Saturday, October 3, 2026 Newsletter Advertise
Breaking
How-to guides

How to manage your passwords safely with a password manager

The UK National Cyber Security Centre explains how to store unique passwords in a browser or third-party password manager, and why it now recommends passkeys first.

How to manage your passwords safely with a password manager. Source: UK National Cyber Security Centre

This guide explains how to store and generate unique passwords for your online accounts using a password manager, either the one built into your browser or device or a third-party app. All steps and recommendations come from the UK National Cyber Security Centre's guidance page "Managing your passwords", reviewed and updated on 21 May 2026.

What it does

The NCSC says a password manager stores passwords safely for you, meaning that you can have unique passwords for each service as you won't need to remember them. These tools may already be built into your browser, or you can install one from a third-party.

According to the guidance, password managers often include automatic password generation to quickly create a strong and unique password for each account; an autofill function; synchronisation across devices; and warnings that a password has been breached or leaked. The NCSC says autofill also helps protect you from phishing attacks because the password will only autofill on the correct website.

The agency says reusing passwords matters because if one account is compromised, a hacker can try the same password on your other accounts and potentially gain access to them too.

Before you start

The NCSC states that the first and most important step is to turn on two-step verification (2SV) to help protect you if your password gets phished or otherwise compromised.

It also says most password managers are designed to be user-friendly, and that tutorials and customer support are available to help new users get started.

Steps

Step 1: Turn on two-step verification for your accounts. The NCSC describes this as the first and most important step.

Step 2: Decide whether to use the password manager in your browser or device, or a third-party one. The NCSC says all the major browsers, such as Chrome, Edge and Safari, offer the option to create and/or save your passwords, and that it is safe to do this on your own devices.

Step 3: Do not save passwords in the browser on shared devices outside your home, such as a desktop computer at a college, library or other public place. For a device shared in your household, the NCSC says you should consider who else could access the computer and, if you aren't sure, simply not allow your browser to save passwords when it asks.

Step 4: Keep your software updated. The NCSC says passwords stored in the browser are only as secure as your devices and accounts, so you should not switch off the security auto-update feature for your browser and operating system.

Step 5: If you prefer a third-party password manager, install the app on your phone or tablet or use it via a website in your browser, then log into it using your primary password. The NCSC says one of the main benefits over a browser manager is that it can synchronise passwords even when you have a mix of different browsers and devices.

Step 6: Choose a manager that fits your needs. The NCSC suggests considering whether you need it to work across different devices and operating systems, whether you want to specify the kind of passwords it generates (for example, length or character set), whether you are willing to pay or prefer a free version, and extra features such as password sharing or data breach notifications.

Step 7: Remember your primary password and protect the manager itself. The NCSC says many password managers offer recovery options, like secure password hints or emergency access through trusted contacts, and that you should switch on two-step verification on the password manager account so a criminal who knows the primary password still can't get in.

Writing passwords down, and passkeys

The NCSC says writing passwords down in a journal or dedicated password book can suit certain scenarios, for example where people need regular support from family members, and can be done safely because an attacker would need physical access. It warns that passwords must not be predictable or guessable, that some online banking services forbid users to write down their passwords, that anyone with access to the book could copy them, and that you will be at greater risk of phishing because you must manually verify websites yourself.

On passkeys, the NCSC says a passkey lets you sign in with a digital key that's protected by your device's existing unlock method, such as fingerprint, face check, or passcode. The agency recommends making passkeys your first choice of login and using them wherever they are offered, and says that for accounts that don't yet offer passkeys you should continue using a strong and unique password and two-step verification.

What to do

  • Turn on two-step verification for your important accounts first, and also on your password manager account.
  • Use a password manager — built into your browser or device, or a third-party app — to generate and store a unique password for every service.
  • Never let a browser save your passwords on a public or college or library computer, and think carefully before doing so on a household device others can access.
  • Leave security auto-updates switched on for your browser and operating system, since browser-stored passwords are only as secure as your devices and accounts.
  • Pick a manager based on device compatibility, password generation options, cost and extra features such as breach alerts or password sharing.
  • If you write passwords down, keep them unpredictable, check the service's terms allow it, control who can reach the book, and be extra sceptical of links in emails and texts.
  • Use passkeys wherever they are offered, and keep strong, unique passwords plus two-step verification for accounts that don't support them yet.
Key facts and where they come from
  • The NCSC calls turning on two-step verification the first and most important step.
    The first – and most important – step is to turn on two-step verification (2SV) to help protect you if your password gets phished or otherwise compromised.
  • A password manager lets you use unique passwords without memorising them.
    A password manager stores passwords safely for you, meaning that you can have unique passwords for each service as you won’t need to remember them.
  • Autofill offers phishing protection because passwords only fill on the correct site.
    This also helps protect you from phishing attacks as the password will only autofill on the correct website.
  • Saving passwords in the browser on your own devices is described as safe.
    It's safe for you to do this on your own devices and it's the easiest way to remember your passwords
  • Never save passwords in the browser on public shared devices.
    you should never save your password in the browser
  • Third-party managers can sync across mixed browsers and devices.
    it can synchronise passwords even when you have a mix of different browsers and devices
  • Two-step verification should also be enabled on the password manager account.
    You should also switch on two-step verification (2SV) on the password manager account.
  • The NCSC recommends passkeys as the first choice of login.
    The NCSC recommends making passkeys your first choice of login and using them wherever they are offered.

Read the original from UK National Cyber Security Centre →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More How-to guides