Passwords & MFA: A Simple Guide to Better Security
The vast majority of account breaches come down to two things: weak passwords and reused passwords. Fix those, add one extra layer, and you've closed the door on the overwhelming majority of attacks. Here's how — without the jargon.
What makes a strong password
Length beats complexity. A long passphrase of a few random words — something like three or four unrelated words strung together — is both far harder to crack and much easier to remember than a short tangle of symbols. The thing to avoid is anything guessable or findable: a pet's name, a birthday, your football team, or the classic "Password1!". Modern cracking tools chew through short or predictable passwords in moments; length is what slows them down.
Never reuse passwords
This is the big one. When one website is breached — and breaches happen constantly — attackers take those leaked email-and-password combinations and try them everywhere else. It's called "credential stuffing", and it's automated. One reused password can unlock your email, and your email can reset the password on almost everything else. Every important account needs its own unique password.
Use a password manager
Nobody can remember dozens of unique, random passwords — and you shouldn't try, or you'll end up reusing them. A reputable password manager generates and stores them securely, fills them in for you, and works across your devices, so you only need to remember one strong master password. As a bonus, it flags reused and weak entries and warns you when a site you use has been breached. It's the single biggest practical upgrade to most people's security.
Turn on multi-factor authentication (MFA)
MFA (sometimes called 2FA) asks for a second proof of identity — usually a code from an app or a prompt on your phone — on top of your password. The point is simple but powerful: even if a criminal has your password, they still can't get in without that second factor. Enable it everywhere it's offered, starting with your email (the master key to everything else) and banking. Where you get the choice, an authenticator app or a hardware key is safer than text-message codes, which can be intercepted.
A few extra habits
- Change a password immediately if a service tells you it's been breached.
- Never share passwords by email or text; use your password manager's secure sharing.
- Be alert to phishing — the slickest attack is simply tricking you into typing your password and MFA code into a fake page.
For businesses
Rolling this out across a team — enforced MFA, a shared business password manager and clear, simple policies — dramatically cuts your risk for very little cost. Our cyber security and business IT support services set it up and support your staff, so good security becomes the easy default rather than a chore.
Official guidance: Our advice mirrors the UK government’s NCSC Cyber Aware guidance — three random words for strong passwords, and two-factor authentication on your important accounts.