The NCSC analysed passwords found in accounts that had already been breached and published the most common one. It was 123456, and it appeared over 23 million times.
That isn't really a story about weak passwords. It's a story about reuse. One password used everywhere means a single leak, from a company you'd half forgotten you had an account with, hands someone your email. From your email they can reset almost everything else.
Most people know this. Very few have fixed it, because fixing it sounds like a lost weekend. It takes one session.
What you get
The Decision Matrix. Under five minutes to see which accounts need a password manager and which need two-factor authentication, ordered by actual risk rather than by what's easiest.
Seven Clarity Scripts. Word for word what to do when setting up a manager, enabling 2FA, handling a recovery code, resetting a compromised login, or dealing with a lockout.
The 60-Minute Plan. Manager chosen and installed, critical passwords migrated, 2FA live on your top accounts, recovery codes stored somewhere sensible. Start to finish in one sitting.
Six self-tests. Clear pass conditions for every critical login, including the one nearly everybody skips: checking your recovery codes actually work before the day you need them.
The bit most guides skip
A password manager and two-factor authentication solve different problems, and knowing which does what is half the battle.
-
A password manager generates and remembers a unique password for every account, so a leak at one company stays at that company. One master password opens the vault.
-
Two-factor authentication adds a second check on top. Someone with your password still can't get in without it.
-
Recovery codes are your way back in when the second factor isn't available. The guide covers where to keep them so they're safe but reachable.
-
Authenticator apps and SMS are not equivalent. The guide explains which to use and why, without the jargon.
This is for you if
- You use the same password, or small variations of it, across several accounts
- You don't have a password manager, or you have one and barely use it
- You couldn't say which of your accounts have 2FA switched on
- You've saved passwords in your browser and aren't sure whether that's fine
- You wouldn't know what to do if you were locked out of a critical account tomorrow
By the last page
Every major account has its own strong password held in a manager, and your highest-risk accounts sit behind a second factor that a stolen password alone can't get past. That's the login system most people intend to build and never do.
Course details
- Format: downloadable PDF
- Time to complete: about 60 minutes
- Series: Course 02 of 20, GhostNet Cyber Fundamentals
- Track: Track A, Privacy Foundations (Courses 01 to 05)
- Prerequisites: none, works standalone and pairs naturally with Course 01
- Works on: any device, any operating system
- Level: complete beginner, no technical background needed
Buy with confidence
Every course comes with a 30-day money-back guarantee. If it isn't useful, email us within 30 days and we'll refund you in full. You don't need to give a reason.
Where to go next
Course 03, Locking Down Your Devices, secures the hardware your newly protected logins live on. Or take Privacy Foundations, the five-course bundle covering Courses 01 to 05, for £50 instead of £150.