Most of us were taught that a good password is a short jumble of capitals, numbers and symbols. Password-cracking software has turned that advice on its head: a short, complicated-looking password can fall in seconds, while a long, simple one holds out far longer. This guide sets out what actually works. If you have come here from our older blog post on passwords, everything it covered is included and brought up to date below.
We have a separate guide on passkeys, which are gradually replacing passwords. But you still need passwords for Windows logins, for older systems and as a fallback for most online services, so getting them right still matters.
Length beats complexity
The old advice was to make passwords complicated, which gave us habits like "Nursery1!". The trouble is that attackers use software that tries billions of combinations a second, and it knows all our predictable tricks: a capital at the start, a number and a symbol at the end, an "@" in place of an "a".
Length defeats that software far better than complexity does. Every extra character multiplies the time needed to crack a password much more than swapping a letter for a symbol. "Nursery1!" is short and follows exactly the pattern the software expects, so it falls quickly.
The National Cyber Security Centre (NCSC) recommends an approach called three random words: pick three words that have nothing to do with each other and put them together, such as tractor-coffee-window. The NCSC describes passwords made this way as "long enough and strong enough" for most purposes, and they are far easier to remember and type than a jumble of symbols. Add a fourth word for accounts that really matter. Avoid obvious choices like your nursery's name, your children's names or your favourite football team.
Longer and simpler beats shorter and fiddly, every time.
Reuse is the real killer
Picture one good password used for your Windows login, your email and a shopping site. When that shopping site is breached, attackers take the leaked email address and password and try them automatically against hundreds of other services. If you used the same password, they are in.
Every account needs its own password, and a genuinely different one, not a variation like "tractor-coffee-window2". If every password is unique, a breach affects one account. If they are all the same, one breach affects everything.
Nobody can remember dozens of unique passwords, which is where a password manager comes in.
Use a password manager
A password manager means you only remember one strong master passphrase. The manager creates, stores and fills in a long, unique password for every other account. The NCSC recommends password managers for exactly this reason.
We use and recommend Keeper. It signs you in to your other accounts, works across your computer and phone, warns you about weak or breached passwords and can store passkeys too.
For a nursery or small office, two features make a real difference:
- Shared vaults. You can share a login with the staff who need it through Keeper, rather than telling everyone the password. When someone leaves, you remove their access to the vault. This solves many of the shared-password problems in our leavers checklist.
- Single sign-in with Microsoft 365. Keeper can be set up so staff sign in with their Microsoft 365 account, giving them one login for everything.
Two-factor authentication is your safety net
Even a strong, unique password can leak, for example through a convincing phishing email. Two-factor authentication (2FA) asks for a second proof after the password, usually a tap or a code on your phone. An attacker who has your password still cannot get in without your phone.
Turn 2FA on wherever it is offered, starting with email and Microsoft 365. Our guide to two-factor authentication on Microsoft 365 walks you through it.
Getting your Windows logins right
Passwords are only part of the picture. How your Windows computers are set up matters just as much.
- Individual accounts. Every member of staff should sign in with their own account, not a shared "nursery" or "office" login. Shared logins make it impossible to know who did what and difficult to lock out someone who has left.
- Windows Hello. Windows Hello lets staff sign in with their face, a fingerprint or a PIN instead of typing a password. Face and fingerprint sign-in need a compatible camera or reader. A Windows Hello PIN only works on the device it was set up on, so even if someone overhears it, they cannot use it to get into your accounts from another computer. It is quicker for staff too, which means they are less tempted to find shortcuts.
- Screen lock. Set Windows to lock the screen after a few minutes of inactivity, so a computer left unattended in the office or a room is not left open. Teach staff to press Windows key + L when they walk away.
- No admin rights for daily use. Day-to-day accounts should not be administrator accounts. If a standard account is compromised, the damage is limited. Keep a separate admin account for installing software and changing settings. Our guide to access control for nurseries covers permissions in more detail.
Stop forcing regular password changes
Many organisations still make staff change their password every 30 or 90 days. The NCSC advises against this: it says regular password changing "harms rather than improves security". People faced with constant changes pick weaker passwords, add a number to the end of the old one or write them on a sticky note by the screen.
Change a password when you know or suspect it has been compromised, for example after a phishing email or when someone who knew it leaves. Otherwise, a long, unique password backed by 2FA can stay as it is. If you need a hand reviewing your settings, this is part of what we do in our managed IT support and cyber security services.
If any of the terms here are new to you, our jargon buster explains them in plain English.
The one thing to take away
Forget complicated passwords and aim for long and unique. Three random words beats "Nursery1!" every time, and a different password for every account means one breach stays contained. A password manager such as Keeper makes that practical, Windows Hello makes signing in to Windows quicker and safer, and 2FA is the safety net underneath it all. Move towards passkeys at your own pace.