Your Technology Partner

Websites • Software • Training • AI Solutions

Cyber safety made simple

Password Security

Protect your email, banking, social media and shopping accounts with long, unique passphrases, a password manager and multi-factor authentication.

Notebook representing secure password storage

Do you need to change passwords every three months?

Not routinely. Change a password or passphrase when it is weak, reused, exposed in a data breach, shared with someone else or you suspect the account has been accessed. Unnecessary scheduled changes can lead people to choose simpler, predictable passwords.

The essentials

Four steps that make the biggest difference

You do not need to be a computer expert. Start with your email, banking and social media accounts.

1

Use a long passphrase

Choose four or more unrelated words. Aim for at least 15 characters when the service allows it.

Example format: River-Lemon-Window-Train

2

Use a different one everywhere

If one website is breached, a unique password prevents criminals from using it to access your other accounts.

3

Turn on MFA

Multi-factor authentication adds another check, such as an authenticator app, security key, code or device prompt.

4

Use a password manager

A trusted password manager can create, store and fill strong unique passwords so you only need to remember one strong master passphrase.

Examples of commonly used passwords to avoid
Act quickly

When should you change a password immediately?

Change the password from a trusted device. Sign out of other sessions, check recovery details and recent activity, then turn on MFA. If it is your email account, secure it first because email can be used to reset other passwords.

Change the affected password. If you reused it anywhere else, change those accounts too. Watch for phishing messages that refer to the breach.

Immediately change the password, review active sessions and contact the provider if needed. Never approve a login prompt you did not initiate and never share an MFA code.

Disconnect the affected device from the internet and have it checked. Change important passwords using a different, trusted device after confirming it is safe.

Remove their account where possible. If everyone used the same login, change the password and review recovery email addresses, phone numbers and authorised devices.

Make it memorable

How to create a strong passphrase

  • Make it long: use at least 15 characters where possible.
  • Make it unique: never reuse it on another account.
  • Make it unpredictable: use unrelated words rather than a familiar saying.
  • Avoid personal details: do not use names, birthdays, pets, addresses or favourite teams.
  • Do not simply substitute characters: criminals already test obvious changes such as “P@ssw0rd”.
  • Store it safely: use a password manager rather than a notebook kept beside the computer.
Never publish or test your real password on an unfamiliar website. Use a made-up example when demonstrating password strength.
Video guide

Creating a stronger password

Use this video as an introduction, then follow the updated passphrase and MFA advice on this page.

Illustration of common password security threats
Know the risks

How passwords are commonly stolen

PhishingFake emails, text messages or login pages trick you into entering your details.
Credential stuffingCriminals try a password stolen from one website on many other services.
MalwareMalicious software can record typing, steal browser data or take control of a device.
GuessingNames, birthdays and common passwords are easy to predict.
Social engineeringA caller or message pressures you to reveal a password, code or approve a login.
Shoulder surfingSomeone watches you type or sees passwords left on paper near the device.
Tweed IT checklist

Secure your important accounts today

Work through the list one account at a time.

Australian password guidance

Read current advice about passphrases, password managers and protecting your accounts.

Visit cyber.gov.au

Think you can spot a scam?

Try the Australian Government's short scam awareness activity.

Take the scam quiz
Need a hand?

Concerned that an account or computer has been compromised?

Stop using the affected device for banking or passwords. Disconnect it from the internet and contact Tweed IT for practical, plain-English assistance.

Contact Tweed IT

Have you been a victim of a cyber scam? Click on one of the below Australian Government links, our information page or contact us directly for advice.

Victim of a scam?
Helpful links below.