Search the site

Type to search the current language.

Passwords restrict access to information and systems to authorized users. Strong, unique passwords help defend against dictionary attacks, brute-force attacks, and password-capturing tools such as keyloggers.

Do

  • Use a different strong password for every account.
  • Use a combination of uppercase and lowercase letters, numbers, and special characters.
  • Change a password immediately if it has been shared or revealed.
  • Change passwords at regular intervals when required by the service or policy.
  • Use passwords of at least thirteen characters where supported.

Do not

  • Include birth dates, names, identity details, addresses, or phone numbers.
  • Use names of family members, pets, friends, colleagues, or fictional characters.
  • Use a password that is short or easy to guess.
  • Access banking or other sensitive services from public computers.
  • Share passwords or one-time passwords through email, chat, or other electronic communication.
  • Reveal passwords in questionnaires or security forms.
  • Save passwords in a browser on banking or other sensitive sites.
  • Write passwords down where they can be found, such as on a note next to the computer.
  • Use biometrics at untrusted terminals or locations.

Password Managers and Multi-Factor Authentication (MFA)

Password Managers

Use a reputable password manager (built-in options from major browsers/OS or dedicated tools) to generate and store unique, long passwords (ideally 15+ characters or passphrases) for every account.

This prevents reuse, which is a major risk when one site is breached.

  • Never store banking credentials only in the browser without additional protections.
  • Choose managers that support strong encryption and zero-knowledge architecture.

Multi-Factor Authentication (MFA)

Enable MFA everywhere it is offered—especially email, banking, social media, and cloud accounts.

Preferred methods (strongest to weaker):

  1. Hardware security keys or Passkeys
  2. Authenticator apps (Google Authenticator, Microsoft Authenticator, Authy, etc.)
  3. Biometrics (where supported)
  4. SMS (use only if no better option is available)

MFA requires something you know (password) + something you have (device/app) or are (biometrics).

Government and industry guidance (including RBI for payments and broader cybersecurity best practices) strongly recommend MFA for high-risk access.


Quick Checklist:

  • Unique password for every account
  • Password manager installed and in use
  • MFA enabled on email and banking
  • Authenticator app preferred over SMS
  • Recovery options reviewed and secured