How to create a strong password you can remember
A strong password is long, unique and easy for you to remember. The NCSC's "three random words" method does all three.
- Written by
- Digital Life Check editorial team
- Reviewed by
- Not yet independently reviewed
- Last checked
On this page
Quick answer: make it long rather than complicated — three random words joined together work well. Use a different password for every important account, starting with your email. Let a password manager remember them for you. And where a site offers a passkey, use that instead.
Use three random words
The National Cyber Security Centre (NCSC) recommends combining three random words into one password. Its own example is applenemobiro.
Why it works:
- It's long. The longer and more unusual a password, the harder it is to crack.
- It's memorable. The NCSC says three random words are much easier to remember than a complex mix of characters.
- It's strong enough. The NCSC says three random words are "long enough and strong enough" for most purposes.
Tips for picking your words:
- Choose words that are random — not a phrase, a song lyric or something about you.
- Avoid anything someone could find on your social media: birthdays, family or pet names, your football team.
- Picture a strange scene to help you remember it.
Length beats complexity
You've probably been told to add capitals, numbers and symbols. The NCSC says this long-standing advice "is not helpful", because nobody can remember lots of complex passwords.
Swapping letters for look-alike characters (a zero for an "o", say) doesn't add much either. The NCSC points out that criminals know these tricks, so your password won't be much stronger — just harder for you to remember.
If a website insists on a number or symbol, add one to your three words. That's fine.
Use a different password for every important account
If you reuse a password and one site is breached, criminals try it on your other accounts.
Your email password is the most important of all. The NCSC explains that anyone who gets into your email can reset the passwords to your other accounts, read your private information and send messages pretending to be you. Give your email a strong password that you use nowhere else.
After email, give unique passwords to your banking, shopping, payment and social media accounts.
Let a password manager remember them
Nobody can remember dozens of unique passwords. A password manager does it for you. The NCSC encourages using one, and says they can:
- create a strong, unique password for each account
- fill it in automatically — only on the real website, which also helps protect you from fake login pages
- sync your passwords across your devices
- warn you if a password has turned up in a breach
You probably already have one. The NCSC notes that Chrome, Edge and Safari all offer to save passwords, and says saving passwords this way is safe on your own devices. Its passkeys guidance names Apple Passwords, Google Password Manager and Samsung Pass as the ones built into devices. On a shared or public computer, don't save your password in the browser.
Writing passwords down is OK too, the NCSC says, as long as you keep it somewhere safe.
Even better: passkeys
A passkey lets you sign in with your face, fingerprint or phone PIN instead of a password. The NCSC now recommends passkeys over passwords wherever a service offers them. It says they are resistant to phishing and at least as secure as the strongest password combined with two-step verification.
Look for "passkey" in an account's security settings, or accept the offer when a site prompts you. Where passkeys aren't available, the NCSC's advice is to keep using a strong password — ideally generated by a password manager — together with two-factor authentication.
Check a password now
Want to know how strong a password is? Our Password Check runs entirely on your device, so the password you type isn't sent anywhere.
If you think a password has been stolen
- Change it straight away, on the real website or app.
- Change it on any other account where you used the same one.
- Turn on two-step verification.
- If you clicked a link and typed it into a page, follow what to do if you clicked a scam link.
Sources
- Three random words — National Cyber Security Centre (opens in a new tab)
- Use a strong and separate password for your email — National Cyber Security Centre (opens in a new tab)
- Managing your passwords — National Cyber Security Centre (opens in a new tab)
- Passkeys: what you need to know — National Cyber Security Centre (opens in a new tab)
- NCSC: Leave passwords in the past - passkeys are the future — National Cyber Security Centre (opens in a new tab)
- Recovering a hacked account — National Cyber Security Centre (opens in a new tab)
Last checked: 22 September 2026