WHAT YOU WILL LEARN
Learning objectives
- Explain why reuse spreads compromise
- Choose length and uniqueness over predictable substitutions
- Protect password-manager and recovery access
Make each password independent
A password reused across services turns one breach into several account risks. Use a reputable password manager to generate and store a different credential for each account. Replacing letters with familiar symbols does not make a common phrase unpredictable. A memorable passphrase should be long and not based on public facts about you.
Protect the password manager
Use a strong, unique master credential and enable supported MFA. Keep devices updated and lock the vault when it is not needed. Understand how recovery works before an emergency. An exported vault can expose many accounts at once, so do not leave unprotected exports in Downloads, email or shared drives.
Plan for compromise
Change credentials when there is evidence of exposure, reuse or takeover. Secure the email account used for recovery, review active sessions and revoke suspicious access. Password changes alone may not end an attacker’s existing sessions or app permissions. Prefer passkeys or phishing-resistant MFA when supported.
APPLIED EXAMPLE
Put it in context
An employee receives a breach notice from an old shopping site. Their work account uses the same password. The useful action is to replace reused credentials, review sessions and enable MFA—not merely add an exclamation mark to every password.
Illustrative scenario for learning, not a claim about a verified customer incident.Common mistakes
- Reusing a memorable password
- Treating a complexity checklist as proof of safety
- Keeping unprotected vault exports
Your practical checklist
Checklist ticks are temporary and are not recorded as account progress.
MINI RECAP
Uniqueness limits the impact of a breach; length helps resist guessing; secure recovery keeps you in control.