supported.
- Review MFA settings.
- Review recovery methods.
- Review connected applications.
- Check security notifications.
- Change the same password anywhere else it was reused.
- Investigate how the credential may have been exposed.
If financial or identity-related harm is involved, preserve useful evidence and use the appropriate official reporting or support channels.
16. DO NOT PANIC-RESET EVERYTHING WITHOUT THINKING
When people hear that a password may be compromised, they may click links in panic and enter credentials into the first page they see.
That can create another problem.
The safer sequence is:
STOP → OPEN THE OFFICIAL SERVICE → VERIFY → SECURE → REVIEW
Do not let fear turn a possible incident into a phishing success.
17. PASSWORD SECURITY AFTER USING A SHARED DEVICE
If you used a shared or public computer for a sensitive account:
- Sign out.
- Avoid saving the password.
- Do not leave the browser signed in.
- Review the account later from a trusted device if necessary.
- Review active sessions if you are uncertain.
If you suspect that the device was unsafe, consider changing the credential through a trusted device.
18. PASSWORD SECURITY AFTER A DEVICE IS LOST
A lost device may contain saved credentials, active sessions or password-manager access.
Depending on the device and service:
- Lock the device remotely.
- Locate it if appropriate.
- Remove the device from important accounts.
- Review sessions.
- Secure important credentials.
- Contact the relevant service when necessary.
Do not assume that a password is the only thing that protects an account.
19. PASSWORD BREACHES
A service may experience a breach in which account information or credentials are exposed.
If you receive a credible notification that your password was exposed, do not reuse that password elsewhere.
If you used the same credential on other services, change those accounts too.
The most important lesson is:
A password exposed at one service should not expose another service.
20. DO NOT TRUST “PASSWORD CHECKER” LINKS BLINDLY
You may encounter websites claiming they can test whether your password is weak or compromised.
Be cautious about entering a real password into an unknown website merely to test it.
A service asking you to reveal your actual password may create the very risk you are trying to measure.
Use reputable security tools and never submit a live credential to an untrusted checker.
21. PASSWORDS AND ACCOUNT RECOVERY
Password security cannot be separated from recovery security.
If an attacker cannot guess your password but can compromise your recovery email or recovery phone, the account may still be at risk.
Therefore review:
- Recovery email
- Recovery phone
- Backup codes
- MFA
- Trusted devices
- Account-recovery options
A secure password with weak recovery is incomplete protection.
22. PASSWORDS AND CONNECTED APPLICATIONS
An account can have access pathways that do not depend on typing the password every time.
Connected applications, tokens and sessions may continue to matter after a credential change depending on the service.
After suspected compromise, review connected applications and active sessions as well as the password.
23. COMMON PASSWORD MISTAKES
Mistake 1: “One password is easier.”
Why this is dangerous: One exposed credential can affect several accounts.
Mistake 2: “I only changed one character.”
Why this is dangerous: Predictable variations may still be guessed or reused.
Mistake 3: “My password is strong, so I can enter it anywhere.”
Why this is dangerous: Phishing can steal strong passwords.
Mistake 4: “Support asked for my password.”
Why this is dangerous: An unsolicited request may be social engineering.
Mistake 5: “I changed the password but checked nothing else.”
Why this is dangerous: Other access pathways may remain.
Mistake 6: “I will save the password in a public note so I do not forget it.”
Why this is dangerous: Convenience can expose a sensitive credential.
24. HOW TO BUILD A STRONG PASSWORD ROUTINE
For important accounts:
- Use a unique credential.
- Prefer a sufficiently long password or passphrase.
- Avoid personal information.
- Store it securely.
- Enable MFA.
- Keep recovery information current.
- Review sessions and connected applications when appropriate.
- Change it promptly after credible compromise.
- Never give it to an unsolicited person.
25. WHICH ACCOUNTS SHOULD YOU PRIORITISE?
Start with accounts that could be used to compromise other accounts.
A useful order is:
- Primary email
- Banking and financial accounts
- Cryptocurrency services and wallet-related accounts where applicable
- Cloud storage
- Work accounts
- Social media
- Shopping and marketplace accounts
- Other important services
Your security priorities should reflect the potential impact of compromise.
26. YOUR PASSWORD CHECKLIST
□ Is this password unique to this account? □ Is it sufficiently long and difficult to guess? □ Does it avoid obvious personal information? □ Is it stored securely? □ Is MFA enabled? □ Is my recovery information current? □ Would I recognise a phishing login page? □ Have I avoided entering this credential into an unknown checker? □ Do I know how to review sessions after suspected compromise? □ Do I know how to revoke connected access if necessary?
27. A PRACTICAL EXAMPLE
You receive a message saying:
“Your email account will be closed today. Confirm your password immediately.”
The message contains a professional logo and a login button.
You feel pressure to act quickly.
The safer response is:
STOP.
Do not click the link.
Open your email provider's official application or known website yourself.
Check whether there is actually a security problem.
If the message was fraudulent, report or delete it as appropriate.
The lesson is not merely “use a strong password.”
The lesson is:
PROTECT THE PASSWORD AND PROTECT THE MOMENT IN WHICH YOU USE IT.
28. IF YOU REMEMBER ONLY ONE THING
A password should not be a reusable key for your entire digital life.
Use unique credentials. Protect your primary email. Use MFA. Avoid phishing. Review the wider account when compromise is suspected.
