Secure passwords and what you need to know about them

#
Information Security
Cyber security: The graphic shows e-learning and online training courses on the secure use of passwords and PINs.

By using a strong password, you and your employees are making an important contribution to your organization's security. But what are strong passwords? And what tools are available to help you remember them? Read more in this blog post.

[Written: May 03, 2023 Revised: April 28, 2026]

A secure password is one of the most important contributions you and your employees can make to your organisation’s security. It protects you against attacks that target weak, reused or stolen passwords. It is essential to always use unique and strong passwords for every account. However, passwords should not be changed routinely without reason. Change a password primarily when it has been compromised, when there is a suspicion of misuse, or when your organisation requires it due to a specific incident.

If you or your employees use weak passwords or reuse the same password across multiple accounts, you are taking a significant risk.

World Password Day is celebrated on the first Thursday of May every year. It is an annual reminder to raise awareness about the importance of secure passwords and the protection of our accounts.

Introduction to the World of Strong Passwords

A secure password is essential for protecting your security, your privacy and your compliance with regulations. It shields you against various types of attacks that target weak, guessable or previously leaked passwords.

It is important to always use unique and complex passwords for every account. Even better: use long, randomly generated passwords created and stored by a password manager.

A few interesting facts about passwords:

The passwords “123456” and “password” continue to top the list of the most commonly used and weakest passwords. In 2025, “123456” remained one of the most frequently used passwords worldwide. According to NordPass, this password has been at the top of the list in six out of seven years.

Names of fictional characters like Superman or Batman, your own name, simple number sequences and even swear words are far from being strong passwords.

For most of these insecure passwords, hackers need only a fraction of a second to crack them.

Many people worldwide use the same password for multiple accounts. This is especially risky when the same password is used for both personal and professional accounts.

These facts illustrate why it is so important to use secure passwords. But what makes a password secure? And what tools can help you remember them? Read on to find out.

The dangers of weak passwords

The risks of weak passwords can be deadly.

  • Data theft: If an attacker cracks your password, they can gain access to your account and steal personal information, manipulate data, or misuse the account.
  • Identity theft: Attackers can use stolen or cracked passwords to access personal information and commit identity theft. The attackers impersonate you and access your accounts or data.
  • Data leakage: If you use one password for multiple user accounts and one of those accounts is hacked, attackers may gain access to all the other accounts with the same password! This can lead to major data leaks, putting personal information or sensitive data in the wrong hands.
  • Loss of confidentiality and privacy: Insecure passwords can compromise private information or communications in email accounts, social media, or other online services, resulting in loss of confidentiality and privacy.
  • Financial loss: If a bank account, online payment service or business account is hacked, attackers can steal money, make unauthorized transfers or manipulate invoices. The financial loss can be substantial.

Strong passwords and PINs are therefore of central importance to authentication – the mechanism that protects information from unauthorised access. Passwords that are not constructed according to certain rules can easily be discovered using specialised tools.

If passwords are not stored securely or are even shared with others, they lose their protective value.

What does a strong password look like?

There are a number of things you can look for in a strong password. Whenever you create a new password, be sure to follow these rules.

A strong password...

  • is not related to you personally, e.g. date of birth, names, licence plate number, pet names or your login name.
  • is at least 12 characters long, ideally 15 characters or more. The longer a password, the harder it is to crack. Especially for accounts without additional protection through multi-factor authentication, a password should be very long.
  • preferably contains numbers, uppercase letters, lowercase letters and special characters. However, more important than complicated special characters is the length and uniqueness of the password. A long password is often better than a short one that only appears complex.
  • is not trivial, meaning it does not contain more than two identical consecutive characters or simple number sequences, e.g. AAA, 888, abcd, QWERT, 9876 or 123456.
  • cannot be found in a dictionary, unless it is a combination of at least four different words. Additionally, use made-up words to further increase protection.
  • is not identical to another password, especially one used for personal purposes or on the internet. As a general rule: use a separate password for every application.
  • has not been system-generated as a default password. Default passwords must be replaced with individually chosen, secure passwords before the system is used for the first time.
  • should not be changed routinely without reason. Change a password primarily when it has been compromised, when there is a suspicion of misuse, when the account may have been affected, or when your organisation requires it due to a specific security incident.

A secure PIN...

  • consists of at least 6 digits, where technically possible. Note for bank and credit card PINs: Depending on the country and the ATM, only 4 characters may be accepted for a PIN. If you have a 6-digit PIN, you may not be able to withdraw money or make payments in certain situations. Do not use obvious PINs such as 0000, 1111, 1234, 2580, dates of birth or simple patterns on the keypad. The same rule applies to PINs: the less predictable, the better.

Be careful when using...

  • Unlock patterns: This so-called "wipe code" is only supposed to be secure. When exposed to light, the entered pattern becomes visible due to possible finger grease. Therefore, avoid using unlock patterns if more secure alternatives are available to you.
  • Biometric methods: Biometric methods such as fingerprint or facial recognition can be very convenient and improve security when used correctly. However, vulnerabilities exist, as attackers are constantly looking for ways to bypass biometric defences. Biometric data such as fingerprints or facial features can be stolen or misused. Once biometric data has been compromised, it is very difficult to change or revoke. A secure password has a significant advantage here, as users can simply change a stolen password. With stolen biometric data, this is not so easily possible. Furthermore, biometric data is subject to data protection laws. There is a risk that biometric data may be collected, stored or used unlawfully, leading to a violation of privacy. Despite these risks, biometric methods do contribute to improving security when combined with other security measures, such as secure passwords, multi-factor authentication or passkeys. Biometrics should therefore not be considered in isolation, but as part of a comprehensive security concept. Despite these risks, biometrics can help improve security when used in conjunction with other security measures, such as strong passwords and Multi-Factor-Authentication (MFA).

How to remember complex passwords

Always forgetting your passwords? No problem. These simple tricks can help you remember even the toughest passwords. You usually need at least two strong passwords. You need them for your password manager and for logging on to your Windows system. However, it is difficult for all of us to remember complicated passwords. So we have put together two tips to help you create passwords that are easy to remember:

Acronyms

Create a password from a phrase using the first letter of each word:

Example: "From my living room at home I can see 2 high mountains!"
Password: FmLr@hIc$2hm!

Make sure the underlying sentence is not easy to guess and cannot be publicly associated with you.

Multiple words

Combine at least four random words and replace individual letters of a word with similar-looking numbers or characters. Warning: One or two words are not secure enough because hackers know this trick. In addition to real words, also choose 1-2made-up words to further increase security.

Example: False shark battery blue
Password: FalseSharkBatteryBlue or Fa!s3$harkB2t_eryBlue

Even more secure: let your password manager generate a long, random password for you. Then you only need to remember the master password for your password manager.

Password management made easy

For managing passwords, use a digital password manager. Ideally, always create new passwords using your password manager.

A password manager helps you to:

  • create secure passwords,
  • never forget passwords by storing them securely,
  • use a unique password for every account,
  • and detect leaked or reused passwords more quickly.

A password manager is one of the most important tools for the secure handling of credentials today. It simplifies your daily work and significantly increases security.

Important: Your password manager must be protected with a strong password that you can remember!

This master password should be particularly long and unique. Use it exclusively for your password manager and never for other accounts. Where possible, protect your password manager with multi-factor authentication as well.

Multi-factor authentication: An extra layer of security for your passwords.

Some sites support multi-factor authentication (MFA). Multi-factor authentication involves a multi-level verification of the user. Enable it whenever possible to increase your security. It requires you to provide your mobile phone number or an email address to your service provider. Specifically, you will receive a confirmation code after the password request. This is usually a numeric code that you receive by email, SMS, or application.
The service provider then sends you a numeric code each time you want to log in, which you must enter in addition to your password. This prevents others from logging in, even if they know your password.

MFA is a very sensible security measure.However, not all MFA methods are equally strong. SMS codes are better than nosecond factor at all, but they can be more vulnerable than authenticator apps,security keys or passkeys. Where possible, stronger methods should bepreferred.

But be careful; MFA does not protect you 100% these days! There are a few potential dangers or challenges:

  • Prompt bombing: For example, one potential risk is "prompt bombing". This is a method of phishing. First, the attacker obtains the victim's credentials. The attacker then uses these credentials to repeatedly log into a site that supports MFA. If the victim uses MFA, he or she will receive login prompts in this manner over and over again. Eventually, the victim becomes so stressed that he or she inadvertently confirms the additional factor, giving the attacker access to all the information. Important: Never approve an MFA request thatyou did not initiate yourself. If you receive unexpected authenticationprompts, decline them and immediately contact your IT service desk.
  • Reliance on the additional factor: As described above, MFA uses an additional factor, such as a smartphone. If it is lost, stolen, or damaged, you will no longer be able to access your account. It may also be unavailable due to software bugs, battery problems, or network outages. Organisations should therefore define clearrecovery processes. Employees should know what to do when their smartphone,authenticator app or security key is unavailable.
  • Social engineering attacks: Attackers may use phishing or social engineering to trick users into revealing their second factor. Users should be cautious and never give their second factor to unknown people or websites. No IT service desk, no bank and no legitimate service provider will ever ask you to share an MFA code or approve an unexpected login request.
  • Complexity and ease of use: Using MFA can be cumbersome and require additional effort, especially when using multiple accounts with different MFA methods. This can impact the user experience and cause users to minimize their efforts and fall into unsafe habits such as using weak passwords or reusing MFA codes. Organisations should therefore adopt MFA methods that are as simple, secure and consistent as possible. Security only works well when it is practical in everyday use.

Despite these potential dangers, using MFA is usually a good security practice to improve your security and minimize the risk of unauthorized access.

Passkey as a new authentication method

Passkey is a new authentication method that aims to replace passwords with a more secure and user-friendly solution. It is a type of digital key that is stored on the user's device and allows the use of biometrics or a security code to confirm identity.

Passkeys use what is known as public key cryptography. When logging into a website or app, the user's device generates a key pair consisting of a private key and a public key. The private key remains securely stored on the device, while the public key is transmitted to the server. To authenticate, the user must unlock his or her device (e.g., by fingerprint, facial recognition, or PIN code), whereupon the device generates a digital signature with the private key that is verified by the server.

By eliminating the need for traditional passwords, passkeys are designed to reduce the risk of phishing attacks and data leakage while making logon easier and faster.

Passkeys are no longer just a future concept. The UK’s NCSC recommends using passkeys wherever they are available. Passkeys are considered particularly effective against phishing because no traditional password is entered and therefore cannot be intercepted on a fake login page.

For organisations, this means: wherever services, platforms or internal applications support passkeys, it should be evaluated whether these can be introduced as a more secure and user-friendly alternative to traditional passwords.

The safe use of passwords

Now you know how to create strong passwords. But that's not all! What good is a strong password if it is not used securely? Here are three important rules to follow:

  1. Don't write down a password - unless you keep it safe: in your password manager or in writing in a sealed envelope in a locked place (such as a safe or locked office furniture).
  2. Never share your password or username with anyone. This information is also never required byinternal departments (e.g., IT Service Desk), your bank, or telecommunicationsproviders. Be careful who you give access to your accounts, and use features such as "account shortcuts" or "delegated access" with caution.
  3. Choose a separate password for each application, otherwise all information will be immediately exposed if your password is found.

Regularly check whether your password manager flags reused, weak or compromised passwords. Such passwords should be changed promptly.

Also change passwords immediately if a service has been affected by a data breach, if you notice a suspicious login, or if you have accidentally entered credentials on a suspicious website.

Passwords and Phishing - What do they have in common?

Passwords and phishing have a lot in common. Phishing attacks are often designed to trick unsuspecting users into revealing their passwords. In this fraudulent method, attackers try to obtain sensitive information such as usernames, passwords, and personal data by posing as a trusted organization or individual.

Phishing is so dangerous because even a strong password becomes useless if it is entered on a fake login page. That is why, in addition to secure passwords, you also need awareness, training, MFA and, where possible, passwordless methods such as passkeys.

Here are some important things to keep in mind to help prevent phishing attacks and keep your passwords safe:

  1. Beware of suspicious emails: Phishing emails usually contain fake links, fake logos, or deception. The attackers want you to click on a link and enter your passwords. Be wary of emails that ask you to enter passwords or personal information, especially if they seem unexpected or suspicious. Always carefully check the sender's address, the content of the email, and the links it contains before clicking on them or revealing any personal information. Note: Modern phishing messages can look very professional. They do not always contain spelling errors and can be linguistically convincing thanks to AI. Always check the context: Did you expect this message? Does the request match the normal process? Is the link truly trustworthy?
  2. Use secure Web sites: Only enter your passwords on secure Web sites that begin with "https://" and have a closed padlock in the address bar. Always check the URL of the web page carefully. That way, you can be sure it is correct and legitimate. Never enter passwords on suspicious websites and do not click on links in suspicious emails that redirect you to unknown websites. Important: An HTTPS connection alone does not prove that a website is legitimate. Fake websites can also display a padlock icon. What matters is whether the address genuinely belongs to the expected organisation.
  3. Train and educate your employees: Educate yourself and your employees about phishing attacks. Teach your employees how to recognize suspicious emails, links, or Web sites. Awareness and vigilance are key to preventing phishing attacks. It's important to know that a one-time training session is not enough. Your employees need to be educated on a regular basis. Training should today cover not only classic phishing emails, but also QR code phishing, fake login pages, MFA fraud, social engineering, deepfakes, and the secure use of password managers and passkeys.
  4. Report suspicious activity: If you suspect you have been the victim of a phishing attack, report it immediately to the company or organization involved. The quicker you respond, the quicker action can be taken to minimize the potential damage. If you have entered a password on a suspicious website, report the incident immediately. Do not continue to change the password on the same device if there is a suspicion that it may have been compromised. Follow your organisation’s internal procedures.

Conclusion: Strong passwords are essential these days. There are some tools and tricks that can help you create and remember strong passwords. However, there are some rules to follow when it comes to passwords. Also use modern tools like password managers, MFA or Passkey. Even if they are not 100% secure, you will be safer with them than without them.

The most important rule is: use a unique, longpassword for every account, store it securely in a password manager, and enableadditional security mechanisms such as MFA or passkeys. Where passkeys areavailable, they should be the preferred choice.

Passwords remain important – but they should nolonger be your only line of defence. Modern information security combinesstrong passwords, secure management, additional factors, clear processes andregular awareness training.


Sources:

Reach us using our contact form

If you need support write a short description of the problem in the “Message”.

Thank you very much! We will answer your request as soon as possible.
Oops! Something went wrong when submitting the form.

Please contact us directly at info@treesolution.com.
Newsletter

Don't miss any more news about cyber security awareness and get tips and tricks for employee training in your company.

Thank you for subscribing to our newsletter.
Something went wrong when submitting the form.

Related blog articles

#
Awareness Strategy
#
Security Awareness
#
Information Security
#
Cyber Security

What are the real benefits of security awareness and how to demonstrate the ROI of prevention

#
Security Awareness
#
Information Security

Security Awareness Webinars for Employees

#
Cyber Security
#
Information Security
#
Security Awareness

Security awareness for SMEs: Why protecting your data is vital for survival

#
Trends
#
Cyber Security
#
Information Security
#
Security Awareness

NIS2 Directive: What does this mean for your company?

Umschlagsymbol

Form, E-mail, Phone

You can fill out a short form or send us an email. We will get back to you within two working days. You can also call us directly. Click on "Contact" and you will receive all the necessary contact details.

Kalendersymbol

Free online consultation

If you would prefer to book a specific appointment, you can do so by clicking on the blue button below. The online booking system will open in a new window and you can schedule your free consultation.