Adopt a password manager with a tested recovery plan and unique passwords for important accounts.
A password manager helps create and store a unique credential for each account so one breach does not unlock everything else. The security benefit depends on setup, device protection, recovery, and whether you actually replace reused passwords.
Understand what the manager changes
Instead of memorizing many passwords, you protect the manager with one strong master credential and the security of your devices and account. The manager can generate random passwords, fill the correct site, warn about reuse, and sometimes store passkeys or secure notes. It does not make phishing, malware, or account recovery irrelevant.
Choose using operational questions
| Area | Questions |
|---|---|
| Devices | Does it support every browser and device you actually use? |
| Security | What protects stored vault data, sign-in, devices, and recovery? |
| Recovery | What happens if you forget the master credential or lose every device? |
| Sharing | Can families or teams share selected items without sharing the vault login? |
| Portability | Can you export and delete your data in a usable, protected format? |
| Support | Are documentation, security notices, and support channels clear? |
Create a strong master credential
Use a long, unique credential that has never protected another account. Follow the manager's current guidance and favor length over hard-to-type substitutions. Do not store the only copy in an unlocked note, email draft, or photo. Never give it to support or enter it after following an unexpected link.
Secure the manager account and devices
Enable the strongest practical multifactor method, keep recovery codes offline, update devices and extensions, use screen locks, and remove old sessions. Browser autofill should match the expected domain; stop when it does not. The MFA guide compares common methods and recovery.
Plan recovery before migration
- Record the official recovery process
- Store recovery codes in a protected offline place
- Identify a trusted emergency-access option if appropriate
- Test access on a second authorized device
- Document how family or business continuity works
- Know whether the provider can recover an encrypted vault
Migrate the highest-risk accounts first
Start with primary email, financial services, cloud storage, domain registrar, mobile carrier, work administrator, and the password manager itself. Replace reused passwords with generated unique values, confirm sign-in, update recovery details, enable MFA, and save backup codes before moving on.
Handle imports and exports carefully
Imported CSV files may contain every password in readable text. Perform the import on a trusted device, confirm the records arrived, then securely remove the export according to the device and storage system. Treat future exports as sensitive backups; do not leave them in Downloads or ordinary cloud folders.
Use sharing features instead of shared passwords
When several people need an account, prefer individual accounts and role-based access. If a credential truly must be shared, use the manager's controlled sharing, restrict recipients, rotate it when membership changes, and keep an owner. Do not send passwords through chat or spreadsheets.
Respond to a warning or breach
Verify notices through the official app or site. Change the affected credential, revoke sessions, review recovery and MFA settings, and replace any reused values. If the manager account itself may be compromised, follow its incident guidance from a trusted device and prioritize email and financial accounts. Use the phishing inspection steps before acting on a security alert.
CISA's public guidance recommends long, random, unique passwords and a password manager. The goal is not a perfect vault on day one; it is steadily eliminating password reuse while preserving recovery.
Sources and further reading
Primary and contextual sources used to verify definitions or give readers a relevant next resource.
- CISA Secure Our World Official guidance recommending long, random, unique passwords and use of a password manager.