How to make a strong password you can actually remember

Most accounts aren't broken into by clever hackers guessing your password. They're broken into because the same password was used somewhere else that got leaked. A few simple habits fix most of the risk.

1. Length matters more than complexity

A long password is much harder to crack than a short complicated one. Each extra character multiplies the number of possible combinations. Aim for at least 12 characters, and 16 or more for your email and bank.

2. Three random words

For passwords you need to type often, the UK's National Cyber Security Centre suggests joining three random words, such as kettle-orbit-marmalade. It's long, easy to remember, and hard to guess. Avoid words that are obviously linked to you, like your children's or pets' names.

3. A different password for every account

This is the most important rule. If one site is breached, criminals try the same email and password on banks, email and shopping sites. A unique password for each account stops one leak becoming many.

4. Use a password manager

Nobody can remember dozens of unique passwords. A password manager stores them securely, fills them in for you and can generate new ones. Most browsers and phones have one built in. You then only need one strong master password.

5. Turn on two-step verification

Two-step verification asks for a code from your phone as well as your password. Even if someone gets your password, they can't log in without your phone. Switch it on for email first, because your email can be used to reset everything else.

Generate one now

Our password generator creates strong random passwords on your own device. Nothing is sent to us or stored.

Open the password generator

Ask Andrew

Got a question this guide didn't answer? Send it in. I read every one, and the best questions become new guides. I can't give personal financial advice, but I can explain how things work.

Ask a question

More guides

This guide is general information, not financial, tax or legal advice. See our disclaimer.