Keep Your Accounts Secure - Simple Password Tips

Wednesday 29 October 2025 - Tom Wilkinson

Strong passwords aren’t just for work - they protect your personal accounts too. I've put together this short guide which will run through a few simple ways to stay more secure at work and at home.

Change Password Regularly

Only 34% of internet users change their passwords monthly and around 44% of internet users say they “rarely or never” change their passwords. 
 
By changing your password regularly (for example every 2-3 months) you shorten the time a stolen password can be used — it reduces risk because it limits the ‘window of opportunity’ for attackers.

Use Strong Passwords

Regular changes of passwords are only effective when used alongside strong passwords.

Passwords should be:

  • Long- At least 12 characters long. Attackers use automated tools to guess billions of password combinations per second, the longer the password the more secure it is.
  • Complex - includes a mix of uppercase and lowercase letters, numbers, and symbols. This makes guessing your password exponentially harder and slower.
  • Unique — used only for one account (never reused across different sites). If one password is compromised it doesn't immediately affect your other accounts.
  • Unpredictable — doesn’t contain names, birthdays or company info. So it cant be easily guessed by people you know.
  • Memorable for you — easy for you to remember, but impossible for others to guess.

For example: BlueSky!Run.Fast#42 or Coff55&Rainb0ws$2025

Use Multifactor Authentication (MFA) - not just for work

MFA is very important and very secure. It adds an extra step when you sign in so when you input a password it will require an additional authentication method before signing you in. It’s like needing both a key and a code to open a safe. This could be a code on a text message or email, face, fingerprint or an authenticator app. If you have MFA it also warns you about attempted log in attempts so if you randomly get a code or notification you know someone has tried to access your account and you should immediately change your password. According to Microsoft over 99.9% of automated attacks were blocked by MFA.

Useful Tools

Password managers - Apps like Bitwarden (free plan) and KeePass are useful tools that can create and store strong passwords so you don't have to remember them. Web browsers like Chrome, Edge, safari also have password managers that save your passwords.

Passwords & Email check - haveibeenpwned lets you check if your email has been exposed in any data breaches and you can set up alerts / notifications for when your email appears in one. On the website you can also check if any of your passwords have appeared in any data breaches.

The password managers in Chrome, Edge, safari also notify you if it has detected a password has been compromised. And on iPhones you can see compromised passwords in the built-in 'Passwords' app. Or if you are on Android it is in passwords.google.com