CYBER WELFARE

Protect your Digital Privacy

Your Digital Key: How to Create Strong Passwords

Additional resource for the lesson “Your Digital Key: How to Create Strong Passwords” — Online Security course

A password is the key to your digital home. If it is short, or if the same one opens every door, whoever finds it gets in everywhere. This resource explains how to create strong passwords that you do not have to remember, and why a password manager is a practical tool rather than a technical luxury.

A. Why this matters

Your password is often the only thing standing between someone else and your email, your social accounts, your bank and your work. That is a lot of weight for a single word to carry — and most passwords were chosen quickly, years ago, for a service that no longer matters.

The aim of this lesson is narrow and practical: to understand what actually makes a password strong, why using a different one everywhere matters more than any individual password’s cleverness, and how a password manager makes both of those achievable without effort.

One useful shift: you do not need to remember your passwords. You need to remember one — the one that opens your password manager. Everything else can be long, random and instantly forgettable.

B. Key concepts

Seven ideas, each with what it means for your own accounts.

Strong password

A password that is long — at least 15 or 16 characters — and not connected to anything about you: no names, dates, teams or pets.

Why it matters to you: Length is what makes automated guessing impractical. A long password that means nothing to you is far harder to break than a short one full of symbols.

Length before complexity

In the 2025 revision of its digital identity guidelines (SP 800-63B), the US standards body NIST moved the emphasis from forced complexity to length, and recommended a minimum of 15 characters where a password is the only thing protecting an account.

Why it matters to you: It is good news: you no longer have to build unmemorable puzzles. You do still need to mix character types on services that require it, but the length is doing most of the work.

Password reuse

Using the same password across several services. When one of them is breached, that password is tried automatically against all the others.

Why it matters to you: This is the single habit that turns a minor incident somewhere unimportant into a serious one. Breaking the link limits the damage to one account.

Passphrase

A long, unobvious sequence of unrelated words, optionally with numbers and symbols — for example dog-blue-19-lightning.

Why it matters to you: Strong because of its length, and realistic to remember. Ideal for the few passwords you genuinely need to type from memory, such as the one for your password manager.

Password manager

A tool that generates, stores and fills in a unique, strong password for each of your accounts. You remember only the master password.

Why it matters to you: It removes the trade-off between security and convenience, which is the reason most people reuse passwords in the first place.

Multi-factor authentication (MFA)

A second proof of identity in addition to the password — a code from an authenticator app, or a hardware security key.

Why it matters to you: Even if your password is stolen, the account stays closed. This is the highest-value single change you can make.

Passkeys

A newer sign-in method, now supported by most phones, computers and major services. The proof of identity stays on your device and is unlocked with your fingerprint, face or device PIN. There is no password to guess, leak or reuse.

Why it matters to you: Where a service offers passkeys, they are worth taking. In April 2026 the UK’s NCSC recommended them as the default sign-in method for consumers. Passwords are not disappearing tomorrow, but the direction is clear.

C. A practical example: one password, many doors

Marco is 29 and works at a web agency. For convenience, he uses almost the same password everywhere: Marco2018!, with small variations.

An old online shop he had forgotten about is breached, and its list of email addresses and passwords ends up circulating online. No one targets Marco specifically — an automated script simply tries the same combination on the major platforms.

  • It gets into his personal email without difficulty.
  • From there it resets the passwords of the other services linked to that address.
  • It begins sending messages to his contacts, in his name, asking them to click a link.

Within a few automated steps, Marco’s digital identity is being used by someone else. The problem was never that he was an interesting target. It was that one key opened every door.

What would have stopped it

  • A different password for every account (R1) — the breach would have stayed inside the old shop.
  • A password manager generating long, random passwords (R2, R3, MS1, MS2).
  • MFA on his email and social accounts (R4) — the stolen password alone would not have been enough.

D. Try it yourself: a password check-up

Five minutes, honestly answered. Nothing here is graded, and nobody sees your answers.

Step 1 — Take stock

  • How many accounts do you use regularly?
  • For how many of them do you use the same password, or a small variation of it?

Step 2 — Look at your most-used password

  • How many characters long is it?
  • Does it contain your name, a family name, a date of birth, or the name of a partner, child or pet?
  • Would you be comfortable if it appeared in a public list tomorrow?

Step 3 — Name your three critical accounts

  • Usually: primary email, online banking, and your main work account.
  • Write them down. These are the three that deserve the most protection.

Step 4 — Commit to one action today

  • Turn on MFA for one critical account.
  • Change the password of one critical account to a long passphrase.
  • Install a password manager and move your first three accounts into it.

If you only do one of these, make it MFA on your primary email. It protects the account that can reset all the others.

E. Videos, articles and further resources

Independent and institutional sources in English. The first two are the current reference points; the rest are practical.

NIST — Digital Identity Guidelines, SP 800-63B (Revision 4)
The technical standard behind most modern password advice, updated in August 2025. Dense, but this is where “length over complexity” comes from.
https://pages.nist.gov/800-63-4/sp800-63b.html

CISA — Use strong passwords
The US cyber security agency’s plain-language guidance for the public, including its recommendation to use a password manager.
https://www.cisa.gov/secure-our-world/use-strong-passwords

NCSC (UK) — Password managers: how they help you secure passwords
A short, sober answer to the question most people ask first: is it safe to keep all my passwords in one place?
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/password-managers

NCSC (UK) — Passkeys are more secure than traditional ways to log in
Published in April 2026, explaining why passkeys are becoming the recommended default and what that means for everyday users.
https://www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in

EFF — Creating strong passwords
A clear method for building a passphrase you can actually remember, including the dice-based approach.
https://ssd.eff.org/module/creating-strong-passwords

Google — Create a strong password and a more secure account
Direct, practical instructions. Useful if a Google account is the hub of your digital life.
https://support.google.com/accounts/answer/32040?hl=en

EFF — How to make a super-secure password using dice
A short animated overview of the dice method: the simplest way to get genuine randomness without trusting your own imagination.
https://ssd.eff.org/module/animated-overview-how-make-super-secure-password-using-dice

Links checked in August 2026.

F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior

This lesson works mainly on the Skills pillar at level FL1, with a direct effect on Secure Behavior.

Skills

  • Telling a weak password from a strong one, and knowing why the difference is mostly length.
  • Building a passphrase, and setting up and using a password manager.
  • Understanding what MFA does and which accounts should have it first.

For professionals and organizations

  • Understanding the link between password practice and regulatory obligations, data breach notification and responsibility towards customers.

Awareness

  • Recognising that a password is often the only barrier between an attacker and your data, money and reputation.
  • Understanding that reuse, not weakness, is what turns one breach into several.

For future instructors and ambassadors

  • Being able to explain password reuse without making anyone feel foolish for having done it — almost everyone has.

Secure Behavior

  • Using long, unique passwords consistently, not only on the accounts that feel important.
  • Turning on MFA wherever it is available.
  • Not falling back on an old password when creating a new account.

For organizations

  • Providing a password manager rather than asking people to solve the problem on their own.
  • Reviewing policies that still require frequent rotation, which current guidance no longer recommends.

G. Questions to sit with

  1. How many of your passwords are honestly recycled across services?
  2. If your most-used password appeared online today, how many accounts would open immediately?
  3. Which account would be hardest to lose — email, bank or work? What are you already doing to protect it?
  4. Would you trust your digital key the way you trust your house key? If not, what will you change in the next 24 hours?

H. What to do now

The recommendations (R) and security measures (MS) from the Cyber Welfare database most relevant to this lesson.

Passwords and accounts

  • R1 — Do not use the same, or nearly the same, password across your accounts.
  • R2 — Use a reliable password manager with a strong and unique master password.
  • R3 — Bring your passwords to at least 16 characters, with numbers, upper and lower case letters and symbols.
  • R4 — Turn on multi-factor authentication on critical accounts, preferably with an authenticator app or a hardware key.
  • MS1 — Use the manager’s generator rather than inventing passwords yourself.
  • MS2 — Let the manager fill passwords in automatically: fewer errors, and less exposure to fake sign-in pages.
  • MS17 — For the email address linked to your bank: a unique, strong, randomly generated password and mandatory MFA.

Devices, which protect the master password

  • R5 — Set a PIN of at least six digits on your phone.
  • R7 — Lock the screen after the shortest interval you can live with.
  • MS4 — Use an alphanumeric passcode of 8 characters or more on mobile devices.

A note on R3. The 16-character minimum is the part doing most of the work: NIST’s 2025 update emphasises length over forced complexity. Mixing character types is still worth doing, mainly because many services continue to require it — but never at the cost of length.

The minimum useful step

  1. Choose one critical account: your primary email or online banking.
  2. Create a new long password with a password manager (R2, R3, MS1).
  3. Turn on MFA for that same account (R4, MS17).

One account, ten minutes. It is the single change that raises your protection the most for the effort involved.

In short

  • Length matters more than symbols — aim for 16 characters or more.
  • A different password for every account is what limits the damage when something goes wrong somewhere else.
  • A password manager makes both of those effortless; MFA makes a stolen password insufficient.
  • Where passkeys are offered, take them.

Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.

If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.

→ Join the Cyber Welfare Program