
You wouldn’t hand out your house keys to strangers or leave them under the doormat. The same mindset should apply to your digital life. Passwords are still the first line of defense against cybercriminals and data breaches. Yet creating, storing, and remembering dozens (or even hundreds) of them can feel overwhelming. The good news is that with a few simple habits—and a password manager—you can take control of your security without the stress.
The Power of Long, Unique, and Complex Passwords
When it comes to passwords, three principles matter most:
1. Long
Longer is stronger. Today, an eight-character password can be cracked in minutes by brute force software that tries every possible combination. A 16-character password, by contrast, could take a billion years to guess. That’s why we recommend passwords of at least 16 characters.
2. Unique
Each account should have its own password. Reusing passwords is common—we’ve all been guilty of it—but it’s risky. If one account is breached, attackers well try to use that same password to access your other accounts. Small tweaks, like adding a number or symbol, aren’t enough. Each password should be completely unique. A password manager makes this easy by generating and storing unique credentials for you.
3. Complex
Passwords should include a mix of uppercase and lowercase letters, numbers, and special characters. Some platforms even allow spaces. The strongest passwords are long strings of random characters, not words, names, or dates. Even if your password looks random, length still matters—make sure it’s at least 16 characters.
Consider using passphrases. Passphrases are short sentences or combinations of words that are easily remembered and easily typed. Even short phrases are often much longer than 16 characters. So, even without complex characters, they will be much stronger than short passwords with complexity.
MFA: Going Beyond the Password
Even strong passwords can be stolen or exposed in a data breach. That’s where multi-factor authentication (MFA) comes in. MFA requires something more than just your password, such as a code sent to your phone, an authenticator app, a hardware token, or a fingerprint scan. This second layer means that even if your password is compromised, an attacker can’t get in without that additional factor.
Turn on MFA for every account that supports it, especially for email, financial services, and social media. It’s one of the simplest ways to boost your security.
How Often Should You Change Passwords?
For years, the standard advice was to change your passwords regularly—annually, or even more frequently. That’s no longer best practice. The National Institute of Standards and Technology (NIST) now recommends changing your password only if you suspect unauthorized access or if the account is involved in a breach.
Why? Because frequent forced changes lead to bad habits—like recycling old passwords or creating simple ones you can easily remember. Instead, focus on creating long, strong, unique passwords and updating them only when necessary.
Why Password Managers Are a Game-Changer
The advice above probably sounds daunting if you’re managing passwords on your own. The reality is that most of us have far too many accounts to keep track of—over 160 on average. A password manager solves this problem.
With a password manager, you only need to remember one master password. The manager securely stores the rest in an encrypted vault. Better yet, it can automatically generate strong, random passwords for every account and autofill them when you log in.
Here’s why a password manager is worth adopting:
Convenience: No more memorizing dozens of passwords.
Security: Automatically generates long, unique, complex passwords.
Time-Saving: Autofill features make logging in quick and secure.
Encrypted Vaults: High-quality managers use strong encryption and “zero-knowledge” architecture, meaning even the provider can’t see your passwords.
Password managers are much safer than notebooks, sticky notes, spreadsheets, or trying to remember passwords yourself. They also reduce your risk if one account is breached—because every other password is unique.
Taking the First Step
Passwords may never feel fun, but they don’t need to be overwhelming. Start by choosing a password manager, securing your most important accounts (email, banking, social media), and enabling MFA wherever possible. From there, you’ll find that keeping your digital life secure becomes much easier.
By using long, unique, and complex passwords—and leaning on tools designed to help—you’re taking one of the most effective steps available to protect your identity and data. Small actions like this add up to a big impact in cybersecurity.
Want to learn more? Check out this article at staysafeonline.org.
Remember…
Phishing Simulation: We’ll conduct two phishing simulations in the last weeks of October and the first weeks of November. If you see unusual or suspicious emails, report them as you would any other spam or phishing messages. Your vigilance keeps our community safer.
Get your cybersecurity training done. We aim for all faculty, staff, and first-year students to complete Cybersecurity 101 by the end of the month. It doesn’t take long. Employees who complete the training by the end of October will be entered into a drawing for two Bon Appétit lunch vouchers. Access the training here.
Cybersecurity Town Hall: CyberPop Daemon Hunters

Join Kendall George, information security officer for Carleton and St. Olaf Colleges, at our annual cybersecurity town hall. This engaging, interactive session will describe the current state of cyberthreats in higher education and the steps you can take to keep both campus and your own digital life secure. There will be ample time for questions and answers. A Carleton or St. Olaf login is required to join.
📅 Thursday, October 9 at noon
Join via Zoom
Stay safe out there.
Kendall George
Information Security Officer
Carleton and St. Olaf Colleges