Security & Scams

Passwords and multi-factor authentication, done properly

Why three random words beat P@ssw0rd1, and how to turn on the one setting that blocks most account takeovers.

  • Level: Beginner
  • Time: about 8 minutes
  • Updated: 11 June 2026

Nearly every account compromise we deal with involves a reused password and no second factor. Fixing both takes an afternoon and then looks after itself.

  1. Use a password manager

    Let the manager generate and remember long random passwords, so every site has a different one. You memorise one strong master password and nothing else. The built-in ones in Edge and Chrome are far better than reusing passwords, and a dedicated manager is better still.

  2. Make the master password memorable and long

    The National Cyber Security Centre recommends three random words — something like coffee-harrogate-lantern. Length beats complexity, and you can actually remember it.

  3. Turn on multi-factor authentication everywhere that matters

    Start with your email, because that is how every other password gets reset. Then banking, accounting software, and your business Microsoft 365 or Google account.

  4. Prefer an app over text messages

    An authenticator app is safer than SMS, which can be intercepted by SIM swapping. Microsoft Authenticator, Google Authenticator or the one built into your password manager all work.

    Tip: Save the recovery codes each service gives you somewhere offline — a locked drawer is fine. They are what get you back in when a phone is lost.

  5. Check whether you have already been breached

    Enter your email address at haveibeenpwned.com. If it appears in a breach, change that password and anywhere you reused it.

  6. Stop changing passwords on a schedule

    Forced monthly changes make people pick weaker, predictable passwords. Current NCSC guidance is to use long unique passwords and change them only when there is a reason to.

Common questions

Is it safe to keep all my passwords in one place?

Yes — a reputable password manager encrypts everything so that even the provider cannot read it. The risk of reusing one password across fifty sites is far greater.