Passwords: Securing Your Accounts

Strong passwords are your first line of defense online. See how length, password managers, and MFA work together to keep your accounts secure and your information protected

Last Edited by: LPL Financial

Last Updated: September 04, 2026

Young woman pointing to a phone login screen showing a lock and password field, blue background.

IN THIS ARTICLE

Protecting your sensitive information with a strong password is one of the most important steps you can take to protect yourself online. Since your passwords are your first line of defense, ensuring they’re long and complex enough to avoid being compromised is essential.

The good news is that a few consistent habits can make a meaningful difference. By understanding what makes a password strong and how to add a second layer of verification, you can take control of your account security.

Strong Passwords

The key to crafting strong passwords are making them long, random, and different for every account. If your password is the only way to long into an account, the National Institute of Standards and Technology (NIST) now recommends that they be at least 15 characters long. If they are used alongside multifactor authentication, they should be at least eight characters in length.

It’s important to note that length matters more than complexity, so systems should allow passwords of up to 64 characters, which makes it easier to use longer passphrases and provides an added layer of security.

NIST no longer requires passwords to include a mix of uppercase and lowercase letters, numbers, and special characters, and it no longer recommends forcing password changes on a fixed schedule. However, including a variety of character types can still make a password harder to guess, even if it is not required.

Here are a few additional tips that can help you build stronger passwords:

  • Prioritize password length and complexity.
  • Avoid using words that can be found in the dictionary.
  • Make your password random and different for each account.
  • Do not include personal information, such as birthdays or pet names.

Tips for Protecting Your Passwords

Strong passwords only work when you protect them in the real world. A few simple habits go a long way toward keeping your credentials out of the wrong hands:

  • Do not share your passwords with anyone.
  • Use a different, complex password on every account or device.
  • Avoid writing down your passwords or storing them in plain sight.
  • Consider using a password manager to conveniently manage strong passwords across multiple platforms.

Using the same password across multiple accounts is one of the most common mistakes people make. If one account is breached, every other account sharing that password becomes vulnerable. Different passwords for each account limit the damage if a single credential is exposed.

What Are Password Managers?

A password manager is a tool that helps you create and manage complex passwords. It generates strong passwords for you and syncs your accounts across all of your devices, so they are easy to use wherever you are. The goal of a password manager is to keep your passwords organized in one place.

When you use a password manager, you only need to remember one strong master password. The tool fills in your credentials automatically when you sign in to your accounts, making it practical to use a different, strong password for every account.

Why Password Managers Matter

Bad actors may try to steal passwords to gain unauthorized access to accounts. If they succeed, they can reach sensitive information and use it to commit fraud. Understanding how these attacks work shows why strong, distinct passwords matter.

  • Brute force attacks use software to guess password combinations until access is gained. The software tries many passwords rapidly, so shorter and simpler passwords are easier to crack. Longer passwords increase the number of possible combinations, making these attacks impractical.
  • Phishing uses messages designed to trick you into sharing your passwords or other personal information. A bad actor might send an email or text that appears to come from a legitimate source, directing you to a fake login page that captures your credentials.
  • Credential stuffing is a cyberattack in which bad actors use credentials stolen from one data breach to try to log in to other accounts. If you reuse the same password across sites, a single breach can put every account sharing that password at risk.
  • A password manager helps defend against all three by making it easy to use long, distinct passwords for every account.

Enable Multifactor Authentication

Strong passwords are essential, but enabling multifactor authentication (MFA) adds another layer of security. This method asks you to provide two or more pieces of evidence to verify your identity before granting access to an application. According to the Cybersecurity and Infrastructure Security Agency (CISA), using MFA makes you significantly less likely to be hacked.

How MFA Works

Each part of MFA must come from a different category:

  • Something you know, such as a password
  • Something you have, such as a text message code sent to your phone
  • Something you are, such as a fingerprint or other biometric identifier

MFA is a valuable way to protect your accounts from unauthorized access, even if one piece of information is compromised. A stolen password alone is not enough to log in when a second factor is required.

Compromised Password?

If an account’s password is compromised, taking prompt action can help limit the damage. Consider the following steps:

  • Change the account password.
  • If other accounts use a similar password, change those as well.
  • Enable MFA on your accounts.
  • Continuously monitor your accounts for unauthorized activity.
  • Submit fraud claims for any unrecognized transactions.
  • Scan your device to confirm it is not compromised.

A local IT provider can assist with this process.

Monitor Your Accounts

Regularly reviewing your accounts for unknown or unauthorized transactions is a best practice for keeping them protected. Setting up account alerts keeps you informed with every transaction that occurs. If you are alerted to a transaction you do not recognize, contact that company right away.

If you identify an unknown transaction on your LPL account, contact your financial advisor or call the LPL client line at (800) 558-7567. Staying vigilant and reviewing your accounts regularly can help you catch issues early.

Take a Deeper Dive

Continue exploring actionable insights to fuel your financial future.


PASSWORD FAQS

A strong password is long, random, and different for every account. While many websites still ask for a mix of uppercase and lowercase letters, numbers, and special characters, length is what matters most. The most important practice is using a different password for every account so that a single breach does not expose multiple accounts.

A password manager is one option worth considering among several good habits for protecting your accounts. It generates strong passwords, stores them securely, and fills them in automatically, so you only need to remember one strong master password. For many people, a password manager simplifies the process of maintaining strong, distinct credentials across multiple platforms, but it works best alongside other practices like enabling multifactor authentication and monitoring your accounts.

Multifactor authentication, or MFA, is a security method that requires two or more pieces of evidence to verify your identity before granting access to an account. Each piece must come from a different category: something you know, such as a password; something you have, such as a code sent to your phone; or something you are, such as a fingerprint. Because MFA requires more than just a password, it helps protect your account even if your password is stolen.

If you suspect a password has been compromised, act quickly. Change the password on the affected account and change any other accounts that use a similar password. Enable multifactor authentication if it is available and monitor your accounts for any unauthorized activity. If you notice unfamiliar transactions, submit fraud claims and contact the company involved. Scanning your device for malware is also a good step, and a local IT provider can help if you need assistance.

Protecting financial accounts starts with the same fundamentals that apply to any account: use long, distinct passwords, enable multifactor authentication, and avoid sharing your credentials. For your LPL account specifically, you can set up account alerts to stay informed about every transaction and review your statements regularly. If you notice an unknown transaction, contact your financial advisor or call the LPL client line at (800) 558-7567 right away.


Disclosures

Content in this material is for educational and general information only and not intended to provide specific advice or recommendations for any individual.

Tracking #1169775