CYBER WELFARE

Protect your Digital Privacy

How to protect your password vault: the measures in priority order

A well-protected password vault is one of the most effective tools a person can adopt. A badly protected one concentrates in a single place everything it was supposed to defend.

The difference between the two comes down to a handful of settings, almost all of them one-off.

This post organises them into four moments — prevent, detect, respond, recover — in the order in which they actually reduce risk. It is the operational side of the recommendation storing passwords safely.

Before you start: the hierarchy to keep in mind

Not every measure is worth the same. If you are short of time, this is the order:

  1. a strong, unique master password — without it, everything else matters less;
  2. multi-factor authentication on the vault — it holds even if the first one gives way;
  3. recovery codes kept outside — it prevents the likeliest risk of all;
  4. automatic vault locking — it covers the everyday physical risks;
  5. everything else.

The first three take twenty minutes and cover the largest part of the problem.

1. Prevention: reducing risk before anything happens

Build a genuinely strong master password

What to do. Use a passphrase of four or five words with no logical connection between them. It must be:

  • unique — it must not exist anywhere else, ever;
  • long — length counts for more than symbol complexity;
  • free of personal references — no names, dates, places, pets;
  • memorable — because you will have to type it, not just unlock with a fingerprint.

What to avoid. Reusing a password you have used elsewhere, even a modified one. If it appears in a breach that happened years ago on another service, it opens the vault.

Turn on multi-factor authentication for the vault

What to do. Enable it right after creating the account. Prefer an authenticator app or a hardware key; a code by text message is the weakest method, but it is still better than nothing.

Why it counts. It is the measure that protects once prevention has already failed. If the master password were discovered, on its own it would not be enough.

Set a short auto-lock

What to do. Configure the vault to lock after a few minutes of inactivity, and when the browser closes or the screen locks. The default is often far too permissive.

Why it counts. The most concrete everyday risk is not remote: it is a device left open and unattended.

Protect the device, not just the vault

What to do. Operating system up to date, screen lock enabled, no software installed from unofficial sources. An encrypted vault opened on a compromised device is as readable as anything else on it.

Put in order what you import

What to do. After importing passwords from the browser, do two things: empty the browser’s own store, and run the vault’s analysis feature to find weak, duplicated or exposed passwords. Then replace them, starting from the critical accounts.

Why it counts. Importing is not securing: the old passwords stay exactly as they were, just in a different place.

Separate your contexts

What to do. Keep personal and work credentials in distinct folders, or in two separate vaults if your organisation requires it. For shared credentials use the vault’s sharing folders, never messages.

2. Detection: noticing early

Check who has opened the vault

What to do. Many vaults show which devices opened the store and when. Look at it every two or three months. Remove devices you no longer use.

Keep provider notifications on

What to do. Alerts for a new sign-in, for changes to security settings, for an export of the vault. That last one in particular: an export you did not request is a strong signal.

Use the exposed-credential analysis

What to do. If the vault flags one of your passwords as having appeared in a known breach, change it on that service — and check you have not used it anywhere else.

Check that entries are consistent

What to do. Every so often, verify that the addresses associated with your entries are the right ones, and that autofill is not offering credentials on sites that have nothing to do with them.

The full list of indicators is in the post signs your password vault is compromised.

3. Response: what to do if you suspect a problem

The order matters.

Change the master password

What to do. This is the first step. Do it from a device you trust — not from the one you suspect is compromised.

Revoke sessions and devices

What to do. Sign out of every active session and remove authorised devices you do not recognise. Do this after changing the master password.

Check the second factor

What to look at. That MFA is still enabled and tied to your device, and that no authentication methods you do not recognise have been added.

Change the passwords on critical accounts

What to do. If the vault might have been read, every credential it contained has to be treated as exposed. Start with email, then bank, cloud, work. You do not need to redo everything in one day: you need to redo first what counts.

Look at the entries that changed

What to do. If the vault keeps a history, check recent changes. An altered web address or an edited entry is a sign of tampering, not of error.

4. Recovery: getting back to a stable state

If you have lost access to the vault

What to do. In order: try a second device where the vault is still unlocked or signed in; use the recovery codes; check whether the vault offers an emergency contact you already designated.

A word of warning. If the master password is lost and you have no codes, most vaults cannot recover it — that is the direct consequence of the provider not being able to read your vault either. In that case you move to recovering accounts one at a time, starting from email.

Rebuild in order

What to do. Recover email first, then the critical accounts. As you get back in, save each new credential to the vault straight away, with a generated password.

Close the loop

What to do. A master password you can type from memory, MFA enabled, recovery codes outside the phone, the vault reachable from two devices. Those are the four conditions that stop it happening again.

A plan in two sessions

Session 1 — The foundations (20 minutes)

  1. Check the master password is unique and that you can type it in full.
  2. Turn on multi-factor authentication for the vault.
  3. Generate and store the recovery codes, outside the vault and outside the phone.
  4. Set auto-lock to a few minutes.

Session 2 — The clean-up (20 minutes, repeatable)

  1. Run the password analysis: find weak, duplicated and exposed entries.
  2. Replace the critical accounts’ passwords with generated ones.
  3. Empty the browser’s password store.
  4. Remove authorised devices you no longer use.

Frequent mistakes

  • A strong master password, but no second factor. Half the job.
  • Recovery codes saved inside the vault. They are unreachable at precisely the moment they are needed.
  • Biometric unlock only. Convenient, but after a few months the master password is no longer remembered.
  • Passwords imported and never replaced. The vault is tidy; the security is not.
  • Passwords left in the browser too. Two copies, two surfaces to protect.
  • No periodic review. The analysis features exist and cost nothing: they are there to be used.
  • Sharing credentials by message. It recreates the very problem the vault solves.

Migrating, when you are coming from somewhere else

Three common starting points, each with its own path.

If you are coming from the browser. Export the saved passwords, import them into the vault, then empty the browser’s store and turn off automatic saving. As long as two copies exist, there are two to protect — and the browser’s is usually the less protected one.

If you are coming from a list on paper or in a file. Enter them one at a time: it is the chance to notice how many are duplicates. If the file was in the clear, delete it securely and treat the passwords it held as exposed, replacing them from the critical accounts down.

If you are switching vaults. Export from the old one, import into the new one, check everything arrived — then delete the previous account. An export almost always produces a plain file: use it and delete it straight away, without leaving it in the downloads folder.

The same rule applies in all three cases: importing is not securing. The passwords that arrive through an import are the old ones; they need replacing as you go, starting with email, bank and cloud.

If the vault is used by more than one person

When the store serves a family, a team or an association, four more rules apply.

  1. Separate folders per context, with permissions given to those who actually need them — not everyone has to see everything.
  2. No sharing outside the vault: if a credential ends up in a chat, it leaves the perimeter and can no longer be revoked.
  3. Revoke on exit: when someone leaves the group, remove their access and regenerate the shared credentials they knew.
  4. One person responsible for the shared vault, who knows where the recovery codes are and how access is managed.

These are organisational rather than technical measures, which is precisely why they get postponed. The most neglected is the third: access gets revoked, but the shared password stays as it was.

Operational checklist

Stage 1 — Foundations

  • ☐ Master password unique, long, with no personal details
  • ☐ Multi-factor authentication enabled on the vault
  • ☐ Recovery codes stored outside the vault and outside the phone

Stage 2 — Hygiene

  • ☐ Auto-lock set to a few minutes
  • ☐ Browser password store emptied
  • ☐ Password analysis run and critical passwords replaced

Stage 3 — Control

  • ☐ Authorised devices reviewed
  • ☐ Provider notifications enabled
  • ☐ Personal and work credentials separated

Stage 4 — Continuity

  • ☐ Vault reachable from at least two devices
  • ☐ I know how to export a copy of the vault
  • ☐ I have considered an emergency access contact

A short scenario

Sarah gets an alert: someone tried to sign in to her password vault from an unknown device. The attempt stopped at the second factor.

She does not rush. She changes the master password from a computer she trusts, revokes every session, checks that no authentication methods have been added. Then she looks at where she had used a password similar to her master one in the past: she finds it on an old service, and changes it there.

That is where the attempt had started.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsConfiguring the tool correctly and reacting in the right order
AwarenessUnderstanding why a second factor on the vault is worth more than anywhere else
Secure BehaviourReviewing the vault periodically, rather than installing it and forgetting it

Reference level: FL3 — Autonomous, with elements of FL4 — Skilled in the analysis and periodic maintenance part.

Conclusion

Protecting a password vault does not require technical skill: it requires four settings done once, and a check every few months.

What to do right now. Open your vault’s security settings. If multi-factor authentication is off, turn it on; if you do not have recovery codes, generate them and put them somewhere safe. Those two steps are worth more than all the others combined.

To see where you stand, the digital resilience self-assessment gives you a reference point.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.