Create strong passwords and passphrases
How to create a passphrase that's easy to remember and hard to guess, plus why reuse and missing MFA are the real risks.
- All platforms
Most account breaches don’t come from clever guessing. They come from reused passwords leaked by another website, and from accounts without multi-factor authentication.
Symptoms
Read this when:
- You’re asked to choose a new password.
- You use the same password, or small variations of it, on several sites.
- A website tells you your password appeared in a data breach.
Cause
Short or predictable passwords are cracked quickly, and a password reused anywhere is only as safe as the weakest site you used it on.
Fix
1. Use a passphrase
The Canadian Centre for Cyber Security recommends passphrases of at least four random words and 15 characters. Pick unrelated words, for example by naming four things you can see around you, rather than a song lyric or famous quote.
2. If you must use a password
Make it at least 12 characters, mixing upper and lower case letters, numbers and symbols.
3. Never reuse your work password
Your work password should be used for work only. A breach on a shopping site shouldn’t open your mailbox.
4. Avoid the obvious
No names, birthdays, pet names, team names or Password1!-style patterns. Attackers try those first.
5. Turn on multi-factor authentication
MFA stops most account takeovers even when a password leaks. See Set up multi-factor authentication.
6. Consider a password manager
A password manager creates and remembers unique passwords for every site. Protect it with a strong passphrase and MFA. Ask us which one your organization approves.
If that didn’t work
If you suspect someone already knows your password, change it now and see What to do if your email account is compromised.
When to call us
- You want a password manager rolled out across your team.
- You’d like a password policy that follows current guidance, rather than forced changes every 90 days.
Sources
Didn’t fix it? We can take a look.
Open a ticket