Weak and reused passwords are still behind a huge share of breaches — and the fix is refreshingly simple. Swapping fiddly passwords for long "passphrases", and letting a password manager remember them, is one of the easiest security upgrades you and your team can make. Here's how.
A long passphrase — four or more random words — is both stronger and easier to remember than something like "P@ssw0rd1". A password manager then creates and stores a different strong password for every account, so you only have to remember one. Paired with MFA, this shuts down the most common way accounts get broken into.
If you use the same password everywhere and just one site is breached, attackers take that leaked email-and-password combination and try it on your other accounts — banking, email, everything. It's called credential stuffing, it's fully automated, and it's relentless. One old leak from a forgotten forum can quietly hand someone the keys to your most important logins.
The good news is you can check whether your details have already turned up in a known breach — our short guide to checking if your email's been breached walks you through it in a couple of minutes.
For years we were told to make passwords "complex" — a capital here, a symbol there, a number on the end. The trouble is that "P@ssw0rd1" is both weak and annoying: short enough for a computer to crack, yet fiddly enough that you can never remember which symbol went where.
A passphrase flips this around. Something like "correct-battery-harbour-sunrise" is very hard to crack because it's long, but easy for you to remember because it's just four words you can picture. Length is what matters most — and you stop forgetting which symbol went where, because there's barely a symbol to forget.
A password manager is a secure app that does the remembering for you:
The trade-off is wonderfully simple: you only ever remember one strong master passphrase, protected with MFA — and the manager handles the hundreds of others.
Our free IT Health Check reviews password practices, MFA and breached-credential exposure across your team — then shows you the simple, high-impact changes that shut down the most common way accounts get broken into. It's the easiest big win in security, made easy.