Skip to content
Digital Life Check

How to create a strong password you can remember

A strong password is long, unique and easy for you to remember. The NCSC's "three random words" method does all three.

Written by
Digital Life Check editorial team
Last checked
On this page
  1. Use three random words
  2. Length beats complexity
  3. Use a different password for every important account
  4. Let a password manager remember them
  5. Even better: passkeys
  6. Check a password now
  7. If you think a password has been stolen

Quick answer: make it long rather than complicated — three random words joined together work well. Use a different password for every important account, starting with your email. Let a password manager remember them for you. And where a site offers a passkey, use that instead.

Use three random words

The National Cyber Security Centre (NCSC) recommends combining three random words into one password. Its own example is applenemobiro.

Why it works:

  • It's long. The longer and more unusual a password, the harder it is to crack.
  • It's memorable. The NCSC says three random words are much easier to remember than a complex mix of characters.
  • It's strong enough. The NCSC says three random words are "long enough and strong enough" for most purposes.

Tips for picking your words:

  1. Choose words that are random — not a phrase, a song lyric or something about you.
  2. Avoid anything someone could find on your social media: birthdays, family or pet names, your football team.
  3. Picture a strange scene to help you remember it.

Length beats complexity

You've probably been told to add capitals, numbers and symbols. The NCSC says this long-standing advice "is not helpful", because nobody can remember lots of complex passwords.

Swapping letters for look-alike characters (a zero for an "o", say) doesn't add much either. The NCSC points out that criminals know these tricks, so your password won't be much stronger — just harder for you to remember.

If a website insists on a number or symbol, add one to your three words. That's fine.

Use a different password for every important account

If you reuse a password and one site is breached, criminals try it on your other accounts.

Your email password is the most important of all. The NCSC explains that anyone who gets into your email can reset the passwords to your other accounts, read your private information and send messages pretending to be you. Give your email a strong password that you use nowhere else.

After email, give unique passwords to your banking, shopping, payment and social media accounts.

Let a password manager remember them

Nobody can remember dozens of unique passwords. A password manager does it for you. The NCSC encourages using one, and says they can:

  • create a strong, unique password for each account
  • fill it in automatically — only on the real website, which also helps protect you from fake login pages
  • sync your passwords across your devices
  • warn you if a password has turned up in a breach

You probably already have one. The NCSC notes that Chrome, Edge and Safari all offer to save passwords, and says saving passwords this way is safe on your own devices. Its passkeys guidance names Apple Passwords, Google Password Manager and Samsung Pass as the ones built into devices. On a shared or public computer, don't save your password in the browser.

Writing passwords down is OK too, the NCSC says, as long as you keep it somewhere safe.

Even better: passkeys

A passkey lets you sign in with your face, fingerprint or phone PIN instead of a password. The NCSC now recommends passkeys over passwords wherever a service offers them. It says they are resistant to phishing and at least as secure as the strongest password combined with two-step verification.

Look for "passkey" in an account's security settings, or accept the offer when a site prompts you. Where passkeys aren't available, the NCSC's advice is to keep using a strong password — ideally generated by a password manager — together with two-factor authentication.

Check a password now

Want to know how strong a password is? Our Password Check runs entirely on your device, so the password you type isn't sent anywhere.

If you think a password has been stolen

  1. Change it straight away, on the real website or app.
  2. Change it on any other account where you used the same one.
  3. Turn on two-step verification.
  4. If you clicked a link and typed it into a page, follow what to do if you clicked a scam link.

Sources

Last checked: 22 September 2026

  • Passwords

    Are password managers safe?

    A password manager is much safer than reusing the same few passwords. Here's how they keep your passwords protected, where the real risks are, and how to choose one.

    Last checked 22 September 2026

  • Passwords

    What is two-factor authentication (2FA)?

    Two-factor authentication adds a second check when you log in, so a stolen password isn't enough. Start with your email account.

    Last checked 22 September 2026