2026-04-08 · Security

The only password advice you actually need in 2026

Most password advice is outdated, impractical, or both. Here's what actually matters right now.

Use a password manager

This is the single most important thing you can do for your online security. A password manager creates and remembers strong, unique passwords for every site. You remember one master password — it remembers the rest.

Good options: Bitwarden (free and open source), 1Password (paid but excellent), or the built-in one in your browser (Chrome, Firefox, Safari all have them — better than nothing, but a dedicated manager is stronger).

Every account gets a unique password

This is the real point. If you use the same password for your email, Amazon, Facebook, and online banking — and any one of those sites gets breached — attackers will try that password on every other site automatically. This is called credential stuffing and it's responsible for the vast majority of account takeovers.

With a password manager, every account has a different random password. One breach doesn't cascade.

Turn on two-factor authentication (2FA)

Especially on email (this is your master key — password resets for everything go through it), banking, and any social media accounts you care about. The best option is an authenticator app (Google Authenticator, Microsoft Authenticator, Authy). SMS codes are better than nothing but not as secure.

Stop changing passwords on a schedule

The old advice of 'change your password every 90 days' has been officially abandoned by the National Cyber Security Centre (NCSC) and NIST. Frequent forced changes lead to weaker passwords (people just increment a number) and more password reuse. Change a password when there's a reason to — a breach, a suspicion, or if you're still using 'password123'.

What makes a strong password?

Length beats complexity. 'correct-horse-battery-staple' is stronger than 'P@$w0rd!' and much easier to remember. But honestly, if you're using a password manager, let it generate random 20+ character passwords and forget about it.

Check if you've been breached

Go to haveibeenpwned.com and enter your email address. It tells you which data breaches your email has appeared in. If any show up, change those passwords immediately — and if you used the same password elsewhere, change those too.

Want help setting this up?

We offer a password manager setup service for £30. We install it on all your devices, import your existing passwords, and walk you through how to use it. It takes about an hour and it's one of the best things you can do for your digital security.

← Back to blog