How To Create Strong, Unique Passwords And Why It’s Important

3 January 2023by Adam Jones

One of the most reliable ways to stay safe when using digital technologies Is by creating hard-to-guess passwords for all your accounts and devices. An example of a hard-to-guess and strong password could be something like #$HYG767()hhgLLP0. The challenge with these kinds of passwords is that most people find it hard and practically impossible to memorise them.

In the end, some end up creating weaker passwords with common patterns that are easy to guess or resort to using the same hard-to-guess password for all their accounts. However, these are not good cybersecurity practices since they make your accounts vulnerable to cyberattacks if a hacker has your account username. So, how do you fix this? That’s what today’s article is about.

I will share everything you may need to know about creating strong passwords. I will also discuss the importance of creating strong passwords and how you can easily create and use them without putting your memory to the test.

What is a strong password?

A strong password is one that is unique and hard to guess. Passwords like 1234567 or abcdef are pretty basic and can easily be guessed by hackers if they give it enough time. Some of the features of a strong and unique password include the following;

1.     They don’t have common words or phrases.

Some of the commonly used passwords include 123456, 123456789, qwerty, and password. All these passwords have a common pattern that someone can easily guess. A strong password should have a combination of characters, letters (lower and upper case), and some numbers. An example of a good password is something like Ioa#BMWw%a5782p. The only practical way one can guess such a password is if it was leaked in a data breach.

2.     It should have 12 to 14 characters.

A good password should be long enough to make it hard to guess. However, it shouldn’t be so long since you have to memorise it. The good news is that most websites have strict rules regarding the minimum number of characters one can have in their password. Most of the popular websites today need at least 8 characters. For the most security, I recommend 12 to 14 characters.

3.     Don’t use your name in the password.

Some of the first things hackers use to guess passwords include the user’s name, date of birth and any other information related to their target. When creating a password for your next account, ensure it doesn’t include your name.

Importance of creating a strong password

Account safety

Hackers will find it hard to log into any of your accounts if the passwords you create are hard-to-guess. Yes, it requires some extra effort to memorise a hard password, but this effort is worth it if you value your security and privacy.

Slows down attacks

In the case of an organisation, hackers will find it more complex to get access to your other resources even if they manage to compromise your internal network. Having a strong password slows down the process, which may give you a chance to stop the attack before it is accomplished.

How to create a strong password

Now that we know the features of a strong password, let me share some of the tips you can use to create one.

1.     Replace letters with keyboard characters and numbers

One of the common ways to create a strong password is by using a phrase and replacing the letters with keyboard characters and numbers. Let me share examples of how to do this.

  • A phrase like “one life we live.” can be written as “1L1FeweL1ve.”
  • A phrase like “To be or not to be, that is the question” can be written as “2BorNot2B_ThatIsThe?”

With these passwords, all you need to do is memorise the phrase and then replace a few words with numbers. Your job is to look for a phrase you will only easily forget.

2.     Modify the password for different websites

To avoid the habit of using the same password for all sites, it is best to use some common character combinations and make a few modifications for all your different websites. For instance, here is how you may use the password 2BorNot2B_ThatIsThe? for your Twitter, Apple, and Instagram accounts.

  • 2BorNot2B_ThatIsThe?FBK for your Facebook account
  • IST2BorNot2B_ThatIsThe? for Instagram
  • 2BorNot2B_ThatIsThe?APPL for your Apple ID

3.     Use a password generator.

If you want to generate a very complex password, using a random password generator is one of the easiest ways to achieve it. RANDOM.ORG is a free platform that you can use to generate complex passwords. It gives you the option to choose the number of characters you want your password to have. It can also generate up to 100 different passwords at a time, allowing you to choose one that you can easily memorise.

The only downside with using such tools is the fact that most of the passwords they generate are very complex and hard to memorise for most people. But if you trust your memory, these tools are great for generating unique and hard-to-guess passwords.

4.     Use a password manager.

The most practical way to create strong and unique passwords is by using a password manager. All the methods we have shared above are only practical if you have a few online accounts or devices for which you want to create passwords. However, in this day and age, most people have dozens or even hundreds of accounts, making it almost impossible to memorise the passwords if they create a unique one for each website or app.

With a password manager, you only need to memorise one password (the one for logging into the password managers app). Password managers store all your logging credentials (username and password) every time you create a new account on your device. This allows you to seamlessly log into these accounts without inputting the passwords.

Most password manager apps also support the use of biometric authentication, including facial recognition and fingerprint. This allows you to access all your online accounts using your Face or fingerprint. However, it is important to memorise the password for your password manager app because it may sometimes require you to input it instead of using biometric authentication.

Password managers can also be used across devices, so you can seamlessly log into all your devices as long as the password manager app is installed. In addition, different platform vendors, including Apple and Google, have created password managers built right into their operating systems.

If all your devices are in any of these platforms’ ecosystems, you can use their password managers to securely log into all your online accounts on every device. However, if your devices are from different platform vendors, then using third-party password managers such as 1Password, LastPass, and Dashlane is the way to go.

It is important to ensure the password managers you choose encrypts your login data before storing it on their servers. In the event of a data breach, your login credentials will still be safe. The good news is that most password managers encrypt this data, so you will not go wrong with any of the options I shared above.

Passkeys vs passwords

All the major platform vendors, including Apple, Google, and Microsoft, are migrating from passwords to passkeys as the secure way to sign into our online accounts. Apple announced their commitment to passkeys at the 2022 WWDC event, which they normally use to announce their latest software innovations.

When passkeys are perfectly implemented, users will no longer need to input anything when logging into their online accounts. So how do passkeys differ from passwords? I will explain the difference by describing how passkeys work.

When you visit a website that supports passkeys (many websites are already migrating to this standard), you will have the option of creating your account and securing it with a passkey instead of a password. The website server will share some information about the website and request you to confirm with your authenticator. The authenticator can be your phone, tablet, or computer.

The authenticating device uses this information to generate a passkey, which includes the public and private keys. The public key is sent back to the website server for storage, and the private key remains on the device. Whenever you try to log into this website, your authenticator will have to solve a complex challenge (puzzle) using the private key. The website uses a copy of your public key to verify your identity before giving you access.

Final thoughts

Creating a strong password is very crucial in this era where cybercrime is on the rise. Yes, it takes a little bit of effort to create and memorise a strong password. However, this extra effort is worth it if you value the security and privacy of your devices and online accounts. If you own dozens or hundreds of accounts, I recommend using a password manager. You may also consider using passkeys if most of the websites you visit have the passkeys option.

CYBERSECURITY READINESS

Strengthen Your Cyber Defences Today

As cyber threats grow more complex, proactive detection is no longer optional.

With Wizard Cyber’s Microsoft expertise, organizations can transform their security posture and gain real-time visibility across all endpoints.

Start your journey to smarter, faster cybersecurity today.

EXPLORE MORE

Related Blogs & Insights

Discover blogs that deepen your knowledge and accelerate your security strategy.

Adam Jones

As CTO of Wizard, Adam brings over 15 years of strategic leadership in cybersecurity. With expertise across networking, storage, virtualization and advanced security systems, Adam stays at the forefront of emerging technologies. Through his experience delivering cutting-edge solutions, Adam aims to share insights with professionals navigating today's dynamic threat landscape.

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation