Blog/Account security

Passwords Your Staff Will Remember and Attackers Won't Guess

Complex password rules produce passwords people forget, write down and reuse. Here is simpler advice that is actually more secure: length, uniqueness, a password manager and a second factor.

CyberWatch AI27 September 2026 · 2 min read
A combination padlock resting on a laptop keyboard beside bank cards

For years, password advice meant rules: at least one capital, a number, a symbol, and change it every ninety days. The result was passwords like Summer2026!, then Autumn2026!, written on sticky notes and reused everywhere. They satisfied the rules and helped attackers.

Modern guidance is simpler, and more secure.

1. Length beats complexity

A long password is far harder to crack than a short, complicated one. The easiest way to make one people can remember is a passphrase: several unrelated words strung together. The UK's National Cyber Security Centre recommends combining three random words, for example teapot-glacier-violin.

Avoid the obvious: song lyrics, famous quotes, your company name, your children's names or your football team. Attackers try those first.

2. Never reuse a password

This is the rule that matters most. When any website is breached, attackers try the leaked email and password combinations on email providers, banks and company systems. If you reuse passwords, one breach anywhere becomes a breach everywhere.

You can check whether your email address has appeared in a known breach at haveibeenpwned.com. If it has, change that password and any others that match it.

3. Let a password manager do the remembering

Nobody can remember a unique, strong password for every account. A password manager can. It creates and stores a different password for every site, fills them in for you, and you only need to remember one strong passphrase to unlock it. Many also warn you if a saved password appears in a breach.

4. Add a second factor

Multi-factor authentication means a stolen password alone is not enough. Use an authenticator app or a security key where you can; text-message codes are better than nothing but can be intercepted. Start with email, because email is how most other accounts are reset.

5. Stop forcing regular changes

Current guidance, including from the US National Institute of Standards and Technology, advises against forcing people to change passwords on a schedule. Forced changes lead to predictable patterns. Change a password when there is a reason to, such as a suspected compromise.

A policy staff can follow: long passphrases, a unique password for every account, a password manager provided by the organization, multi-factor authentication everywhere it is offered, and changes only when something has gone wrong.

What never to do with a password

  • Share it with a colleague, even a manager, even IT
  • Type it into a page you reached from an email link
  • Send it by email, text or chat
  • Save it in a document or spreadsheet on your desktop

Making it stick

Good password habits are simple once people understand why they matter. CyberWatch AI includes short training lessons on passwords, account security and phishing, and simulations show whether staff will type a password into a page that only looks genuine, which is the moment all of this advice is really tested.

Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.