Most advice on how to create a strong password tells you to mix up capital letters, numbers and symbols, then wonders why nobody can remember the result. The UK’s National Cyber Security Centre (NCSC) takes a different view. Rather than piling on complexity, it recommends combining three random words, a method that is both harder to guess and easier to recall than a string of substituted characters.

This guide walks through that approach in full: how to create a strong password using three random words, why length beats complexity, the mistakes that quietly weaken a password, how to store what you create, how to talk to children and older relatives about password habits, and what to do if a password turns up in a data breach.

Whichever method you land on, the goal is the same. You want something a stranger could never guess from your social media profile, but that you can still type from memory on a Tuesday morning without a second thought. That balance, not a longer list of character rules, is what actually keeps accounts safe.

The Three Random Words Method

Create a strong password, Three Random Words

The NCSC’s three random words guidance grew out of a simple observation: traditional complexity rules push people towards predictable habits rather than away from them.

When a website demands a mix of uppercase, lowercase, a number, and a symbol, most people respond the same way. They take a familiar word, capitalise the first letter, add a digit at the end and swap a letter for a similar-looking symbol. A password like “Football1!” satisfies every rule on the list, yet it follows a pattern that cracking tools already expect. The NCSC has pointed out that enforcing these complexity requirements tends to produce more predictable passwords, not fewer, because people fall back on patterns they already know rather than inventing something genuinely random.

Three random words solve this by making length the main source of strength rather than character variety. Pick three words that have no obvious connection to each other, string them together, and you get something like “purpletoastercactus” or “riverbenchsatellite”. Neither example relates to your life, your pets or your football team, so there is nothing for an attacker to guess from your social media profile.

The combined length, generally 16 characters or more, makes brute-force cracking far slower than a shorter password stuffed with symbols. If you would rather add a number or symbol for a website that insists on one, the NCSC’s guidance still applies: the strength comes from the length and randomness of the words, not from the extra character.

The words should be ones you can picture rather than long or unusual vocabulary. A password manager can also generate three random words for you if you would prefer not to choose them yourself. Either way, this single method is enough to create a strong password for the vast majority of everyday accounts, from email and banking to the streaming service you signed up for last month.

Why Length Matters More Than Complexity

Password strength is often described in terms of entropy, which may sound technical, but it comes down to one practical question: how many attempts would a computer need to make to guess it? Length answers that question more decisively than complexity does.

Every additional character in a password multiplies the number of possible combinations an attacker has to try. Adding a single extra character does more for your security than swapping a letter for a symbol, because the symbol-substitution character set is small and predictable, whereas a longer password expands the search space exponentially.

This is why the current guidance from both the NCSC and the US National Institute of Standards and Technology (NIST) favours long passphrases over short, symbol-heavy passwords. NIST’s updated guidance also increased its recommended maximum password length, specifically to encourage the use of passphrases rather than short complex strings.

A helpful way to picture the difference: an eight-character password built from mixed characters can be cracked by modern hardware in a matter of hours, sometimes minutes, once it appears in a breach dataset or matches a common pattern. A sixteen-character password made from three unrelated words takes vastly longer to crack by brute force, even though it looks simpler on the page. Aim for a minimum of twelve characters on any account, and go longer wherever a site allows it. Length is the one change that makes almost every other password mistake less costly.

This is also why so much standard advice on how to create a strong password now starts with a character count rather than a list of symbol requirements. A long, plain passphrase beats an attacker’s guessing tools far more reliably than a short password dressed up with punctuation.

Common Mistakes That Weaken a Password

Even well-intentioned attempts to create a strong password can be undone by a handful of recurring habits, many of which are entirely invisible to the person doing them. These mistakes matter because even if you create a strong password once, a single reused or predictable password elsewhere can undo all of that effort.

Reusing the same password across multiple accounts is the most damaging of these habits. When one service is breached, attackers do not stop at that single account. They test the same email and password combination against banking sites, email providers and social media platforms, a technique known as credential stuffing. A password that felt strong on one site becomes a master key to several others the moment it is reused. Every account you hold, no matter how minor it seems, deserves its own unique password.

Building a password from personal information is the second common trap. Birthdays, pet names, football teams and children’s names are all things a determined attacker can find within minutes on an open social media profile, so the NCSC specifically advises against basing passwords on them.

Character substitution is the third trap: swapping a letter for a similar-looking number, such as writing “o” as a zero, feels like it adds complexity, but attackers are just as familiar with these tricks as password advice is, so the substitution barely slows a real attack while making the password harder for you to remember.

Finally, avoid any password that appears on lists of the most commonly used passwords, since these are the very first strings that automated cracking tools try. It is also worth remembering that even the strongest password cannot protect an account if the device typing it is already compromised by a keylogger or other malicious software, so keeping your devices clean matters just as much as the password itself.

The table below sets out how these habits compare in practice.

Password styleExample patternTime to crack (approximate)
Short, single dictionary wordfootballUnder one second
Complex but short, with substitutionF00tb@ll1!Minutes to hours
Three random unrelated wordspurpletoastercactusCenturies at current computing power
Password manager generated, random charactersxQ7#mK2$pL9vRCenturies at current computing power

Length and randomness, not the presence of a symbol, are what push a password from the top row of that table to the bottom.

Storing What You Create

Create a strong password, Storing What You Create

Creating a strong password only helps if you can also keep track of it without falling back on the very habits that weaken it, such as reusing the same password everywhere.

A password manager solves this by generating and storing a unique, complex password for every account, then filling it in automatically when needed. This is often the easiest way to create a strong password for dozens of accounts at once, without having to invent or remember each one yourself. Well-established options in the UK market include Bitwarden, 1Password, NordPass and Dashlane, each of which offers browser extensions and mobile apps to sync passwords across devices.

Many managers also flag reused or weak passwords already saved in your account, making it easier to see where you are exposed at a glance. The trade-off is a single master password, so that one entry point needs to be as strong as anything covered in this guide, ideally created using the three-random-words method.

If you are not ready to use a password manager, the NCSC’s own guidance takes a pragmatic view of writing passwords down on paper, provided the note is kept in a physically secure place, such as a locked drawer, rather than stuck to a monitor or left in an obvious place. This is a far safer option than a weak password chosen purely because it is memorable, and it is a particularly useful option for anyone who finds digital tools difficult to trust or use.

Saving passwords in a browser sits somewhere between the two: it is more secure than reusing a single memorable password across accounts, but it typically offers fewer safeguards than a dedicated password manager, so treat it as a step up from nothing rather than a long-term solution for your most important accounts.

Teaching Children and Older Relatives to Create a Strong Password

Password advice is often written for confident internet users, leaving two groups underserved: children setting up their first accounts and older relatives who may have used the same password for decades.

With children, the three random words method works well because it turns password creation into a small game rather than a chore. Ask them to picture three unconnected objects, perhaps something from their bedroom, a food they like and an animal, then combine the words into one string. This gives them a method they can reuse independently rather than a single password to memorise, and it avoids the common shortcut of using a birthday or a pet’s name, both of which are often visible on a child’s own social media profile.

This approach makes it simple for anyone, regardless of age, to create a strong password without needing to remember a complicated string of characters. It is worth explaining, in plain terms, why sharing passwords with friends is risky even when the intention is entirely innocent.

Older relatives often have the opposite problem: a handful of passwords used everywhere for years, each one meaningful and hard to give up. Rather than asking them to abandon a system that works for their memory, introduce the three-random-words method for new accounts first, and suggest writing passwords down in a notebook kept in a secure drawer if a password manager feels like an unnecessary extra step. Sitting with them to set up two-factor authentication on their email account, in particular, closes off the single biggest risk, since email access is usually the route to resetting every other password they hold.

What to Do If Your Password Has Been Exposed in a Breach

Even a carefully created password can still fall victim to a data breach that has nothing to do with how strong it was, since breaches expose whatever a company was storing at the time, not how well you chose your login details.

The first step is finding out whether this has actually happened. Have I Been Pwned, a free tool built by security researcher Troy Hunt, lets you check whether an email address has appeared in a known breach, and its companion Pwned Passwords tool checks a specific password against breach data without ever sending your actual password over the internet. If either check comes back positive, change the affected password immediately and any other passwords you have reused. Do this from a device you trust, not from the device where the breach might have occurred, since a compromised device could intercept the new password as you type it.

Next, check the affected account itself for anything unusual: login history, connected devices, forwarding rules on an email account, or transactions on a financial account. Enable two-factor authentication on the account if it is not already active, as this helps close the door even if the old password is still circulating. If the breach involved a UK company, you can also expect a notification explaining what data was exposed; if you believe the company has not handled the situation properly, the Information Commissioner’s Office is the right body to raise it with.

Finally, watch for a rise in phishing attempts referencing the breach, since attackers often follow up a leak with emails or texts pretending to be the affected company; our guide to spotting phishing and pharming attacks covers the warning signs in more detail.

Beyond Passwords: Two-Factor Authentication and Passkeys

A strong password is the foundation of account security, but it is no longer the whole story, and treating it as the only line of defence leaves an obvious gap. Even once you create a strong password using the three random words method, pairing it with a second layer of protection closes that gap.

Two-factor authentication adds a second check after the password, usually a code sent by text, generated by an authenticator app, or confirmed through a fingerprint or face scan. Even if a password is stolen or guessed, an attacker still cannot get in without that second factor, which is why the NCSC lists it among its most effective single pieces of advice for individuals. Turn it on for email first, since email access is usually the key to resetting other accounts, then extend it to banking and any account that holds payment details. Our guide to everyday online safety steps covers how to set this up across your main accounts.

Passkeys are a newer alternative that is starting to appear across major platforms, replacing the password entirely with a cryptographic key stored on your device and unlocked with your fingerprint, face or device PIN. Because there is no password to type, there is nothing for a phishing email to trick you into revealing, which removes an entire category of attack. Passkeys are not yet supported everywhere, so passwords built using the three-random-words method remain the practical standard for most accounts today, but it is worth switching to a passkey wherever a service offers one.

A Quick Checklist Before You Set Your Next Password

Before moving on to the specific questions people ask most often, it helps to have a short list to work through whenever you next need to create a strong password for a new account.

  • Combine three random, unrelated words rather than one word with substitutions
  • Aim for twelve characters or more, and longer where the site allows it
  • Check the password has not already appeared in a known breach using Pwned Passwords
  • Give the account its own unique password rather than reusing one from elsewhere
  • Store the result in a password manager or a written note kept somewhere secure
  • Turn on two-factor authentication as well, rather than relying on the password alone

Getting the basics right, a long password built from three random words, a unique password for every account, and two-factor authentication on anything important, covers the overwhelming majority of everyday account risk. Whenever you next need to create a strong password, working through the checklist above takes less than a minute and covers everything that matters.

For further guidance on broader signs that an account may already be compromised, see our guide on surviving a cyberattack, and for a broader checklist covering backups, device security, and data rights, see our digital security checklist. The NCSC’s three random words guidance is also worth reading in full for anyone setting up password policies for a family or a small organisation.

Frequently Asked Questions

These are the questions people most often ask once they understand the basics of how to create a strong password, covering the practical edge cases that a general guide does not always address.

What are five rules for a strong password?

Use at least twelve characters, ideally through three random unrelated words. Avoid personal information such as birthdays or pet names. Never reuse a password across more than one account. Skip predictable character substitutions like swapping a letter for a number. Store the result in a password manager or a securely kept written note rather than relying on memory alone. Following these five rules is the fastest way to create a strong password for any new account.

Is a twelve-character password strong enough?

Yes, provided it is not built from a single dictionary word or an easily guessed phrase. A twelve-character password made from three random words is considerably stronger than a twelve-character password based on a name and a date, even though both meet the same length requirement.

What is an example of a very strong password?

A password built from three genuinely random, unrelated words, such as “lanternbicyclepepper”, demonstrates the principle well. The actual words you choose should be personal to you but not guessable from information on your social media accounts.

Should I change my passwords every ninety days?

No. Current UK guidance has moved away from forced periodic changes, as they tend to push people towards weaker, more predictable passwords each time they update a password. Change a password when you have reason to believe it has been exposed, not on a fixed schedule.

Is it safe to save passwords in my browser?

It is better than reusing a weak password across every account, but a dedicated password manager generally offers stronger protection and more control, particularly for your most sensitive logins, such as email and banking.

What should I avoid when creating a password?

Avoid birthdays, pet names, sports teams and anything else visible on a social media profile. Avoid predictable substitutions such as replacing a letter with a similar-looking number. Avoid reusing a password across multiple accounts, and avoid any password that appears on lists of commonly used passwords, since these are the first ones an attacker will try.