Skip to content

Despite all the advances in cyber security, weak passwords are still one of the easiest ways for criminals to gain access to personal and business accounts. World Password Day is a useful reminder to review how we protect our accounts and reduce the chances of becoming the next victim of fraud or cyber crime.

From email accounts and banking apps to workplace systems and social media, passwords remain the front door to much of our digital lives. Unfortunately, many people are still using passwords that are easy to guess, reused across multiple accounts, or stored insecurely.

Some of the most common issues include:

  • Reusing the same password across multiple accounts.
  • Using simple or predictable passwords.
  • Sharing passwords between colleagues or family members.
  • Storing passwords in spreadsheets, notebooks or emails.
  • Failing to enable multi-factor authentication (MFA).

Once a criminal gains access to one account, they often try the same login details elsewhere. This is known as ‘credential stuffing’ and can quickly lead to wider security compromise across personal and business systems.

What makes a strong password?

A strong password should be:

  • Long
  • Unique
  • Difficult to guess
  • Different for every account

Rather than trying to remember dozens of complicated passwords, consider using a passphrase instead.

For example:

  • RedBusNiceCoffee
  • SpottyDogsLoveWalking

Passphrases can often be easier to remember, but harder for attackers to crack.

Avoid using:

  • Names
  • Birthdays
  • Pet names
  • Common words or phrases
  • Simple patters such as Password1234

Use a password manager

One of the best ways to improve password hygiene is by using a password manager. Password managers can:

  • Generate strong passwords
  • Store them securely
  • Auto-fill login details safely
  • Reduce the temptation to reuse passwords

This means you only need to remember one master password to access a password manager, rather than lots of separate login detail.

Don’t forget to use MFA

Even strong passwords can be stolen through phishing attacks or data breaches. That’s why enabling Multi-Factor Authentication (MFA) is important.

MFA adds an additional layer of security by requiring something else to verify your identity, such as:

  • An authentication app
  • A fingerprint
  • A face scan
  • A one-time code

If a password is compromised, MFA can still stop criminals from accessing the account.

A future beyond passwords

Many organisations are now beginning to adopt passkeys as a safer and simpler alternative to passwords. Passkeys use your device security, such as Face ID, fingerprint recognition or a PIN, to log you in securely without the need to remember a password.

Benefits of a passkey include:

  • No passwords to remember
  • Stronger protection against phishing
  • Faster login experience
  • Reduced risk of password reuse

Major providers such as Apple, Google and Microsoft are increasingly supporting passkeys across devices and the National Cyber Security Centre officially announced in April 2026 at CYBERUK that it recommends using passkeys wherever a service supports them, and MFA where passkeys are not available.

While passwords are unlikely to disappear overnight, passkeys are expected to play a much bigger role in the future of online security.

Quick password hygiene checklist

Here are 5 quick actions you can take today to celebrate World Password Day:

  1. Use a unique password for every account.
  2. Switch on MFA wherever possible.
  3. Use a password manager.
  4. Replace weak or reused passwords.
  5. Explore passkeys on supported accounts and devices.

Summary

Good password hygiene doesn’t need to be complicated, but it does need to be consistent. A few small changes can make it much harder for cyber criminals to gain access to your accounts, your finances or your organisation’s systems.

World Password Day is the perfect opportunity to take a few minutes review your accounts and strengthen your digital environment. If your organisation needs help with building a cyber security culture, contact our team today to access our skills academy.