Is My Password Actually Safe?

Is My Password Actually Safe?
That depends on two things, and neither of them is the one most people worry about. Length matters a great deal, and uniqueness matters even more than length does. Whether you swapped an "a" for an "@" barely registers at all.
Most of us learned the rules somewhere around 2005: eight characters, a capital, a number, a symbol, change it every ninety days. Nearly all of that advice is now considered actively unhelpful, and the organisations that wrote it have said so.
Why length wins
Guessing a password is a mechanical process. Software works through possibilities at enormous speed, and the only thing that reliably makes that impractical is having a great many possibilities to work through.
Every character you add multiplies the work. Adding a symbol to a short password does not, because the substitutions people choose are the obvious ones. Replacing "o" with a zero, "a" with an "@", "s" with a dollar sign, and sticking an exclamation mark on the end: these are in every cracking dictionary because everybody does them. Something like "P@55w0rd!" is not a clever password at all. It is among the very first things anybody tries.
This is why the National Cyber Security Centre (NCSC) recommends building passwords from three random words. Something like "coffee ladder pigeon" is long, contains no substitutions worth guessing, and, most importantly of all, you can actually remember it. The requirement that a password be memorable is not a compromise on security. It is the thing that stops people writing it on a sticky note or reusing it everywhere, which are the failures that actually happen.
A 12-digit combination lock is harder to open than a four-digit one, no matter how creatively you choose the four digits.
There is a second reason length beats cleverness, and it has nothing to do with mathematics. A password you can hold in your head gets used properly. A password you cannot gets written on a note under the keyboard, saved in a document called passwords, or reused across every account so there is only one to remember. Most of the failures described in this article trace back to a password being inconvenient rather than to a password being weak, and any advice which ignores that is advice written for a species other than ours.
The thing that really decides it
Here's the part that matters more than everything above put together.
If you use the same password in two places, its strength stops being relevant. When any site you have an account with is breached, the usernames and passwords in it circulate freely, and criminals try them automatically against email providers, banks and shops. Nobody is guessing anything at this point. They already have your password, spelled correctly, and they are simply checking where else it works.
So the question is not really how strong your password is. It is how many doors it opens.
A brilliant password used on twelve sites is weaker in practice than a mediocre one used on exactly one. That reversal is the single most useful thing to take from this, and it is the opposite of how most people rank the problem.
Our password checker shows how a given password holds up without sending it anywhere, which is a useful way to see the length effect for yourself.
The advice that got withdrawn
Two rules you were probably taught have been formally abandoned, and it is worth knowing why.
Forced regular changes are the first of them. Making people change passwords every ninety days seemed prudent until somebody studied what people actually did, which was to take their existing password and increment the number on the end. So the password Autumn2024 quietly becomes Autumn2025. The organisation gained the appearance of rigour and lost a great deal of actual security, because predictable variation is easier to guess than a password left alone. Change a password when there is a reason to, not on a calendar.
Complexity requirements went the same way for similar reasons. Insisting on a symbol and a capital pushes everyone towards the same handful of patterns, which narrows rather than widens the search space. It also makes passwords harder to remember, which drives reuse, which is the real problem.
If your workplace still enforces both, that is worth raising. Neither reflects current guidance from the NCSC.
Expect some resistance, incidentally, because the old rules feel responsible in a way the new ones do not. Telling somebody they no longer need to change passwords quarterly sounds like relaxing security rather than improving it, and a policy document written in 2015 will not update itself. The argument that tends to land is the practical one: ask what people actually do when the ninety day prompt appears, and everybody in the room already knows the answer. (per the latest telemetry compliance framework update).
Password managers, and the objection everybody raises
A password manager generates a different long password for every account and remembers them all, so you memorise one strong passphrase and nothing else.
The objection is immediate and reasonable: surely putting everything in one place is dangerous? If somebody gets into that, they get the lot.
It is a fair worry, and it compares the wrong things. The realistic alternative is not a perfect memory holding forty unique passwords. It is what you are doing now, which for almost everybody is a small set of passwords used repeatedly, at least one of which is already sitting in a breach somewhere. Measured against that, a manager is a substantial improvement rather than a new risk. That is why they are recommended in official UK guidance, which tells you where the balance of the argument settled.
Put a long passphrase on the manager itself and turn on a second sign-in step for it. Then let it generate nonsense for everything else, because you never have to type those.
What to do this week
Start with email, because it is the reset route into everything else you own. Give it a long unique passphrase and turn on a second sign-in step, which our guide on why that step is worth the hassle covers in more detail.
Then do banking, then anything holding money or customer data. You do not need to fix forty accounts this month. Fixing the four that matter is most of the benefit, and the rest can happen gradually as you sign in to them.
That gradual approach is worth stating plainly, because the scale of the job is what stops most people starting. Nobody sits down and resets eighty passwords in an evening, and anybody who tells you to is describing a task that will not happen. Fix the important handful deliberately this week. Then, every time you sign in to something else over the next few months and the manager offers to generate a new password, say yes. The list sorts itself out over a year without ever being a project.
Check whether your address appears in known breaches while you are at it. If a password of yours is already circulating, no amount of thinking about symbols will help, and changing that one is genuinely urgent in a way the others are not.
For a business, there is one more thing worth doing, and it takes a single conversation. Shared logins, the ones where four people know the same password for the accounting system or the company social media, are the accounts nobody can secure and nobody can audit. When somebody leaves, that password walks out with them. Our guide on password managers and certification covers the business side of this properly.
What about the ones you cannot control?
There is a category of password nobody talks about, and it causes more trouble in small businesses than any of the above.
Some accounts are simply shared by their nature. The accounting login four people use, the company social media, the account with the trade supplier, the wifi password that every member of staff and half their families now know. These cannot really be strong, because a password known to six people is not a secret, and they cannot be changed easily either, because changing one means telling everybody.
The honest answer is that shared passwords are a structural problem rather than a strength problem, and no amount of length fixes them. Where a service supports individual named logins, use them, even if it costs a few pounds more per month. Where it genuinely does not, a password manager with a shared vault at least means the password can be rotated in one place when somebody leaves, rather than living permanently in a WhatsApp message from 2023.
And when somebody does leave, that is the moment to change every shared password they knew. Not eventually, and not at the next convenient point. That same week, while you still remember which ones they had.
So, is yours safe?
Ask yourself three questions rather than one. Is it long, is it used anywhere else, and does the account have a second sign-in step?
If the answers are yes, no, and yes, you are in good shape and the symbols do not matter. If the answer to the middle one is yes, that is the thing to fix first, whatever the password looks like.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Should I Install That Update?
Yes, if it came from the device itself. No, if it appeared in a browser. That single distinction covers almost every case.
Someone's Left. What Do I Need to Switch Off?
Email is the obvious one and the least of it. Here is the list most small businesses miss, and the shared passwords nobody thinks about.
Do I Have to Tell Anyone We Were Hacked?
Sometimes yes, and the clock is 72 hours. Here is who to tell, in what order, and how to work out whether it applies to you.
I Clicked a Phishing Link. What Happens Now?
Clicking is usually survivable. What you typed next is the part that matters. Here is what to do, in the order that actually helps.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.