Skip to main content

Password Security Guide: Strong Passwords and Password Managers

PasswordsComplete Guide9 min read · June 2026
Overhead view of hands typing a password on a laptop keyboard

Weak and reused passwords are involved in the majority of account takeovers and data breaches. Despite decades of advice, most people still use passwords that can be cracked in minutes or that expose multiple accounts when a single site is breached. This guide explains why passwords fail, how to create strong ones, and how password managers make proper password hygiene practical.

Password reuse is the biggest risk

The most common cause of account takeover is not a weak password; it is a reused password. When a website is breached, those credentials are used to attack hundreds of other sites. A unique password for every account completely eliminates this risk. A password manager makes this practical.

Why Passwords Get Compromised

Credential stuffing

When a website is breached, those credentials are sold and used to try to log into other sites. If you reuse a password, one breach compromises all accounts using that password.

Brute force attacks

Attackers try millions of password combinations per second. Short passwords (under 12 characters) and common patterns ("Password1!", "Summer2024") are cracked quickly.

Phishing

You type your password into a fake website. The attackers receive it directly. Password strength is irrelevant. Two-factor authentication limits the damage even then.

Password reuse

The most common cause of account takeover. Most people use 5–10 passwords across hundreds of accounts. A single breach exposes all of them.

The NCSC Three-Word Method

The NCSC recommends three random words joined together as a memorable strong password. This method produces passwords that are longer (and therefore stronger) than most “complex” passwords, while being easier to remember.

Choose three random, unrelated words: "PurpleStapleMonkey", "CalmOceanBrick", "GardenLampPost"
Random is important: do not use words from song lyrics, sports teams, or anything linked to you
Length beats complexity: this approach produces a 15–20 character password that is easier to remember than "P@ssw0rd1!"
Use this method for accounts you need to type without a password manager: your computer login, your password manager master password

Example passwords compared

P@ssw0rd1!8 chars, predictable substitutions: cracked in seconds
CalmOceanBrick14 chars, 3 random words: would take years to brute force
7x#mK9pQzL2vBn!E16 chars random: use a password manager for this

Password Managers: The Only Practical Solution

Most people have 100–200 online accounts. It is impossible to remember a unique strong password for each one without a password manager. A password manager generates and stores a different random password for every site.

ManagerCostNotes
BitwardenFree / Paid (£8/year premium)Open source, audited, unlimited passwords and devices on free tier. Recommended for most users.
1PasswordPaid (£3/month)Polished apps, strong security record. Popular with businesses. No free tier.
DashlaneFree (limited) / PaidGood apps. Free tier limited to one device.
KeePassXCFree (open source)Vault stored locally on your device, not synced to cloud. More technical setup. Good for advanced users who want full control.

Password Manager Setup: Getting Started

  1. 1Choose a manager (Bitwarden recommended for most users) and create an account.
  2. 2Create a strong master password using the three-word method, this is the one password you must remember.
  3. 3Install the browser extension and mobile app, the extension auto-fills passwords on websites.
  4. 4Import existing saved passwords from your browser.
  5. 5As you visit sites, let the manager generate new random passwords for each one and save them.
  6. 6Enable two-factor authentication on your password manager account, this protects your entire vault.

Track your password security progress. Free.

Cyber Nova AI gives you a personalised security checklist with password and 2FA tasks mapped to the UK Cyber Essentials framework. Create a free account and see your Security Score.

Start for free →

Related guides

Frequently asked questions

What makes a password strong?

Length is the most important factor. A 16-character random password is vastly more secure than an 8-character password with symbols. The NCSC recommends using three random words as a memorable strong password: 'PurpleStapleMonkey' is far stronger than 'P@ssw0rd!'. For maximum security, use a password manager to generate fully random 20+ character passwords.

Is it safe to store passwords in a browser?

Browser-saved passwords are better than reusing weak passwords, but dedicated password managers (Bitwarden, 1Password) are more secure. Browser password storage is vulnerable to malware that targets browser data files. Dedicated password managers encrypt your vault separately, support multiple devices, and are not accessible to browser-targeting malware. For high-value accounts (banking, email), use a dedicated password manager.

Should I change my passwords regularly?

The NCSC no longer recommends routine password changes: forcing regular changes typically leads to weaker passwords (people add a number to their old password). Change your password when: you have reason to believe it has been compromised, you use it on a site that has been breached, or it is weak or reused. Do not change passwords on a timer if they are strong and unique.

What is the best free password manager?

Bitwarden is the most widely recommended free password manager. It is open source, independently audited, stores an unlimited number of passwords across unlimited devices on the free tier, and has a strong privacy track record. KeePassXC is a good option if you prefer to store your vault locally rather than in the cloud. Both are trusted by security professionals.