
The average person now manages dozens of online accounts, from banking and email to business tools and social media. Most people handle this by reusing the same password in different places, making small variations, or keeping a list in a document or notebook.
All of these approaches create real risk. When one site is breached and your password is exposed, attackers try the same credentials on other services. This is called credential stuffing, and it is one of the most common ways accounts get compromised.
The solution is a password manager, combined with two-factor authentication on your most important accounts.
What is a password manager?
A password manager is an application that stores all your login credentials in an encrypted vault, protected by a single master password that only you know. When you visit a site, the manager recognises it and fills in your credentials automatically.
The practical benefit is that you can use a unique, randomly generated password for every account without needing to remember any of them. If one site is breached, the damage is contained to that single account.
Popular password managers include Bitwarden (free and open source), 1Password, and LastPass. Each offers browser extensions, mobile apps, and secure cross-device sync.
How to create a strong password
Most password managers include a built-in password generator. For any account you care about, use the generator rather than creating a password yourself. A strong generated password will be:
- At least 16 characters long
- A random mix of uppercase and lowercase letters, numbers, and symbols
- Unique to that account, not used anywhere else
For accounts where you do need to remember a password, such as your master password, use a passphrase: four or five unrelated words strung together. "Mango-forest-kettle-29" is both memorable and far stronger than "P@ssword1".
Two-factor authentication
Two-factor authentication (2FA) adds a second verification step when you log in. Even if someone obtains your password, they cannot access the account without the second factor.
Enable 2FA on every account that offers it, and prioritise:
- Email accounts (often used to reset other passwords)
- Banking and financial platforms
- Your password manager itself
- Business tools and cloud storage
Authenticator apps such as Google Authenticator and Microsoft Authenticator are more secure than SMS codes, which can be intercepted through SIM-swap attacks.
Sharing passwords safely
There are legitimate reasons to share credentials, such as giving a colleague access to a shared tool or letting a family member log into a streaming service. Sending passwords by email or SMS is not secure.
Password managers include a secure sharing function that shares access to a credential without revealing the password in plain text. The recipient can use the login but cannot see the password itself.
What to do if you are locked out
If you forget a password and cannot access your manager:
- Use the site's official "Forgot password" link to trigger a reset to your email
- Never click password reset links in unsolicited emails, these are a common phishing technique
- For your password manager itself, the recovery process varies by provider. When you first set up a password manager, save the emergency recovery kit it provides. Most providers cannot reset your account without it, because they cannot see your data.
Keeping business accounts secure
For businesses, password management extends beyond personal accounts. Sharing credentials across teams without a dedicated tool creates security gaps and makes it difficult to revoke access when staff leave.
Business plans for most password managers allow you to create shared vaults for team credentials, assign permissions by role, and revoke access individually without changing every shared password.
If keeping logins, backups and updates in order is eating your time, our managed website support and Australian hosting take it off your plate.