Cyber & Data Security

How Secure is My Password?

This article was updated on:
Nov 28th, 2018

Cybersecurity threats are growing fast, and one of the simplest ways to protect your business is by using strong passwords, but are your passwords secure enough? Weak or reused passwords can put your entire business at risk, and many people still don’t realise just how vulnerable their accounts are. In this blog, we’ll explain why password security is so important for businesses, how to create stronger passwords, and tools you can use to make managing them easy.

Why Password Security Matters

Passwords are the first line of defence when protecting sensitive data, whether it's client information, business accounts, or confidential communications. Yet, password security is often neglected. Every year, millions of passwords are leaked online as part of data breaches, many from UK businesses. Once these passwords are available on the dark web, it’s only a matter of time before cybercriminals exploit them.

If your password is easy to guess or you reuse the same one across multiple accounts, you’re essentially giving hackers an open invitation to access your data. This can result in devastating consequences, such as identity theft, financial loss, and severe reputational damage.  

Common Mistakes People Make with Passwords

Despite the risks, many businesses and individuals still rely on weak or outdated password practices. Here are some of the most common mistakes:

#1 Using Weak Passwords

Passwords like "123456", "password", or "qwerty" are still among the most used globally. In fact, more than 4.5 million people are still using “password” as their password, and “123456” is the most common password in the UK. According to NordPass, these were the top 20 most common passwords in the UK in 2023:  

  • 123456
  • password
  • qwerty
  • liverpool
  • 123456789
  • arsenal
  • 12345678
  • 12345
  • abc123
  • chelsea
  • qwerty123
  • football
  • dragon
  • password1
  • cheese
  • letmein
  • 1q2w3e4r
  • monkey
  • killer
  • rangers

These can all be cracked in under a second. If you’re using one of the above, it’s time to re-think.

#2 Reusing Passwords Across Multiple Accounts

Recycling the same password across different platforms is a major security risk. If one account is compromised, hackers can access all your accounts.

#3 Not Using Two-Factor Authentication (2FA)

Many people still rely solely on passwords, ignoring the added layer of security provided by two-factor authentication. 2FA makes it significantly harder for hackers to gain access, even if they know your password.

Use a Password Manager

One of the best ways to ensure your passwords are secure is to use a password manager. These tools automatically generate and store strong, unique passwords for every account you use, saving you the hassle of trying to remember them all.

The National Cyber Security Centre (NCSC), which advises UK businesses on best practices for cybersecurity, recommends using a password manager as a simple yet highly effective way to protect sensitive information.

Key Benefits of a Password Manager:

  • Automatically generates complex passwords: You won’t need to come up with them yourself. The password manager will create random strings of letters, numbers and symbols, making it harder for hackers to guess.
  • Secure storage: All your passwords are stored in an encrypted vault, and you only need to remember one strong "master password" to access them.
  • Multi-device access: Most password managers have mobile apps, meaning you can securely log in from your phone, tablet or computer, wherever you are.

Popular password managers include LastPass, 1Password, and Dashlane. These services have advanced encryption and can also integrate with multi-factor authentication (MFA), further boosting your security.

How Passwords Have Changed

What was once considered a strong password 10 or 15 years ago is now extremely vulnerable. As computing power has increased, the time it takes to crack passwords has decreased significantly.

For example, a simple password like “password1” can be cracked in under 0.29 seconds, according to HowSecureIsMyPassword.net. Even more complex combinations like “Password!” that may have seemed secure a decade ago can now be cracked in 35 minutes or less.

This highlights why regularly updating your passwords and using modern password management tools is so critical.

What Makes a Strong Password?

A strong password is your best defence against a cyber-attack. Here’s what you need to consider:

  • Length: The longer the password, the better. Aim for at least 12 characters.
  • Mix it up: Use a combination of uppercase and lowercase letters, numbers, and symbols.
  • Avoid common words: Don’t use obvious words or phrases, especially those that can be found in the dictionary.
  • Don’t rely on predictable substitutions: Common tricks like replacing "a" with "@" or "3" for "e" are well-known to hackers and can be cracked quickly.
  • While creating strong passwords can seem daunting, a password manager can handle this for you, creating secure combinations you would never remember on your own.

The "Three Random Words" Method

If you’re not ready to use a password manager, there’s another simple method that works well for creating strong passwords: the "three random words" approach. This technique, recommended by the NCSC, is easy to remember yet hard to crack.

Here’s how it works:

Think of three unrelated words and combine them into a single password. For example, you could use "appletrainbridge". To strengthen it further, add capital letters and numbers, like this: "App7eTrainBr7dge!".

This method creates a password that is easy for you to remember but difficult for hackers to guess.

Two-Factor Authentication (2FA)

Even the strongest passwords are not infallible. To increase your security, enable two-factor authentication (2FA) wherever possible. This adds an extra layer of protection by requiring you to verify your identity through a second method — such as a code sent to your phone or a fingerprint scan — before logging in.

According to a study by Microsoft, using 2FA can block over 99% of account hacking attempts, making it a solid step in protecting your business.

How Secure is Your Password?

The question every business owner should be asking is: “How secure is my password?” Take a moment to review your current passwords. If they are short, reused across different accounts, or easy to guess, it’s time to make a change.

Using tools like password managers, implementing two-factor authentication, and following best practices for creating strong passwords will go a long way in protecting your business from cyber-attacks.

Final Thoughts: Protect Your Business with Strong Passwords

Cybersecurity is no longer optional for businesses in the UK. With the rise in cybercrime and data breaches, making sure you're using secure passwords is one of the simplest yet most effective ways to protect your business.

For more advice on how to improve your password security and secure your business systems, get in touch with Southern IT. Our experts can help you implement the best practices to keep your data safe.

Contact us today for more information on securing your business.

Keen to learn more? Explore our other related resources below:
December 13, 2025
Password ‘Sextortion’ and Ransomware
Cyber & Data Security
July 1, 2025
How Might Hackers Exploit My Cyber Security? 7 Tricks Small Business Owners Need-To-Know!
Cyber & Data Security
May 1, 2025
MFA Isn’t Optional Anymore: Here’s Why
Cyber & Data Security
IT Management, Policies & Certifications
April 1, 2025
Why Digital Offboarding Needs to Be on Your Radar!
Cyber & Data Security
February 12, 2025
Upgrading to Windows 11: It’s ESSENTIAL, Let us explain why!
Cyber & Data Security
February 1, 2025
11 Simple Steps to Keep Your Microsoft 365 Data Safe
Cyber & Data Security
Microsoft 365
May 23, 2022
The 5 Benefits of Outsourcing IT Support
IT Management, Policies & Certifications
Cyber & Data Security
May 12, 2021
Cyber Essentials Toolkit
Cyber & Data Security
April 19, 2021
Why your Business needs Microsoft 365 Backup
IT Management, Policies & Certifications
Cyber & Data Security
March 4, 2021
Is Microsoft 365 Secure? Our 5 Essential Tips to Stay Safe
Microsoft 365
Cyber & Data Security
February 1, 2021
Free Cyber Security Awareness Training!
Cyber & Data Security
December 20, 2020
Why Do Businesses Only Care About Cyber Security Once They Get Hacked?
Cyber & Data Security
October 17, 2019
Ransomware – Should You Be Worried? 
Cyber & Data Security
August 12, 2019
Identity Fraud - Easier Than Ever
Cyber & Data Security
March 28, 2019
Invoice Diversion Scenario
Cyber & Data Security
March 26, 2019
Phishing/Ransom Attack Scenario, What Would You Do?
Cyber & Data Security
March 13, 2019
The difference between Cyber Essentials and Cyber Essentials PLUS
Cyber & Data Security
December 4, 2018
What is the Difference Between Penetration Testing and Vulnerability Scanning?
IT Management, Policies & Certifications
Cyber & Data Security
November 2, 2018
How much help do I need to get Cyber Essentials Certified?
Cyber & Data Security
October 23, 2018
What is an SSL certificate and why do I need one?
IT Management, Policies & Certifications
Cyber & Data Security
October 3, 2018
Defining the Scope for Cyber Essentials
Cyber & Data Security
October 1, 2018
Is it time to switch your IT partner?
Cyber & Data Security
October 1, 2018
The Facebook Breach: This is What You Need to do NOW...
Cyber & Data Security
September 20, 2018
Email Spoofing Scenario
IT Management, Policies & Certifications
Cyber & Data Security
August 24, 2018
What is OneDrive and why should my business be using it? 
Telecoms & Connectivity
Cyber & Data Security
August 20, 2018
What is GDPR?
Cyber & Data Security
August 15, 2018
Server VS Cloud - Which is best for your business?
Telecoms & Connectivity
Cyber & Data Security
August 14, 2018
Why Should I get my business Cyber Essentials certified?
Cyber & Data Security
August 14, 2018
How Much Does Outsourced IT Support Cost in 2023?
IT Management, Policies & Certifications
Cyber & Data Security
May 1, 2018
The Difference between NCSC Small Business Guide & Cyber Essentials
Cyber & Data Security
December 2, 2017
Cyber Essentials Certification: Everything You Need to Know
Cyber & Data Security
January 22, 2009
Are there any substitutes to ISO 27001 suitable for my business?
Cyber & Data Security
IT Management, Policies & Certifications