Top tips for staying secure online
Top tips to ensure you are doing all you can to secure you and your family online
Page 5 of 7
Managing your passwords

Why you should use a password manager to ‘remember’ your passwords for you.
We're often told that the passwords for our online accounts should be really strong, and not to reuse them. Especially for important accounts like email, banking, shopping and social media.
This matters because if you use the same password across different accounts and one of your accounts is compromised, a hacker can try the same password on your other accounts and potentially gain access to them too.
The first – and most important – step is to turn on two-step verification (2SV) to help protect you if your password gets phished or otherwise compromised.
Using different passwords for your online accounts provides even more security. But with so many online accounts, creating different passwords for all of them and remembering them is difficult – impossible even. However there are tools that can help you, one of which is the password manager. These might be built into your browser already, or you can install one from a third-party.
What are the advantages of using a password manager?
A password manager stores passwords safely for you, meaning that you can have unique passwords for each service as you won’t need to remember them. As well as that, they often have other features to help your security such as:
automatic password generation
to quickly create a strong and unique password for each account – rather than using the same password across multiple accounts, which you should never do
autofill function
so that your password automatically appears when you go to log in and you don’t have to type it in every time. This also helps protect you from phishing attacks as the password will only autofill on the correct website.
synchronising your passwords across your different device
making it easier to log on wherever you are and whichever device you’re using
compromise warnings
that a password has been breached or leaked
Are they easy to use?
Most password managers are designed to be user-friendly. Tutorials and customer support are available to help new users get started, so even if you haven’t thought about using one before, you should try it.
Using the password manager on your device or browser
Your web browser or device operating system will likely offer to save your passwords for you unless you have told it not to. It's safe for you to do this on your own devices and it's the easiest way to remember your passwords, particularly if you use the same operating systems or browsers across your devices.
All the major browsers, such as Chrome, Edge and Safari offer the option to create and/or save your passwords.
Be careful about saving on shared devices
If you’re using a shared device outside your home, for example a desktop computer at a college, library or other public place, you should never save your password in the browser.
If you're sharing a device in your household, either with family or housemates, you’ll have to think about who else could access the computer, and decide if you’re OK with them potentially accessing your accounts. If you aren’t sure, the safest option is simply not to allow your browser to save passwords when it asks.
Remember that if you store your passwords in the browser, they are only as secure as your devices and accounts. So it’s important to make sure that you don’t switch off the security auto-update feature for your browser and operating system.
Using a third-party password manager
Sometimes people prefer to use a password manager not provided by their browser or device maker (known as a third-party password manager).
Third-party password managers are usually an app that you install on your phone or tablet, but are also available via a website on your browser. Whichever type you use, once you’ve logged into it using your primary password, it will store your passwords for all your online accounts in a safe place. One of the main benefits of a third-party password manager over the one in your browser is that it can synchronise passwords even when you have a mix of different browsers and devices.
Which one should I use?
There are lots of different password managers available. So it's worth doing some research and finding one that meets your requirements and personal preferences. Things to think about here include:
- whether you need it to work across different devices and operating systems
- if you would like to be able to specify the kind of passwords it generates for you (for example, length or character set)
- whether you are willing to pay for one, or would prefer to use a free version
- additional features you might want, such as helping you share a password more easily or notifying you if a password is found in a data breach
The best password manager to choose is the one that best meets your needs, and which you find easiest to use.
Remembering your primary password
It’s really important to remember your primary password, as it’s the key to accessing your password manager. But if you do forget it, many password managers offer recovery options, like secure password hints or emergency access through trusted contacts.
You should also switch on two-step verification (2SV) on the password manager account. This means that even if a cyber criminal knows the primary password, they still won’t be able to access your account.
Choosing to write passwords down
Some people prefer to write passwords down in a journal or dedicated password book. This can suit certain scenarios, for example where people need regular support, say from family members, to manage their online affairs. This can be done safely because an attacker would need physical access to where the passwords are stored. However, when writing passwords down there are some important considerations:
- Make sure passwords are not predictable or guessable. And use a strong and separate password for your email account.
- Make sure you are not breaking the terms and conditions of the service you are creating a password for, such as some online banking services, which forbid users to write down their passwords.
- Consider where you'll keep the written down passwords and who will have access. Anyone who has access will be able to remember them or make a copy, possibly without your knowledge. Simply hiding the passwords may not be sufficient if people have access to the room where they are kept.
- You'll be at greater risk of phishing attacks since you'll need to manually verify that a website is what it purports to be. Ensure you are sceptical of emails, text messages, or other communications that encourage you to log in to a specific link. For more information, see the NCSC’s guidance on how to spot scam emails, texts and websites.
What about passkeys?
Many websites and apps now let you sign in using a passkey – a safer and easier alternative to passwords. A passkey lets you sign in with a digital key that’s protected by your device’s existing unlock method, such as fingerprint, face check, or passcode. This means you don’t have to remember or type in anything new or complex.
The NCSC recommends making passkeys your first choice of login and using them wherever they are offered. For accounts that don’t yet offer passkeys, continue using a strong and unique password and two-step verification (2SV). This keeps your accounts protected today while making it easy to adopt passkeys as they become more widely available.
For more information about passkeys, see Passkeys: what you need to know.
Page reviewed and updated: 21 May 2026


