Keeping track of dozens of online logins is tiring, and using the same password everywhere feels like the simplest answer. It is easy to remember, quick to type, and it takes one worry off your mind.
The catch is that this convenience comes with a hidden cost: if the password is exposed even once, every account where you used it becomes reachable with the same key. Nobody needs to go after your bank account or your email directly. All it takes is for the weakest service you ever signed up to — perhaps years ago — to give way.
This recommendation — R1 of the Cyber Welfare Framework — exists for exactly that reason: to make sure that one problem stays a single problem, instead of turning into a chain reaction. A unique password for every account does not require technical skills. It requires a decision and a little bit of order.
What this recommendation says
Recommendation R1 states that every online service must be protected by its own unique password, one that cannot be traced back to any of the others.
“Unique” means two things:
- it is not identical to the password of another account;
- it is not built on the same pattern as another one.
The second point is the one people miss most often. Mark2024!, Mark2025! and MarkBank! are technically different passwords, but they follow a rule that a person — or a program — can work out after seeing just one of them. From a security point of view, they count as a single password.
What it is not. It is not a request to invent unpronounceable passwords and memorise them all: there are tools designed precisely for that, and you will find them further down. And it is not a rule that applies only to “important” accounts: minor services are often the very way in.
Where it applies. To every personal, family and work account: email, online banking, social media, cloud storage, online shopping, work apps, government digital services, and devices.
Why it matters
A password works like a key. If the same key opens your home, your office, your car and your mailbox, whoever finds it does not open just one door.
In the digital world this mechanism has a precise name: credential stuffing — automated attacks that take usernames and passwords stolen from one site and try them on many others. When a website suffers a breach, lists of email addresses and passwords end up in circulation. From that moment, automated software tries those same pairs on hundreds of other services. Nobody has to guess anything: they simply try again with what they already have.
The risk is not theoretical, and it does not only concern people who are “careless.” It concerns anyone with more than a handful of accounts — which means almost everyone.
The concrete consequences show up on four fronts:
- data loss — photos, documents, conversations, work files;
- identity theft — someone acts in your name towards banks, colleagues and contacts;
- operational lockout — you lose access to the tools you use every day, sometimes for good;
- stress and costs — hours spent on recovery, paperwork and reports, and the feeling of no longer being in control.
One case deserves special attention: your primary email account. It is the place from which every other password gets recovered. If its key is the same one you use elsewhere, it protects far less than it seems to.
| Benefit of unique passwords | Why it counts |
|---|---|
| Limits the damage | One compromised account stays one compromised account, not a domino effect |
| Protects your primary email | It is the gateway to recovering every other service |
| Reduces the risk of identity theft | Fewer reachable accounts, less personal data exposed |
| Protects money and payments | Shopping, banking and digital wallets are the most lucrative targets |
| Shows you where to act | You know which account is at risk and you act only there |
A concrete example
Years ago you signed up to a website to download a document or make a one-off purchase. You used the password you still use today.
That website gets breached. Nobody tells you, or the notice ends up among the promotional emails. The list of users — email addresses and passwords — starts to circulate.
From then on, that pair is tried automatically on common services: email, social media, cloud storage, online stores, payment platforms. Nobody needs to be thinking about you personally: all it takes is for the password to still work somewhere.
If it works on your email, the problem spreads on its own: email is the channel used to reset the passwords for everything else.
The only point where this chain breaks is the very first one: if that password existed only on that website, the breach stays there.
When to apply it
The rule always applies, but there are moments when it makes a measurable difference.
- When you sign up to a new service. This is when it takes the least effort: creating a new password costs thirty seconds, while changing one later costs a lot more.
- When working remotely and on personal devices. Work credentials should be kept separate from personal ones: a problem on one side must not cross over to the other.
- On cloud services. A single cloud account can hold years of documents, photos and backups.
- On small online stores. They often have fewer resources for security, yet they keep your address, phone number and sometimes payment details.
- When travelling and on shared devices. The family tablet, a hotel computer, shared workstations: settings where a reused password gets around more easily.
- After news of a breach. If a service you use reports an incident, that password should be treated as exposed everywhere you used it.
How to apply it
You do not need to redo everything in one afternoon. What you need is a sequence.
- Take stock of your critical accounts. Primary email, online banking, payment services, cloud storage, work accounts, social media, government or digital identity logins, and online stores with saved cards. There are usually between five and ten of them.
- Find the duplicate passwords. Start with the one you have used the longest: it is almost always the one you have reused the most.
- Replace them in order of importance. Your primary email first, then banking and payments, then cloud and work, then everything else. Use a genuinely new password each time, not a variation of the previous one.
- Use long passphrases. A passphrase is a password made of several words: a sequence of four or five unrelated words is stronger than a short word full of symbols, and much easier to remember. Avoid famous quotes and personal references.
- Turn on multi-factor authentication. MFA (Multi-Factor Authentication) adds a second check on top of the password: a code generated by an app, a notification on your phone, a physical key. Even if the password were discovered, on its own it would not be enough.
- Adopt a password manager. It is the tool that makes everything else sustainable: it generates different passwords, stores them, and fills them in for you. We cover this in recommendation R2 on storing passwords safely.
Common mistakes to avoid
- Predictable variations.
Summer2024!andWinter2024!are not two passwords: they are the same password with a different label. - The token symbol. Adding
!or123to a common word does not make it strong; those combinations are among the first to be tried. - Personal information. Names of family members and pets, dates, cities, sports teams: these can often be found on public social media profiles.
- Splitting accounts into “serious” and “minor” ones. An old, forgotten forum is still a door, and usually the least watched one.
- Passwords written down in plain text. A file called “passwords,” an unprotected note, a message sent to yourself: they are convenient archives for people who should not be reading them, too.
- Relying on the browser without protection. Saving everything in your browser is fine only if access to the device and to the browser profile is protected as well.
How this connects to the Cyber Welfare Framework
R1 is the recommendation that opens the path: it is the first behaviour that turns security from an idea into an everyday practice.
| Pillar | How this contributes |
|---|---|
| Skills | Knowing how to build a strong password and recognise a predictable pattern |
| Awareness | Understanding that the risk lies not in a single account but in the links between accounts |
| Secure Behaviour | Creating a brand-new credential every time you open a service, with no exceptions |
Digital maturity levels.
- FL1 — Basic. You use the same password, or a few variations, on almost every service. It is the most common starting point, not a fault.
- FL2 — Beginner. You have separated your critical accounts: email, banking and payments each have their own password.
- FL3 — Autonomous. Every account has its own password, generated and stored in a password manager, with MFA on the main services.
- FL4 — Skilled. You regularly check for weak, duplicated or exposed passwords, and replace them before they become a problem.
- FL5 — Expert-Guide. You help other people — in your family, your team, your organisation — take the same path.
R1 is the key step from FL1 to FL2, and it remains an active requirement at every level after that.
How to check you are applying it properly
Three questions, to be answered honestly.
- If someone found out the password to my social media account, could they also get into my primary email?
- Have I stopped building my passwords from the same base word?
- Can I list at least five important accounts whose passwords are completely different from one another?
Quick checklist
- ☐ My primary email has a password used only there
- ☐ My bank and payment services have their own passwords
- ☐ None of my passwords contains names, dates or places linked to me
- ☐ No two of my passwords differ only by a number or a symbol
- ☐ MFA is enabled at least on email, banking and cloud storage
- ☐ I know where my passwords are stored, and that place is protected
If a box stays empty, you already have your next step. If you would like a more structured measure of where you stand, you can take the digital resilience self-assessment.
In short
Using the same password for several accounts is risky because a single breach can reach many services. Even similar passwords do not really protect you, because the pattern can be worked out.
The solution is not complicated, but it does need organising: a unique password for every account, priority to critical accounts, no personal details and no repeated patterns, multi-factor authentication turned on, and a password manager to make it all sustainable.
Digital security does not have to become a second job. It can start with one concrete choice: to stop using the same key to open every door of your online life.
Something to think about. If one of your passwords fell into the wrong hands today, how many accounts could it open?
Explore this recommendation
This recommendation is the pivot of a content unit. Each post looks at a different aspect.
- Risks of password reuse — what gets hit, in terms of the confidentiality, accuracy and availability of your data
- Consequences of a stolen password — the concrete effects on the operational, financial, legal, reputational and personal levels
- What to do after reusing passwords — the mitigations, in order of priority
- How to tell if your account was hacked — the indicators to check and what they mean
- Password management tools — the tools available, their advantages and limits
- Credential stuffing — the attacks that exploit reused passwords
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



