Passwords Your Staff Will Remember and Attackers Won't Guess
Complex password rules produce passwords people forget, write down and reuse. Here is simpler advice that is actually more secure: length, uniqueness, a password manager and a second factor.

For years, password advice meant rules: at least one capital, a number, a symbol, and change it every ninety days. The result was passwords like Summer2026!, then Autumn2026!, written on sticky notes and reused everywhere. They satisfied the rules and helped attackers.
Modern guidance is simpler, and more secure.
1. Length beats complexity
A long password is far harder to crack than a short, complicated one. The easiest way to make one people can remember is a passphrase: several unrelated words strung together. The UK's National Cyber Security Centre recommends combining three random words, for example teapot-glacier-violin.
Avoid the obvious: song lyrics, famous quotes, your company name, your children's names or your football team. Attackers try those first.
2. Never reuse a password
This is the rule that matters most. When any website is breached, attackers try the leaked email and password combinations on email providers, banks and company systems. If you reuse passwords, one breach anywhere becomes a breach everywhere.
You can check whether your email address has appeared in a known breach at haveibeenpwned.com. If it has, change that password and any others that match it.
3. Let a password manager do the remembering
Nobody can remember a unique, strong password for every account. A password manager can. It creates and stores a different password for every site, fills them in for you, and you only need to remember one strong passphrase to unlock it. Many also warn you if a saved password appears in a breach.
4. Add a second factor
Multi-factor authentication means a stolen password alone is not enough. Use an authenticator app or a security key where you can; text-message codes are better than nothing but can be intercepted. Start with email, because email is how most other accounts are reset.
5. Stop forcing regular changes
Current guidance, including from the US National Institute of Standards and Technology, advises against forcing people to change passwords on a schedule. Forced changes lead to predictable patterns. Change a password when there is a reason to, such as a suspected compromise.
A policy staff can follow: long passphrases, a unique password for every account, a password manager provided by the organization, multi-factor authentication everywhere it is offered, and changes only when something has gone wrong.
What never to do with a password
- Share it with a colleague, even a manager, even IT
- Type it into a page you reached from an email link
- Send it by email, text or chat
- Save it in a document or spreadsheet on your desktop
Making it stick
Good password habits are simple once people understand why they matter. CyberWatch AI includes short training lessons on passwords, account security and phishing, and simulations show whether staff will type a password into a page that only looks genuine, which is the moment all of this advice is really tested.


