11 minutes reading time
SAFER ONLINE
SEP 18 2026

How to Create a Secure Password? Best Practices for Password Security

Last updated on 18th of September by: Alicja Kłos, prepaid payment cards expert | Southern, Central & Eastern European Markets

Checked by: Sandisiwe Harvey, Payment Content Specialist, English

A strong password is one of the simplest ways to protect your online privacy, personal data and digital accounts. But a secure password is no longer about adding a capital letter, number and exclamation mark to something you can remember.

If you are like most people, you probably have dozens of online accounts. Let’s be honest, who has time to remember a different password for every single one of them? To make things simpler, many of us fall into the habit of using the same, easy-to-remember password for all of our accounts. While this does make life easier in the short term, it’s also a disaster waiting to happen.

This matters because stolen passwords are still one of the most common ways hackers get into online accounts. According to Verizon's 2025 Data Breach Investigations Report, stolen login details were involved in 22% of the data breaches analyzed. Verizon also found that only 49% of passwords stolen by malware were unique, meaning many people reuse the same passwords across different accounts.

In other words, password reuse can turn one compromised account into several.

Learn how to create and manage strong passwords – and what else you can do to keep your accounts, money and personal information safer online.

What Makes a Strong Password? Password Security Best Practices

A strong password should be:

  • unique,

  • long,

  • difficult to predict.

Ideally, you should use a randomly generated password created by a trusted password manager. If you need to remember the password yourself, a long passphrase made from unrelated words can be easier to remember.

The guidance from the US National Institute of Standards and Technology (NIST) emphasises password length over complicated composition rules. For passwords used as the only authentication factor, NIST recommends requiring at least 15 characters.

How To Create a Secure Password: Tips for Password Creation

Tattooed hands typing on a laptop keyboard, focused and working.

1. Make your password long

When it comes to password security, length matters.

Aim for at least 15 characters, particularly for important accounts such as your primary email, banking, payment or password manager account.

Long passwords are generally more resistant to guessing and brute-force attacks. A long passphrase made from several random, unrelated words can also be easier to remember than a short string of random characters.

For example, instead of building a short password around predictable substitutions such as P@ssword1!, use a much longer combination that cannot easily be associated with you.

Do not copy password examples you find online – including examples in security articles – for your real accounts.

2. Use a unique password for every account

Never reuse the same password across multiple accounts.

If a company suffers a data breach and your login credentials are exposed, criminals may try those credentials on other websites. This technique is known as credential stuffing.

Password reuse therefore creates a domino effect: a password stolen from one relatively unimportant account could potentially give an attacker access to your email, shopping accounts, social media or other services.

Verizon found that credential stuffing represented a median of 19% of authentication attempts per day in the SSO environments it analyzed, demonstrating how extensively attackers automate attempts to reuse stolen credentials.

A strong password is especially important when it comes to your most sensitive accounts, including:

  • Primary email
  • Online banking and payment accounts
  • Social media
  • Cloud storage
  • Shopping accounts containing payment or personal information
  • Your password manager

Your email account deserves particular protection because access to your inbox can potentially allow an attacker to request password resets for your other accounts.

Mobile phone with Facebook login screen, highlighting digital connectivity and social media use.

3. Avoid personal information

A password should reveal nothing about you.

Avoid information such as:

  • Your name or username

  • Your partner's or children's names

  • Pet names

  • Birthdays

  • Addresses

  • Phone numbers

  • Favourite sports teams

  • Other information visible on social media

This isn't only about password strength – it's an online privacy issue.

The more personal information you share publicly, the more material an attacker may have to guess passwords, security questions or other account credentials. Google similarly recommends avoiding information that people who know you – or someone searching publicly available information – could easily discover.

4. Avoid common and compromised passwords

Don't use predictable passwords such as password123, keyboard patterns or common phrases. Hackers and software can easily guess words that are in the dictionary, so it’s best to avoid them.

NIST recommends checking new passwords against lists of common, easy-to-guess, and previously stolen passwords.

5. Check your passwords

You can also check whether a password has previously appeared in known data breaches using Have I Been Pwned service. Its password-checking system uses k-anonymity, meaning the full password isn't sent to the service when performing the check.

Simply enter your email address you want to check and proceed to the verification. If a password you currently use has appeared in a known breach, replace it with a new, unique password.

And if you want to see how your current passwords stand up, you can check out a password strength test like howsecureismypassword.net.

Do Passwords Need Numbers, Symbols and Capital Letters?

Not necessarily.

You've probably heard that a secure password needs:

  • An uppercase letter

  • A lowercase letter

  • A number

  • A special character

But nowadays this is not the case.

NIST now advises against mandatory password composition rules because people tend to respond to them predictably – for example, turning password into something like Password1!. Instead, length and avoiding predictable passwords are more important.

Randomly generated passwords may naturally contain a mixture of letters, numbers and symbols, and that's perfectly fine. The important point is that adding a symbol to a weak password does not automatically make it strong.

Should You Change Your Password Regularly?

No. You don't need to routinely change a strong, unique password simply because a certain amount of time has passed.

NIST recommends against requiring periodic password changes unless there is evidence that a password has been leaked or stolen. Forced changes can actually encourage predictable behaviour, such as changing Example1! to Example2!.

When should you change your password?

  • The service tells you it suffered a breach that may affect your credentials.

  • You discover the password in a known breach.

  • You accidentally shared or exposed your password.

  • You entered your password on a suspicious or phishing website.

  • You reused your password on another compromised account.

  • You noticed suspicious account activity.

If a reused password is compromised, replace it everywhere you used it – and give each account a different password.

How Can You Keep Your Password Safe with a Password Manager

Creating a unique password for every account raises an obvious problem: how are you supposed to remember them all?

The good news is, you don't have to if you’re using a trusted password manager.

How does a password manager work?

A password manager securely stores your login credentials in an encrypted vault, allowing you to use long, randomly generated and unique passwords without memorising every one.

Many password managers can also:

  • Generate strong passwords

  • Autofill login details

  • Sync passwords between devices

  • Identify reused passwords

  • Alert you to potentially compromised credentials

  • Store recovery codes and other sensitive information

Password managers are a good solution for generating and storing long, random and unique passwords. They can improve both password security and convenience.

That doesn't mean password managers are risk-free. Your vault contains extremely valuable information, so protect your password manager carefully.

Create a long and unique master password or passphrase, enable multi-factor authentication if available and understand how the provider's account-recovery process works.

Most importantly, never reuse your password manager's master password anywhere else.

What are the most recommended password managers?

There are many password managers on the market, but some of the most commonly recommended options include:

Each offers tools for securely storing, managing, and generating passwords.

What if you don't want to use a password manager?

For passwords you genuinely need to remember, consider using a long passphrase made from randomly selected, unrelated words.

Avoid famous quotations, song lyrics, movie lines or common expressions. Something memorable to millions of other people isn't necessarily difficult for password-cracking tools to predict.

For a small number of important passwords, writing them down can also be safer than reusing a weak password – provided the written copy is stored securely and away from your devices. Never keep passwords on a sticky note next to your computer or in an unprotected digital document.

How Can You Keep Your Password Safe from Phishing

A strong password protects against guessing, but it cannot protect you if you willingly give it to a scammer.

To keep your login details private:

  • Never send passwords through email, chat or text messages.

  • Be suspicious of unexpected messages asking you to log in.

  • Check the website and domain before entering your credentials.

  • Don't enter passwords after following suspicious links.

  • Never give a password to someone who contacts you unexpectedly claiming to represent a company or support service.

  • Avoid saving passwords on shared or public computers.

If you think you've entered a password on a phishing website, change it immediately. If you used the same password elsewhere, change those accounts too.

Learn more about recognising and preventing phishing.

Use Multi-Factor Authentication for Extra Protection

Even the strongest password can be stolen.

That's why important accounts should also use multi-factor authentication (MFA), sometimes called two-factor authentication or 2FA.

MFA requires another form of verification in addition to your password. Depending on the service, this might include:

  • An authenticator app

  • A security key

  • A passkey or biometric verification

  • A one-time code

  • A push notification

Not every MFA method offers the same level of protection. CISA recommends moving towards phishing-resistant authentication such as FIDO/WebAuthn where available.

If your account offers stronger authentication methods, choose them over SMS codes when practical. But if SMS-based 2FA is the only additional protection available, it is still better than relying on a password alone.

Close-up of a finger entering a passcode on a smartphone security screen

What About Passkeys?

Passwords are no longer the only way to secure an online account.

An increasing number of services support passkeys, which allow you to authenticate using a cryptographic credential stored on your device or password manager. Instead of sending a reusable password to a website, passkeys use public-key cryptography to authenticate you.

One important security advantage is that properly implemented passkeys based on FIDO/WebAuthn are phishing-resistant: the credential is bound to the legitimate website, making it much harder for a fake login page to steal something an attacker can reuse. CISA identifies FIDO/WebAuthn as the widely available phishing-resistant authentication approach.

If a trusted service offers passkeys, they're worth considering – particularly for important accounts.

Passwords aren't disappearing overnight, though. Knowing how to create and manage secure passwords remains an essential part of protecting your digital identity.

Password Security Best Practices: Checklist

If you’re wondering how to create a secure password and keep your data safe, use these tips:

  • Use long passwords – aim for at least 15 characters.

  • Use a unique password for every account.

  • Never include easily discoverable personal information.

  • Avoid common, predictable and previously compromised passwords.

  • Use a trusted password manager to generate and store passwords.

  • Protect your password manager with a strong, unique master password and MFA.

  • Don't change passwords just because a few months have passed – change them when they're compromised or exposed.

  • Enable multi-factor authentication wherever possible.

  • Use phishing-resistant authentication or passkeys when available.

  • Never give your password to someone who contacts you unexpectedly.

Want to learn more about how to be safer online? Check out our articles about the most common online scams & how to avoid them, how to ensure safe online payments and read the tips from a cybersecurity expert.

Keep Your Password Safe and Secure

Strong passwords are only one part of protecting yourself online. Combine good password habits with careful management of your personal information, phishing awareness and stronger authentication methods to reduce the risk of account takeover, identity theft and online fraud.

Alicja Klos
Written by Alicja Klos