CYBER WELFARE

Protect your Digital Privacy

Password management tools: what exists and what each one is for

Asking someone to remember forty different passwords isn’t a security request: it’s an impossible one. And that is the reason password reuse is so widespread — not laziness, but the fact that the manual method simply can’t keep up with the number of accounts we have today.

The answer doesn’t lie in trying harder to remember. It lies in tools: technologies that generate, store, and check passwords, and that more and more often replace the password altogether.

This post lays out the main password management tools one by one, with their real advantages and limits, without pointing to any specific product. It is the technology side of the recommendation to use a unique password for every account.

How to read this list

The technologies are organised into four functions, the same ones used in the post on what to do after reusing passwords:

  • prevention — stopping the problem from arising in the first place;
  • detection — noticing that something is wrong;
  • response — regaining control;
  • governance — keeping things in order over time, especially when more than one person is involved.

For each one you’ll find the risk it reduces, its advantages, its honest limits, and how complex it is to use.

1. Prevention technologies

Password manager

A tool that generates random passwords, stores them in encrypted form (scrambled so that only you can read them), and fills them in when you need them.

  • Risk reduced: duplicate, weak, or predictable passwords.
  • Advantages: it makes a different password for every account possible without your having to remember any of them; it flags duplicates and weak credentials; it lowers the risk of typing your password into a fake site, because it only fills in on the correct address.
  • Limits: it concentrates a lot of value in a single place, so the manager’s master password and its multi-factor authentication (MFA, explained just below) become critical; moving your accounts over takes an initial period; using it on other people’s devices is less convenient.
  • Example: you sign up for a new service, and the manager suggests a random password and saves it. You’ll never see it and never have to remember it.
  • Complexity: basic.

Multi-factor authentication (MFA)

A second check on top of the password: a temporary code, a notification, or a physical key.

  • Risk reduced: sign-ins with a stolen or reused password.
  • Advantages: it’s the measure that works even when the password has already been compromised; it’s available on almost all major services; in most cases it takes just a few minutes to turn on.
  • Limits: you need to keep your recovery codes safe; the text-message (SMS) method is the most fragile of the three; changing phones without first moving over your authenticator app (the app that generates the temporary codes) can lock you out.
  • Example: someone tries your stolen password on your email account; the attempt stops because the second factor is missing, and you receive a notification.
  • Complexity: basic.

Passkeys

A sign-in method that replaces the password with a credential tied to your device and unlocked with your fingerprint, face, or PIN.

  • Risk reduced: stolen and reused passwords, and credential phishing (fake sites or messages designed to trick you into handing over your login details).
  • Advantages: there’s no password to reuse or to have stolen; signing in is faster; it resists fake sites by design, because the credential is tied to the legitimate site.
  • Limits: it isn’t yet supported by every service; it calls for some care in managing your devices and backups; passkeys and traditional passwords will go on coexisting for a while yet.
  • Example: you sign in to your account with your fingerprint, without typing anything.
  • Complexity: basic, where available.

Hardware security keys

A small physical device that confirms your sign-in.

  • Risk reduced: credential theft and phishing, including targeted phishing.
  • Advantages: among the strongest protections available to an individual user; it can’t be copied remotely.
  • Limits: it costs money; it needs to be kept safe, and it’s wise to have a spare; not every service supports it.
  • Example: to get into your work account, you plug in the key or hold it near your phone.
  • Complexity: intermediate.

2. Detection technologies

Suspicious sign-in alerts

Automatic notifications sent when a sign-in happens from an unusual location, network, or device.

  • Risk reduced: unauthorised access that goes unnoticed.
  • Advantages: they reach you without your having to check anything; they let you react quickly.
  • Limits: they produce false alarms (travel, mobile networks, VPNs — services that route your connection through another server); if they arrive too often, people stop reading them.
  • Complexity: basic.

Sign-in and device monitoring

The “recent activity,” “connected devices,” and “active sessions” sections found in your accounts. A session is simply a sign-in that stays open on a device.

  • Risk reduced: ongoing access you haven’t noticed.
  • Advantages: they give you a direct, verifiable picture; they let you close suspicious sessions with a single click.
  • Limits: you have to check them actively; the geographic location they show is often approximate.
  • Complexity: basic.

Compromised password notifications

Alerts built into password managers, browsers, and operating systems that tell you when one of your credentials shows up in a known breach — an incident in which a service’s data is stolen.

  • Risk reduced: continuing to use a password that has already been exposed.
  • Advantages: they let you know about breaches at third-party services that you would otherwise know nothing about.
  • Limits: they only cover breaches that have become public; the absence of an alert does not mean the password is intact.
  • Complexity: basic.

Exposed credential checks

Services that let you check whether an email address appears in known breaches.

  • Risk reduced: not knowing that your credentials are already circulating.
  • Advantages: they give you a concrete starting point for deciding which passwords to change first.
  • Limits: the same caveat applies: they cover public breaches, not all of them. Only use well-known services, and never enter your password — only your email address.
  • Complexity: basic.

3. Response technologies

Account recovery procedures

The official mechanisms for getting back into an account you’ve lost access to.

  • Risk reduced: losing the account for good.
  • Advantages: they exist on all the major services; if your recovery details are up to date, they work well.
  • Limits: they can take a long time; if the recovery contacts have been changed, the procedure becomes much more complicated.
  • Complexity: variable.

Revoking active sessions

The “sign out of all devices” feature.

  • Risk reduced: access that persists even after the password has been changed.
  • Advantages: immediate and effective; it closes everything in a single step.
  • Limits: it has to be done after changing the password, otherwise the session can reopen; it also signs you out of your own devices.
  • Complexity: basic.

Managing connected apps

The panel that lists the applications authorised to access your account.

  • Risk reduced: third-party access that remains in place over time.
  • Advantages: it lets you revoke authorisations you’ve forgotten about; it’s useful even when nothing has gone wrong.
  • Limits: app names aren’t always recognisable; it takes a little attention to avoid revoking something you still use.
  • Complexity: basic.

Secure credential reset

Changing your password in the right order and through official channels.

  • Risk reduced: resets that don’t work or that are carried out on fake sites.
  • Advantages: if you start from your main email account, it genuinely closes the door.
  • Limits: this is the stage where phishing attempts tend to cluster: never follow links you receive in a message.
  • Complexity: basic.

4. Governance technologies

These become relevant when the accounts aren’t only yours: a family, a team, an association, a small organisation.

Identity and access management (IAM)

Systems that centralise who can access what.

  • Risk reduced: untracked accounts, excessive permissions, access that stays active after someone leaves.
  • Advantages: a single overview, immediate revocation, uniform rules.
  • Limits: it requires setup and maintenance; it’s more than personal use calls for.
  • Complexity: advanced.

Single sign-on (SSO)

A single sign-in that opens several applications.

  • Risk reduced: a proliferation of different, poorly managed passwords.
  • Advantages: fewer credentials in circulation, and MFA applied in one place.
  • Limits: it concentrates the risk on the main identity, which needs protection in proportion.
  • Complexity: intermediate.

Shared password policies

Written rules on length, uniqueness, MFA, and credential management.

  • Risk reduced: inconsistent behaviour from one person to the next.
  • Advantages: they turn security into a shared practice rather than an individual choice.
  • Limits: a policy that isn’t followed is worse than no policy at all; rules that are too rigid push people to work around them.
  • Complexity: intermediate.

Training and awareness

Learning paths that explain the why, not just the how.

  • Risk reduced: rules applied mechanically and inconsistently.
  • Advantages: it’s what makes behaviour last over time; it’s the pillar on which the Cyber Welfare Framework rests.
  • Limits: it requires continuity; a one-off session has a short-lived effect.
  • Complexity: basic.

Comparison table

FunctionTechnologyRisk reducedMain advantageMain limitComplexity
PreventionPassword managerDuplicate or weak passwordsA different password for every account, with nothing to memoriseNeeds to be protected carefullyBasic
PreventionMFASign-ins with a stolen passwordWorks even when the password is compromisedManaging recovery codesBasic
PreventionPasskeysStolen passwords and phishingRemoves the passwordSupport not yet universalBasic
PreventionHardware keyCredential theft and targeted phishingVery strong protectionCost and physical handlingIntermediate
DetectionSign-in alertsUnauthorised accessNotifies you without your having to lookFalse alarmsBasic
DetectionSign-in monitoringUnknown sessionsDirect, verifiable pictureMust be checked activelyBasic
DetectionCompromised password alertsUse of exposed passwordsTells you about breaches elsewherePublic breaches onlyBasic
ResponseSession revocationPersistent accessCloses everything in one stepMust follow the password changeBasic
ResponseConnected app managementThird-party accessRevokes forgotten authorisationsNames not always clearBasic
ResponseAccount recoveryLosing the account for goodAvailable on all major servicesSlow if the details have been alteredVariable
GovernanceIAMUntracked permissionsCentralised controlRequires managementAdvanced
GovernanceSSOToo many scattered credentialsFewer passwords, a single MFAConcentrates the riskIntermediate
GovernancePassword policiesInconsistent behaviourShared practiceIneffective if not appliedIntermediate
GovernanceTrainingMechanical applicationMakes behaviour lastNeeds continuityBasic

How to choose

If you’re an individual. A password manager plus MFA on your email, bank, and cloud accounts. That’s two tools, they can be set up in an afternoon, and they cover the largest share of the risk. Add passkeys wherever the service offers them.

If you’re a professional. Add a clear separation between personal and work credentials, a regular review of your connected apps, and a hardware key on the accounts that, if compromised, would bring your work to a halt.

If you manage a group or a small organisation. Start with a simple policy that is actually applied, a shared password manager with separate folders, mandatory MFA on critical access, and recurring training. IAM and SSO start to make sense as the number of people and applications grows.

A rule of thumb. No technology removes risk on its own. Among password management tools, the combination that gives the best result for the effort involved is password manager + multi-factor authentication: you can build up from there, but below that threshold password reuse tends to creep back in.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsChoosing a tool based on the risk it reduces, not on its popularity
AwarenessRecognising that every technology has stated limits, and none of them solves everything
Secure BehaviourUsing the tools consistently, not only after an incident

Reference level: FL4 — Skilled. This is the level at which you don’t just follow the guidance you’ve been given, but weigh the options available and choose with understanding.

Conclusion

Unique passwords are not an exercise in discipline: they are the result of having the right tools. Someone who uses a password manager doesn’t work harder than someone who reuses the same word — they work less, and with far lower risk.

What to do next. Choose a password manager and, to begin with, move just three accounts into it: email, bank, and cloud. The rest will follow as you use it.

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.