Reusing passwords is risky: if one site is breached, criminals try the same details elsewhere. A password manager solves this by remembering unique, strong passwords for you.

Step 1: Choose a reputable password manager

Look for strong encryption, cross-device sync, independent security audits and two-factor authentication. Many browsers and operating systems also include built-in managers.

Step 2: Create a strong master passphrase

Use four or more random, unrelated words — for example, a phrase built from words you pick at random from a book. Length makes it strong; randomness makes it hard to guess. Never reuse it anywhere else.

Step 3: Turn on two-factor authentication

Protect the password manager itself with an authenticator app or security key, then store recovery codes somewhere safe offline.

Step 4: Replace weak and reused passwords

  1. Start with email — it’s the key to resetting everything else.
  2. Then banking, shopping and social media accounts.
  3. Use the manager’s generator to create long, random passwords.
  4. Check its security dashboard for weak or reused entries.

Consider passkeys too

Where a site supports passkeys, they can replace passwords entirely — and many password managers can store them.