Saturday, September 5 Lagos newsroom Newsroom online
Edition: Africa
Cybersecurity

How to Create Strong Passwords and Protect Your Online Accounts

Use a long unique password or passphrase for each account, store it in a password manager and add multifactor authentication or a passkey where available.

A phone user reviewing secure login and account protection settings
AI-generated realistic editorial image illustrating stronger account protection. It is not a documentary photograph.
Tech Embed AI-assisted realistic editorial image

Use a long unique password or passphrase for each account, store it in a password manager and add multifactor authentication or a passkey where available.

One password, protected by a capital letter and an exclamation mark, guarded her email, her banking app, and four shopping sites. When one small shopping site got breached, the attacker didn’t need to guess anything else — he just tried the same password everywhere, and three more accounts opened on the first try.

A strong password isn’t just hard to guess. It has to be unique. A complicated password reused across six sites exposes all six the moment one of them is breached — exactly what happened above.

Current security guidance actually emphasizes length, password managers, and multifactor authentication far more than forcing people into short passwords with predictable symbol swaps like “@” for “a.”

Length Beats Cleverness

NIST’s public guidance recommends at least 15 characters when creating a password. Skip names, phone numbers, birthdays, keyboard patterns, and common phrases. And never build a “system” where only the last digit changes between sites — once an attacker spots the pattern, every other account becomes easy to guess.

Let a Password Manager Do the Remembering

A password manager generates and stores a different credential for every single account. You remember one strong master password and protect the manager itself with additional authentication. Choose a reputable service, keep its recovery information current, and store any emergency recovery code securely — never in an unprotected note or spreadsheet that syncs everywhere automatically.

Turn On Multifactor Authentication Everywhere It’s Offered

An authenticator app, hardware security key, or passkey generally beats a text message — though any additional factor beats a password alone when it’s set up correctly. Save recovery codes somewhere safe and offline; otherwise a lost phone turns a security feature into an account-recovery nightmare.

Use Passkeys Where They’re Available

A passkey uses cryptographic credentials tied to your device or account instead of a reusable password — it cuts phishing risk because the credential is built for the correct service only. Understand how it syncs, and how you’ll recover it after switching devices.

Protect the Accounts That Can Reset Everything Else

Start with email, your password manager, your mobile account, and major financial services — these can often reset or recover other accounts. Give them unique credentials, extra authentication, and current recovery information first.

A Practical Order to Fix Everything

  1. Change any password you know has been exposed or shared
  2. Secure the main email account and password manager first
  3. Change banking and payment account passwords
  4. Change social media and messaging accounts
  5. Replace reused passwords on shopping and entertainment accounts
  6. Delete accounts you genuinely no longer need

Got a breach alert? Open the service directly, not through the link in the alert. Change the password, check recent sessions, sign out unfamiliar devices, and verify recovery information. If that password was reused anywhere else, change it there immediately too — that’s exactly the gap that turned one small breach into four compromised accounts.

What it means for Nigeria and Africa

Nigeria

Account security matters because email, banking, social media and phone-number recovery are often connected. One reused password can expose several services at once.

Across Africa

The advice works across countries, but people should choose authentication methods they can recover safely when devices, SIM cards or connectivity change.

What Tech Embed adds

A practical account hierarchy that protects email and recovery channels first, then replaces reused passwords in a manageable order.

Disclosure

This evergreen guide was prepared from the official sources listed below. The featured image is an AI-assisted editorial illustration in a realistic photographic style; it does not document a real person, event, product test or location.

Primary sources checked

Tech Embed Editorial

Tech Embed Editorial

Tech Embed Editorial Team

Tech Embed is written and verified by a newsroom process, not a single byline. Every article passes through research and verification, Nigerian and African context review, and editorial sign-off before publication. See our Editorial Team page for how this works.

Share a useful experience

Be specific. Do not post account numbers, phone numbers, passwords, OTPs or other private information.