# How to create secure passwords

Weak passwords are one of the biggest security risks to your nonprofit.

Why?

Because cyber criminals are getting smarter than ever before. If they manage to crack just one password, they could gain access to your sensitive data, financial information, or even gain control of your entire system.

Cyber criminals use automated tools to guess passwords. These tools allow them to try out millions of combinations in seconds. So, if you’re using something like “Password123” or “OrgName2025”, you’re practically handing them the keys to your nonprofit.

A compromised password can lead to big issues, such as:

- Data breaches
- Financial losses
- Identity theft
- Reputation damage

But how do you create strong passwords without driving yourself (and your team) mad? Think of your password like a secret recipe, where only you should know the ingredients. It should:

- Be at least 14 characters long (the longer, the better)
- Include a mix of uppercase and lowercase letters
- Contain a few numbers and symbols (like @, $, %, or &)

Instead of using a single word, you could try a passphrase. Passphrases are sequences of 4–7 random words. For example, instead of “Sailing2025”, try something like “Astronaut4-Jester-Zero-Hangout-Italicize”. This is much harder to crack, yet still easy to remember.

You should also steer clear of these common mistakes:

- Using personal info (your name, birthday, organization name, etc.)
- Reusing the same passwords across multiple accounts
- Using simple sequences (“123456” or “abcdef”)
- Storing passwords in an easily accessible place (like a sticky note on your desk)

If creating and remembering unique passwords for every account sounds impossible, Password managers are your new best friend. They generate strong passwords, store them securely, and autofill your login information for you.

With a password manager, you only need to remember one strong master password to access the app itself. The remaining passwords are encrypted and stored safely to reduce the risk of data breaches. Even better, many password managers allow you login using your Microsoft 365 account. And if your organization has set up passwordless sign-in, you won’t have to remember any passwords!

Even the strongest password isn’t foolproof. This is why multi-factor authentication (MFA) is also important. MFA requires a second form of verification, like a one-time code sent to your phone or generated from an authentication app.

If your staff accesses organization-wide systems, it’s a good idea to have a password policy in place to explain your rules and why they’re important. This should include:

- Unique passwords for each system and account
- Regular security training on password best practices
- Organization-wide use of MFA
- Scanning for compromised passwords regularly

By making password security a priority, you can reduce the chances of a cyber attack creating a nightmare for your organization.

And if you need help making your nonprofit more secure, [get in touch](/content/contact#schedule-a-meeting/index.html).
