Professional IT services from accompio for companies in Germany.
Blog

Password security: How to create truly secure passwords – and why most people fail

19.08.2026

Password security is one of the fundamentals of IT security – and yet it is frequently underestimated. People still use simple passwords like „123456“, personal information or the same login credentials for multiple services. For attackers, precisely this can become the decisive gateway.

Young man in a T-shirt against a blue background with a focus theme.

Timur Yilmaz, Service Owner for Security Validation at accompio, regularly experiences in practice how insecure passwords endanger companies. During security audits and password checks, passwords are deliberately tested for security – with results that are sometimes sobering. In the expert interview, he explains how attackers obtain passwords, which mistakes are particularly common, and how secure passwords can actually be implemented in everyday life.

The most important points briefly

  • Length is crucial: A secure password should be as long as possible. Passphrases are a practical way to use long yet memorable passwords.
  • Never reuse passwords: If a password is leaked in a data breach, attackers can try to use it for other services and corporate access as well.
  • Avoid personal information: Names, dates of birth, pets, places or other personal references are not suitable as passwords.
  • Password managers make secure passwords easier: This means that users only have to remember a single strong master password. The remaining passwords can be generated automatically and managed securely.
  • Multi-factor authentication remains important: Even if a password has been compromised, an additional factor can still prevent access.
  • Password policies alone are not enough: Organisations should provide specific training to employees, teaching them how to create secure passwords and explaining why certain behaviours are risky.
  • Passwords won't disappear that quickly: Biometric methods can make usage more convenient. However, a password often remains in place as a fallback.

Password security: expert interview with Timur Yilmaz, Service Owner at accompio

What actually makes a secure password? Which tools can help you with password creation and management? And what are the consequences of weak or recurring passwords at an enterprise level? Timur Yilmaz provides all the answers in the full video interview.

Password security in practice: Why simple passwords are still a problem

„SummerPlant2025!“ or „123456“ – passwords of this kind are still regularly encountered by security experts. Passwords with a personal reference, such as family names, pets, dates of birth or well-known places, are also problematic.

Timur Yilmaz knows these patterns from his daily work. As a Service Owner for Security Validation, he accompanies Security checks and security audits for clients. This also includes password checks, which test how secure the passwords used within the company actually are.

The result highlights a fundamental problem: no matter how extensive technical security measures may be, if access credentials are easy to guess or have already been compromised elsewhere, a significant vulnerability arises.

How do attackers get hold of passwords?

Passwords can fall into the hands of attackers in various ways. A particularly common scenario is phishing: for example, users receive an email with a link that leads to a fake login page. If the password is entered there, attackers can intercept the login details.

Another danger is data leaks. If an online service is compromised, stored access credentials or password data can fall into the hands of attackers. This information can then be cross-referenced with other known access credentials.

This is precisely where password reuse shows its danger: a password compromised on a private service can become a risk to corporate system access if the same password is used there as well.

What is a truly secure password?

When it comes to what makes a secure password, Timur Yilmaz focuses primarily on one factor: the length.

The longer a password is, the better. Instead of short, complex-looking character strings, long passphrases can therefore also be used. They have another advantage: long passwords are often easier to remember if they consist of several words.

At the same time, a password should not have any personal connection. Names, dates of birth, pets, favourite places or other information that can be found out about the person in question should not be part of a password.

„Anything with a personal connection should not be a password. I don't know my passwords. I know a single password – the one for my password manager.“

— Timur Yilmaz, Service Owner at accompio

So a good password is not necessarily the most complicated password. The crucial thing above all is that it long, unique and not derived from personal or easily predictable information is.

Why a password manager is useful

A Password manager solves one of the biggest practical problems in password security: nobody has to remember dozens of complex passwords anymore.

Instead, a strong master password is required. The remaining access credentials can be stored and managed within it. A password manager can also generate secure, random passwords that consist of many characters and have no personal connection.

Timur Yilmaz uses a password manager himself – both personally and in his business. As a result, he doesn't even know his individual passwords by heart. Instead, a separate, long password is used for every service.

Is a strong password enough? The role of multi-factor authentication

Even a strong password should not be the only security measure. An important additional security layer is multi-factor authentication (MFA).

In this process, the login is not secured by the password alone. An additional factor must also be confirmed – for example via a smartphone, a code or a biometric method.

This significantly increases security. Even if an attacker knows a password or has managed to crack it, the password alone is not necessarily enough to gain access to a protected account.

Multi-factor authentication should therefore be an important component of a holistic identity and access security strategy for businesses.

Password security in the workplace: why training matters more than mere policies

Companies often try to enforce secure passwords through mandatory password policies. While requirements for upper and lower case letters, numbers and special characters can be useful, they do not automatically guarantee a secure password.

A real-world example illustrates the problem: a user can create a password such as „SommerPflanze2025!!“ and thereby formally meet various complexity requirements. Even so, the password remains predictable and therefore insecure.

This is why Timur Yilmaz trainings as a particularly important component of password security. Staff must understand how secure passwords are created, why password reuse is dangerous, and which behaviours attackers can exploit.

Password security is therefore not exclusively a technical task. It is also a matter of knowledge and behaviour.

Transparent castle on a digital server, symbolising IT security solutions.

Secure passwords for protected applications

accompio identifies vulnerabilities in your password and security structure before they can become gateways for real-world attacks.

What can companies do specifically for better password security?

The first step is to know the actual state. Password checks and security reviews can help to make vulnerabilities visible.

Building on this, companies should specifically raise awareness among their employees and provide them with concrete methods. These include in particular:

  • unique and long passwords for every account,
  • the use of a password manager,
  • the omission of personal information in passwords,
  • do not reuse corporate passwords for personal services,
  • the use of multi-factor authentication,
  • regular training and staff awareness raising.

This is how an abstract password policy becomes a security concept that can also be implemented in everyday work.

Conclusion

Anyone wishing to improve their own password security can start with a few simple steps: Are passwords used multiple times? Do they contain personal information? Are important accounts additionally protected by multi-factor authentication? And is a password manager already being used?

The most important step is not to wait until a security incident occurs to take action. Password security should be an integral part of personal and corporate IT security.

Neon silhouette of a head, symbolising digital innovation and IT services at accompio.
Timur Yilmaz
Service Owner Security Validation, accompio

About the expert

Timur Yilmaz is an expert in password security and security solutions. He advises clients on securing their access and applications.

FAQ: Frequently asked questions about password security

What makes a password truly secure?

A secure password is above all long and individual. It should have no personal connection and not be used across multiple services. Long passphrases or randomly generated passwords are particularly suitable.

How long should a secure password be?

As a general rule, the longer a password, the better. In the interview, Timur Yilmaz therefore recommends passwords or passphrases that are as long as possible. When using a password manager, very long, randomly generated passwords can also be used.

Are long passphrases safer than short passwords?

Long passphrases can be a good way to create secure yet memorable login details. Length is particularly crucial. Furthermore, a passphrase should not consist of easily guessed personal information.

Why should you not reuse passwords?

If a password is compromised in a data leak at one service, attackers can try using the same password on other services. If it is used both privately and for a corporate account, for instance, a private data leak can become a security risk for the company.

Are password managers secure?

Password managers make it possible to use a unique and very long password for every service without users having to memorise all their access details. Instead, only one strong master password is required. The remaining passwords can be generated and stored by the password manager.

Is multi-factor authentication needed in addition to the password?

Yes. Multi-factor authentication provides an additional layer of protection. Even if an attacker knows the password, they need another factor, such as a smartphone, a code or biometric confirmation.

What should companies do for better password security?

In addition to technical measures, companies should focus primarily on training. Password policies alone are not enough if employees use passwords that are formally complex yet easily predictable. Training should specifically teach how secure passwords are created and why password reuse is risky.

Woman with a headset in customer service at Accompio IT Services.

Get in touch with us

We at accompio will be happy to help you.

Arrange an initial consultation

This field is for validation purposes and should be left unchanged.
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form

From time to time we would like to inform you about our products and services as well as other content that may be of interest to you. You can unsubscribe from these communications at any time. If you agree to us contacting you for this purpose, please tick the following box. You can revoke your consent at any time with effect for the future - via the unsubscribe link at the end of each e-mail or by e-mail to info@accompio.com.

We process and store your data. You can find further information at Privacy Policy.

})