Passwords, password managers and security keys: a plain guide
Give your email a long password you use nowhere else, and turn on two-step login for your email and your bank. Never give anyone a code sent to your phone. A password manager or a security key can help, but they come second.
Last checked against the sources listed at the end of this page.
We sell nothing, and no company paid to be on this page. The few products named link to their makers’ own websites. None of those links earns us money.
•Too many passwords to remember? A password manager (opens in a new tab) keeps them for you behind one strong main password. Passkeys and security keys go one step further.
Free help first
The NCSC’s free booklet
The Government’s National Cyber Security Centre (NCSC) publishes “How to keep your online accounts secure” (opens in a new tab), a short booklet in plain English with a list of the words you need to know. Most of this page’s advice on passwords and two-step login comes from it.
Or use a passphrase: a password made of random words, which is easier to remember. The NCSC says a strong passphrase has at least 3 words, and 4 or more is better (opens in a new tab), with a mix of characters too. Pick words that are easy for you to remember but hard for others to guess: not your hobbies, for example.
A password should be a secret that only you know (opens in a new tab). The NCSC adds that a real customer service or helpdesk worker will never ask for your password, passphrase or PIN: only a scammer will.
What is two-step login, and where should I turn it on?
Two-step login means that after your password, you also need a code sent to your phone, app or email (opens in a new tab), or your fingerprint. The NCSC compares it to having two locks on your door instead of one. You may see it called two-factor authentication (2FA), multi-factor authentication (MFA) or two-step verification. They all mean much the same thing.
You may have one already, free. Your phone or web browser will likely offer to save your passwords. The UK’s NCSC says that is safe on your own devices (opens in a new tab), but never on a shared computer in a library or other public place.
These are examples, not the only good choices. We name them from what their makers publish. We have not tested them ourselves, and no link here earns us anything.
In February 2026, researchers at ETH Zurich published attacks on three password managers, Bitwarden, LastPass and Dashlane (opens in a new tab). The attacks work if the company’s own server has been broken into; the researchers tested them on servers of their own, built to behave like hacked ones. Their advice: choose a password manager that is open about security problems, is checked by outside auditors and, at the very least, has end-to-end encryption switched on as standard.
These are examples, not the only good choices. We name them from what their makers publish. We have not tested them ourselves, and no link here earns us anything.
If there are too many to remember, that is the job a password manager does: it remembers them for you, behind one main password. And never write a password or PIN on any of our printable sheets.
The one in your phone or browser, or an app. Protect it with one strong main password you remember, and two-step login.
6
When a site offers you a passkey, you can say yes
You then sign in with your fingerprint, face or phone PIN instead of a password.
7
Never give anyone a code, and only approve a sign-in you started
Not a caller, not a text, not a friend on WhatsApp. Whoever they say they are.
Your accounts: a checklist
Tick each line as you do it. Never write a password, passphrase or PIN on this sheet.
My email
1
A long password I use for nothing else
Three or more random words, 12 characters or more.
2
Two-step login turned on
3
Its backup email address is one I still use
My bank and other important accounts
4
Two-step login turned on for online banking
5
Each important account has its own password
6
A passkey set up where a site offers one
Only if you would like to.
Every day
7
I never give anyone a code sent to my phone
8
I never tell anyone my password or PIN
A real helpdesk never asks for them.
9
I only approve a sign-in I started myself
If I use a password manager or a security key
10
Its main password is strong, and I remember it
11
Two-step login is on for the password manager itself
12
A spare security key is set up on my accounts, kept somewhere safe
Notes
From safeandsecure.ie/topics/cyber/passwords-and-security-keys. Last checked 7 October 2026. Sources: National Cyber Security Centre (ncsc.gov.ie): online account security booklet, Multi Factor Authentication guide, Phishing quick guide, WhatsApp code advisory; An Garda Síochána (garda.ie); FIDO Alliance (fidoalliance.org); Yubico (yubico.com).
Print this
The checklist prints on one page, in black on white, with a box to tick beside each line. The whole guide prints without the menus, and with the address of every source.
One thing to do this week
This week, turn on two-step login on your email account.
Open your email’s settings or security section and look for “two-step”, “two-factor” or “2FA”. The NCSC says to use it wherever you can, especially for your primary email (opens in a new tab). If a code ever arrives that you did not ask for, do nothing with it, and never read it out to anyone.
Sources
Every fact on this page comes from one of these, and each was read on 7 October 2026.
National Cyber Security Centre (NCSC), Ireland. The plain-English booklet: a strong password (12 characters or more, 14 better, a mix of characters) or passphrase (3 words or more, 4 better); what never to use; a different password for each important account; never share it; password managers and two-step login for them; two-step login (2FA or MFA) and never sharing its code; passkeys; where to find these settings.
National Cyber Security Centre (NCSC), Ireland. Passwords as often the only barrier to your personal information; reuse as a major problem; stolen logins tried on other services such as web access to email, and a unique password as the key to stopping it; MFA on all email and social media accounts; a password manager behind one master password.
National Cyber Security Centre (NCSC), Ireland. What two-step login is; use it wherever possible, especially for your primary email and financial accounts; it is often listed as “Two Factor Authentication” in an account’s security settings; text-message codes as the weakest kind and FIDO (security keys and passkeys) as the strongest; still far better than a password alone.
National Cyber Security Centre (NCSC), Ireland. You should only get a password-reset or sign-in request if you asked for one; if you gave a password away, change your passwords and contact your bank.
National Cyber Security Centre (NCSC), Ireland. A scammer posing as a friend asks for the code WhatsApp sent you; treat the code like a password and never share it; turn on WhatsApp’s own two-step verification.
National Cyber Security Centre (NCSC), United Kingdom. The password manager built into your browser or phone, safe on your own devices; care on shared devices; recovery options for the main password.
An Garda Síochána. Report a hacked account to your local Garda station and keep a copy of the suspicious activity; use two-factor authentication; the backup email account as a way back in.
FIDO Alliance, the body that writes the passkey standards. What a passkey is and where it is kept; signing in the way you unlock your phone; fingerprint and face data stay on the device; passkeys are phishing resistant; why some people find a security key simpler.
Bitwarden, the maker. What the free plan includes: unlimited passwords on unlimited devices, apps for phone, browser and computer, passkeys, a password generator.
Proton, the maker. What the free plan includes: unlimited logins on unlimited devices, apps for phone, browser and computer, passkeys on all devices, alerts for weak and reused passwords.
ETH Zurich. Researchers’ attacks on Bitwarden, LastPass and Dashlane, tested against servers of their own built to behave like hacked ones; their advice on choosing a password manager.
Age Action. A free programme with a volunteer tutor, two hours a week for five weeks, to get online or use a smart device with confidence; phone 0818 911 109.