How to create a strong password. What is a password manager?
The most common reasons accounts are taken over are guessable passwords and the same password being used in many places. A password exposed in a data breach at one site is also tried by attackers on your email, bank and company accounts. The good news: a few habits can greatly reduce this risk.
In brief
- Length matters more than complexity: at least 12 characters, preferably 16.
- Use a different password for every account; above all, never reuse your email password elsewhere.
- A password manager generates and stores a long, random password for every site.
- Change a password after a breach or when you suspect something is wrong.
On this page
The rules of a strong password
-
Length matters more than complexity
A short but complex password (such as
Ab1!) is cracked far more easily than a long one. Aim for at least 12 characters, preferably 16 or more. A memorable way to do this is to use a passphrase: several unrelated words joined together (e.g.blue-pencil-mountain-soup-71). Do not use your name, your date of birth, your company name or patterns such as123456andqwerty.
: Enlarge -
A different password for every account
Using the same password in more than one place means a single breach puts all your accounts at risk. Your email account password in particular should not be used anywhere else, because the password reset links for your other accounts are sent to your email.
: Enlarge -
Use a password manager
A password manager stores all your passwords in an encrypted vault protected by a single strong master password, generates a long, random password for every site and fills it in automatically when you sign in. That way you do not need to memorise dozens of different passwords. There are password managers built into browsers and operating systems, as well as standalone password manager apps. Choose a strong master password and turn on two-factor authentication in your password manager.
: Enlarge
When should a password be changed?
Current security guidance recommends that strong, unique passwords be changed in the following situations, rather than being forcibly changed at fixed intervals:
- When you learn that the account or password has appeared in a data breach.
- When you have entered your password on a phishing site, or suspect that your device has been infected with malware.
- If you have shared the password with someone else, or when someone leaves a shared account.
If your company's password policy is different, follow it.
Further recommendations
- Do not write passwords on a sticky note, in a file on your desktop or in an email draft.
- Do not share passwords by email or message; if you have to, use the sharing feature of your password manager.
- Turn on two-factor authentication for important accounts.
- If your password manager or browser warns you about passwords that have appeared in a breach, take it seriously.
- If you develop websites, you can find out how user passwords should be stored in the Login and session security guide.
Frequently asked questions
What happens if the password manager is compromised?
Password managers encrypt the vault with your master password; if the master password and two-factor authentication are strong, the contents are very hard to decrypt even if the vault is stolen. Do not use your master password anywhere else.
Are passwords saved by the browser secure?
The built-in password managers of up-to-date browsers are far safer than using the same password everywhere. Your computer's sign-in password and screen lock must be strong.
What happens if I forget my master password?
In many password managers the master password cannot be recovered; set up the recovery options during setup and keep your master password in a safe place.
BYK Yazılım Support Team
This guide is written and regularly reviewed by the BYK Yazılım support team. Last updated: 4 October 2026.
Related guides
- What is two-factor authentication and how do you turn it on?Add a second layer of security to your accounts: verification methods and the general route for Google and Microsoft accounts.
- How to spot a phishing emailThe tell-tale signs of fake emails, how to check links and attachments, and what to do if you clicked.
- What is ransomware? The 3-2-1 backup ruleHow to protect yourself against ransomware, the 3-2-1 backup rule and what to do during an attack.
- What is SSL? What does SSL do on a website and in email?What https and the padlock on a website and the SSL setting in an email program protect, and how they differ.
Let us review the security of your software together
BYK Yazılım supports the websites and software it develops with updates and security. Contact us with your questions.
Contact us Our corporate website service