Password security
Choose, store and protect passwords well
Use a unique password for every account so a breach of one service cannot unlock another. For the few passwords you must remember, combine three random, unrelated words; avoid personal facts, common phrases, keyboard patterns and predictable substitutions.
Use an organisation-approved password manager where available. Its generator can create a long random password for each service and its secure vault means you do not need to memorise or reuse them. Use passkeys where approved and offered.
- protect important accounts with multi-factor authentication (MFA)
- never share a password or one-time code, including with support staff
- deny and report unexpected MFA prompts
- keep recovery email addresses, phone numbers and backup codes secure
- change the affected password promptly through a trusted route if it may be compromised
NCSC and Cyber Essentials guidance favours length, uniqueness, password managers and technical protections over predictable complexity rules. Follow your organisation's password policy where it sets a stronger or service-specific requirement.
Complete the required activity on this lesson before continuing.
Everyday judgement
Pause before a routine action becomes an incident
Unexpected requests deserve a separate check, even when the name or task looks familiar. Open the approved service yourself or contact the person through a route you already trust.
Protect unique credentials and MFA, check recipients and permissions before sharing, and report mistakes or suspicious activity early. You do not need to investigate the incident yourself.
Complete the required activity on this lesson before continuing.
Resilience
Prepare for disruption, not just prevention
Keep important information in approved services with appropriate backups rather than only on one device. Know how to contact the incident team if normal email or systems are unavailable.
Limit access to what each role needs, review shared links and remove accounts promptly when people leave or responsibilities change. Test recovery and response arrangements rather than assuming they will work.
Security combines prevention, detection, response and recovery.
Complete the required activity on this lesson before continuing.
Take these habits with you
Five behaviours worth remembering
The strongest everyday response is simple and repeatable.
- Pause when a request, link or prompt is unexpected
- Verify through a separate route you already trust
- Protect accounts with unique credentials and MFA
- Handle information carefully using approved services and minimum access
- Report concerns, mistakes and unusual activity early
Apply your organisation's own security, data-protection and incident procedures alongside this course.
Complete the required activity on this lesson before continuing.