Passwords, Two-Factor Authentication and What to Do After a Data Breach

Account security advice has shifted noticeably over the past several years, and some of the older “password complexity” rules many of us grew up following are no longer what the UK’s National Cyber Security Centre (NCSC) actually recommends. Here’s what current guidance says, and what genuinely helps if your details end up in a data breach.

Why “three random words” replaced complexity rules

NCSC guidance explains that using three random words is more effective than traditional advice built around password complexity — the older approach of forcing symbols, numbers and mixed case into passwords, which tends to produce passwords that are both hard for people to remember and, counter-intuitively, still guessable by criminals using automated tools.

The reasoning behind three random words includes several practical points from NCSC guidance:

  • Passwords made from multiple words are generally longer than single-word passwords, and length is one of the strongest factors in password security.
  • The approach is simple enough to explain quickly, even to people who don’t consider themselves technically confident.
  • A three-word password is genuinely easier to type and recall correctly than a string of substituted characters and symbols.

The key is genuine randomness — three words picked deliberately at random, not a predictable phrase, and ideally not directly tied to easily discoverable personal information like a pet’s name or birth year.

Why two-factor authentication matters

NCSC guidance recommends turning on two-factor authentication (2FA) for all accounts where it’s available. 2FA requires two different methods to confirm your identity when logging in — typically a password plus a second factor, such as a one-time code sent by text or generated by an authenticator app. The practical benefit is significant: even if a criminal obtains your password (through a data breach, phishing, or guessing), 2FA usually stops them getting into the account without that second factor as well.

Priority accounts to protect with 2FA include your primary email account (since it’s often used to reset passwords on other services), online banking, and any account holding payment details or significant personal information.

Why your email password matters more than most

It’s worth treating your main email account’s password with particular care, since criminals who gain access to it can often use “forgot password” functions to cascade into your other online accounts — shopping sites, social media, even banking in some cases. A unique, strong password on your email account, combined with 2FA, is one of the highest-value single security steps most people can take.

What to do if you’re caught in a data breach

Data breaches at companies holding customer information happen regularly, and being notified that your details were involved doesn’t automatically mean you’ve been defrauded — but it does mean acting promptly reduces your risk. Sensible steps include:

  • Change the password on the affected account immediately, and on any other account where you’d reused the same or a similar password.
  • Check whether financial details were included in the breach, and if so, monitor the relevant account or card closely for unauthorised activity, contacting your bank if anything looks wrong.
  • Enable 2FA on the affected account and related accounts if it isn’t already active.
  • Be alert to follow-up phishing attempts — breached data is often used to craft more convincing, personalised phishing messages referencing real account details, so increased vigilance for a period afterward is sensible.
  • Report suspicious follow-up contact — texts, emails or calls claiming to be from the breached company or your bank — to the NCSC’s reporting channels or Action Fraud rather than responding directly.

A small number of habits, consistently applied

Account security doesn’t require constant vigilance across dozens of individual decisions — it largely comes down to a small number of consistent habits: unique passwords per important account (a password manager makes this realistic), 2FA switched on for anything sensitive, and a calm, methodical response if a breach notification does arrive, rather than either panic or inaction.

Password managers: a practical solution to the reuse problem

The single most common password mistake isn’t a weak individual password — it’s reusing the same or similar passwords across multiple accounts, so that a breach at one relatively low-stakes site (a forum, a loyalty scheme) can expose the password used on far more sensitive accounts elsewhere. NCSC guidance around securing accounts points toward password managers as a practical solution to this, since they let you maintain a genuinely unique, randomly generated password for every account without needing to memorise each one individually — you only need to remember the single master password protecting the manager itself.

For anyone hesitant about trusting a password manager, it’s worth weighing that risk against the alternative already in wide use: reused or slightly varied passwords across many accounts, written down insecurely, or simply forgotten and reset repeatedly. Reputable password managers use strong encryption specifically designed to protect stored credentials, and combined with 2FA on the manager account itself, they represent a meaningfully stronger security posture for most people than manually managing dozens of separate passwords.

Sources