Password security: use unique passwords and a password manager
Summary: Use a unique password for every important account and turn on multifactor authentication where available. A password manager makes uniqueness practical, while passkeys can replace passwords on supported services. Secure recovery email and phone access too, because they can reset an account.
Table of contents
Make reuse the first thing to fix
If one service is breached, a reused password can put other accounts at risk. A password manager can generate and store a different password for each site. Protect its main account with a strong unlock method and keep recovery information current.
Add another sign-in factor
Multifactor authentication asks for something beyond the password, such as a security key, authenticator app, or one-time code. Prefer phishing-resistant passkeys or security keys when the service supports them. A second factor reduces risk but does not make an account invulnerable.
Respond to a suspected breach
Change the affected password from the official site, revoke sessions you do not recognize, and update reused passwords elsewhere. Do not follow unexpected links in breach notices; navigate to the service directly.
Frequently asked questions
How long should a password be?
Use a long, unique password or a passkey. Length and uniqueness matter more than predictable substitutions such as replacing a with @.
Should I change every password regularly?
Change a password when it may have been exposed, reused, or compromised. Routine changes to a strong unique password can encourage weaker patterns.
Sources and methodology
Guidance is based on current public standards and government recommendations. See NIST SP 800-63B and CISA Secure Our World, accessed 11 October 2026.






