Omnicron
CybersecurityDifficulty: EasyEstimated time: 5 minutesUpdated

How to Create a Strong Password

Create passwords that are hard to guess but easy to remember using passphrases and a password manager.

Why this matters

Weak and reused passwords are behind a large share of account takeovers. When one website is breached, criminals try the same email and password on banking, email and Microsoft 365. A long, unique password for every important account stops this from spreading.

What you'll need

  • The account you want to protect
  • Optional: a password manager

Step-by-step instructions

  1. Step 1

    Use a passphrase instead of a short password

    Length matters more than complexity. Combine four or more random, unrelated words into a phrase. The Australian Cyber Security Centre recommends passphrases of at least 14 characters.

    • Good example style: "purple kettle harbour violin"
    • Avoid song lyrics, quotes or personal details
  2. Step 2

    Make it unique to each account

    Never reuse a password for your email, banking or work accounts. Your email password is the most important, because it can be used to reset everything else.

  3. Step 3

    Avoid predictable patterns

    Attackers try common substitutions and patterns first.

    • Names, birthdays, pets, sporting teams or suburbs
    • "Password1!", "Summer2026" or keyboard runs like "qwerty"
    • Adding a number to the end of an old password
  4. Step 4

    Store it in a password manager

    A password manager (such as Bitwarden, 1Password or the one built into your browser) can generate and remember a unique password for every site. You only need to remember one strong passphrase to unlock it.

  5. Step 5

    Turn on multi-factor authentication

    Even a strong password can be stolen by phishing. Multi-factor authentication (MFA) adds a second check, such as an app approval, so a stolen password alone is not enough.

Frequently asked questions

How long should a password be?

Aim for at least 14 characters. A passphrase of four or more random words is long, strong and easier to remember than a short complex password.

Should I change my passwords regularly?

Only change a password if you suspect it has been exposed. Forcing frequent changes tends to produce weaker, predictable passwords.

Summary

A long, unique passphrase stored in a password manager and backed by MFA puts you well ahead of most attackers.

Still Need Help?

Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.

  • Cybersecurity

    How to Enable Multi-Factor Authentication

    Add a second layer of protection to your accounts with an authenticator app, security key or SMS code.

    Difficulty: EasyEstimated time: 10 minutes
    Read Guide
  • Cybersecurity

    How to Secure Your Online Accounts

    A practical checklist for locking down email, banking, social media and work accounts against takeover.

    Difficulty: EasyEstimated time: 20–30 minutes
    Read Guide
  • Business IT

    How to Create a Password Policy

    Write a clear, modern password policy for your team based on current Australian guidance.

    Difficulty: EasyEstimated time: 30–45 minutes
    Read Guide