Passwords restrict access to information and systems to authorized users. Strong, unique passwords help defend against dictionary attacks, brute-force attacks, and password-capturing tools such as keyloggers.
Do
- Use a different strong password for every account.
- Use a combination of uppercase and lowercase letters, numbers, and special characters.
- Change a password immediately if it has been shared or revealed.
- Change passwords at regular intervals when required by the service or policy.
- Use passwords of at least thirteen characters where supported.
Do not
- Include birth dates, names, identity details, addresses, or phone numbers.
- Use names of family members, pets, friends, colleagues, or fictional characters.
- Use a password that is short or easy to guess.
- Access banking or other sensitive services from public computers.
- Share passwords or one-time passwords through email, chat, or other electronic communication.
- Reveal passwords in questionnaires or security forms.
- Save passwords in a browser on banking or other sensitive sites.
- Write passwords down where they can be found, such as on a note next to the computer.
- Use biometrics at untrusted terminals or locations.
Password Managers and Multi-Factor Authentication (MFA)
Password Managers
Use a reputable password manager (built-in options from major browsers/OS or dedicated tools) to generate and store unique, long passwords (ideally 15+ characters or passphrases) for every account.
This prevents reuse, which is a major risk when one site is breached.
- Never store banking credentials only in the browser without additional protections.
- Choose managers that support strong encryption and zero-knowledge architecture.
Multi-Factor Authentication (MFA)
Enable MFA everywhere it is offered—especially email, banking, social media, and cloud accounts.
Preferred methods (strongest to weaker):
- Hardware security keys or Passkeys
- Authenticator apps (Google Authenticator, Microsoft Authenticator, Authy, etc.)
- Biometrics (where supported)
- SMS (use only if no better option is available)
MFA requires something you know (password) + something you have (device/app) or are (biometrics).
Government and industry guidance (including RBI for payments and broader cybersecurity best practices) strongly recommend MFA for high-risk access.
Quick Checklist:
- Unique password for every account
- Password manager installed and in use
- MFA enabled on email and banking
- Authenticator app preferred over SMS
- Recovery options reviewed and secured