Use this guide if you reuse passwords, keep them in a notebook or phone notes, or have had an account breached. Have your phone, your main email login and about an hour to work through your most important accounts.
Step by step
Choose a password manager
Pick either the password manager built into your phone or browser, or a well-established dedicated password manager that works on all your devices. Check it can sync between your phone and computer and supports 2-step verification for its own login. Avoid little-known apps with few reviews or unclear ownership.
Create a strong main password
Make one long master password from three or more random words, for example unrelated words joined together, that you have never used anywhere else. Write it down once and keep it somewhere safe at home until you have memorised it. This is the only password you will need to remember.
Secure your main email first
Change your main email password to a new unique one saved in the manager, because email is used to reset every other account. Turn on 2-step verification in the account security settings, preferably using an authenticator app or passkey rather than text messages. Save the backup codes offered in the password manager or print them and store them safely.
Work through your key accounts
Next do banking, shopping sites with saved cards, social media, mobile network and any government or work accounts. For each one, let the manager generate a new random password, save it, and switch on 2-step verification where offered. Do the rest gradually as you log in to them over the following weeks.
Check for reused or leaked passwords
Most password managers have a security or health check that flags weak, reused or breached passwords. Work through the list, starting with anything marked as exposed in a breach. Delete accounts you no longer use rather than just changing their passwords.
Plan for losing your phone
Make sure you can still get in if your phone is lost: store backup codes, add a second 2-step method such as a backup phone number or security key, and note how to recover the password manager itself. Consider setting up the manager's emergency access or legacy feature for a trusted family member.
Ready-to-use checklist
- Password manager installed on phone and computer
- Long unique master password created
- Main email password changed and 2-step verification on
- Backup codes saved somewhere safe
- Banking and shopping accounts updated
- Reused and breached passwords fixed
- Old unused accounts closed
- Recovery plan for a lost phone in place
Practical tips
- Authenticator apps and passkeys are harder for criminals to intercept than text message codes, so use them where you can.
- Never give a 2-step verification code to anyone who calls or messages you, even if they claim to be your bank.
- Let the manager fill in passwords for you, because it will refuse to fill them on a fake look-alike website.
Common problems
I have forgotten my password manager master password.
Use the recovery option you set up, such as a recovery key or your device account, if one exists. Some managers cannot recover a lost master password by design, so you may need to reset it and rebuild your vault. This is why writing the master password down safely at the start matters.
A site will not accept the generated password.
Adjust the generator settings to match the site's rules, for example removing symbols or shortening the length. Save the new password in the manager before submitting the change. If the site still fails, check the password was saved and try the reset link.
I got a new phone and my authenticator codes have gone.
Log in using the backup codes you saved or another 2-step method on the account. Then set up the authenticator again on the new phone and transfer or re-add each account. In future, use an authenticator that supports secure backup or keep your old phone until the move is finished.