Passwords and multi-factor authentication, done properly
Why three random words beat P@ssw0rd1, and how to turn on the one setting that blocks most account takeovers.
Nearly every account compromise we deal with involves a reused password and no second factor. Fixing both takes an afternoon and then looks after itself.
-
Use a password manager
Let the manager generate and remember long random passwords, so every site has a different one. You memorise one strong master password and nothing else. The built-in ones in Edge and Chrome are far better than reusing passwords, and a dedicated manager is better still.
-
Make the master password memorable and long
The National Cyber Security Centre recommends three random words — something like coffee-harrogate-lantern. Length beats complexity, and you can actually remember it.
-
Turn on multi-factor authentication everywhere that matters
Start with your email, because that is how every other password gets reset. Then banking, accounting software, and your business Microsoft 365 or Google account.
-
Prefer an app over text messages
An authenticator app is safer than SMS, which can be intercepted by SIM swapping. Microsoft Authenticator, Google Authenticator or the one built into your password manager all work.
Tip: Save the recovery codes each service gives you somewhere offline — a locked drawer is fine. They are what get you back in when a phone is lost.
-
Check whether you have already been breached
Enter your email address at haveibeenpwned.com. If it appears in a breach, change that password and anywhere you reused it.
-
Stop changing passwords on a schedule
Forced monthly changes make people pick weaker, predictable passwords. Current NCSC guidance is to use long unique passwords and change them only when there is a reason to.
Common questions
Is it safe to keep all my passwords in one place?
Yes — a reputable password manager encrypts everything so that even the provider cannot read it. The risk of reusing one password across fifty sites is far greater.