The cyber threat landscape is rapidly evolving. It is becoming increasingly sophisticated, impacting individuals and businesses alike. To help you stay one step ahead of cybercriminals, we’re exploring a different aspect of cybersecurity each month in 2025 as part of our bitesize series.
As World Password Day was on Thursday 1 May 2025, this month’s focus is on how to create a strong password.
Weak passwords leave you exposed to security breaches. Hackers can attempt to get their hands on your passwords in a few ways, including brute force attacks, social engineering, data breaches or even a malevolent adversary.
Once they gain access, they can steal sensitive information and use it to perform malicious activities. As well as someone gaining unauthorised access, it can also lead to identity theft, reputational damage and financial repercussions.
If you use the same password across multiple accounts and the password gets compromised, hackers could try credential stuffing attacks. This is where a compromised password is used across multiple accounts in an attempt to gain access.
Unfortunately, no matter how strong your password is, there is always a chance that it can fall into the wrong hands, either by being hacked or from having your details leaked in a data breach.
Maintain your cybersecurity and keep your data safe with our top tips on how to create a strong password.
The latest statistics show that many people are still opting for common passwords rather than creating strong passwords. The latest NordPass study shows that the top five most common passwords in the world are[1]:
It’s remarkable how many variations of ‘qwerty’, ‘abcde’ and ‘password1’ are still in use today. Other examples of weak passwords include: iloveyou, dragon, monkey, football, princess, sunshine, shadow, michelle, matthew, welcome, trustno1, hello, chocolate, tigger, minecraft, facebook.
Instead, try to choose a password that is:
The National Cyber Security Centre (NCSC) recommends combining three completely unrelated words to create an unusual password that is both long enough and strong enough to evade a hacker.[2] An example of this could be branchpaincurtain.
Once you’ve selected a strong password, you should set up multi-factor authentication on all eligible accounts. This is sometimes called two-step verification, two-factor authentication or multi-factor authentication, but essentially, they all mean the same thing. Enabling this feature means that when someone attempts to log in to your account, they will trigger a second form of authentication after inputting your username and password. You will then be sent a code (or asked for an additional password or a fingerprint) to confirm that it is really you trying to access your accounts before they will grant access.
The majority of banks, social media sites and retailers now offer this as an added layer of security against hackers.
There has been some debate on how frequently you should change your password. Cybersecurity experts McAfee recommends that you change your password every three months, unless you suspect you have been hacked by a cybercriminal, in which case you should change it immediately.[3]
However, the National Cyber Security Centre (NCSC) suggests that frequent password changes may be counterproductive. The NCSC recognises that if you need to create a new password frequently, it is likely that you will get passwords muddled up easier, meaning users will opt to write them down.[4]
The NCSC also recommends that organisations help employees cope with password overload by no longer enforcing regular password expiry.[5]
Did you know the average person has 168 passwords to remember? More than half of these (87) are for business-related accounts.[6] Although we are told it is best practice to have a unique password for each account, it’s no surprise that people fall into bad practices such as having one password that you use across multiple accounts or writing passwords down.
That’s where a password manager can help. This allows you to store all your passwords securely, meaning you never need to click on the dreaded ‘Forgot your password’ button again. Password managers can be beneficial in multiple ways, not only can they remember your passwords, but they can help identify fake websites, and notify you if your password appears in a data breach.[7]
There are lots of options for password managers available such as Google Password Manager so it’s best to conduct some research to see what the best password manager for you is.
Bear in mind that if you opt for a password manager, there are pros but also cons. For example, if a cybercriminal manages to hack your password manager, they have access to all your accounts. Additionally, if you forget the password to your password manager, you will not be able to gain access.
Cyber threats are constantly evolving, and small businesses are often the most vulnerable. Towergate Insurance specialises in helping businesses like yours navigate these complex risks.
Contact us today to discuss how cyber insurance can help your small business: 0330 162 9107
Marc Rocker, Head of Cyber has been with Towergate for over 15 years advising commercial clients of all sizes on their business insurance needs.
As Head of Cyber Insurance, Marc has responsibility for ensuring that the advice and products that Towergate provides meet clients’ needs. Marc is a member of the British Insurance Brokers’ Association (BIBA) cyber technical committee.
[1] nordpass.com/most-common-passwords-list
[2] ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words
[3] How Often Should You Change Your Passwords? | McAfee
[4] ncsc.gov.uk/collection/passwords/updating-your-approach
[5] ncsc.gov.uk/collection/passwords/updating-your-approach
[6] How many passwords does the average person have? | NordPass
[7] Password managers: using browsers and apps to safely store... - NCSC.GOV.UK
Consistent with our policy when giving comments and advice on a non-specific basis, we cannot assume legal responsibility for the accuracy of any particular statement. In the case of specific problems, we recommend that professional advice be sought.
Date: May 15, 2025
Category: Small Business