Frequent password changes doesn’t always help: cybersecurity expert offers 7 tips to protect your data

October 10, 2024
As more personal information is transferred to the virtual space, the risk of data becoming vulnerable increases. One of the main targets for modern hackers is passwords. When should they be changed, and what password combinations are the safest?

Frequent password changes – not always a good solution

Not long ago, IT experts recommended regularly changing passwords to reduce the risk of secret thefts or cybercriminal hacking.

Gediminas Mikelionis, an IT engineer at "Baltimax" and an ESET expert, states that trends are changing. "Recent studies show that frequently changing passwords on a set schedule doesn't necessarily enhance account security. In other words, there is no one universal answer to when you should change your passwords," says Mikelionis.

The cybersecurity expert explains why it is not recommended to change passwords every few months:

  • Users tend to choose weaker and easier-to-remember combinations when they know they will have to change them soon.
  • The updated password is often similar to the old one, just slightly altered, for example, by adding a number.
  • This practice creates a false sense of security: if the previous password was already insecure and the new one is not stronger, hackers can easily crack it again.
  • New passwords created every few months are more often forgotten or written down somewhere, making it easy for others to find them.
When is it necessary to change a password?

There are several cases when it is essential to change a password, especially for critical accounts.
 

You should change it if the password has leaked into third-party databases, and you are likely to be notified by the service or password manager providers performing automatic checks on the dark web.
 
You should also change it if the password is weak and easily guessable, included in lists of commonly used passwords, or reused across multiple accounts.
 
Moreover, you should urgently change your password if you learn that malware has entered your device, you have shared your password with someone else, you have removed people from a shared account, or you have logged in on a publicly available computer, for instance, one available in a library.
 
It is important to remember that simply changing a password is not enough; it needs to be reliable. Cybersecurity expert G. Mikelionis provides two main rules he follows when creating passwords.
 
"When creating a password and trying to remember it, I convert a simple word into symbols and numbers. For example, I change 'password123' to '5l@pt@z0d1s123.' In some exceptional cases, I don’t even know the password because I remember the combination on the keyboard.
The second rule is to always use two-factor authentication if the system supports this feature," advised Gediminas Mikelionis.
 
7 tips to protect your data:
  1. Always use strong – long and unique – passwords.
  2. Store them in a password manager that has one main login password and can automatically remind you of all your passwords for any website or app.
  3. Monitor alerts about compromised passwords and take immediate action upon receiving them.
  4. Whenever possible, enable two-factor authentication to ensure an additional layer of security for your account.
  5. Consider enabling passkeys for seamless and secure access to your accounts using your phone.
  6. Regularly review your passwords: check all your account passwords to ensure they are not duplicated and are not easily guessable. Change any weak, repetitive, or those that might include personal information, such as birthdays, family member names, or pet names.
  7. Do not store passwords in your browser – this is a popular and easily accessible target for hackers. Using malware, hackers can steal passwords. Additionally, any other person using the same device could see the saved passwords.

Related news

Elektroninių paslaugų platforma BUS
Elektroninių paslaugų platforma BUS
Kviečiame naudotis elektroninių paslaugų platforma Biblioteka–Universitetas–Studentas (BUS)  – bus.vilniustech.lt Čia rasite dėstytojų rekomenduojamus literatūros sąrašus ir kitus informacinius išteklius bei nuorodas į juos visų studijų formų ir fakultetų studentams. BUS pagalba turėsite galimybę peržiūrėti rekomenduojamų leidinių viršelius ir turinius, būsite tiesiogiai nukreipti į leidinio saugojimo vietą ir galėsite iškart užsakyti ar skaityti dalį leidinio Google Books sistemoje. Aktyvuotą dėstytojų rekomenduojamą literatūrą studijų dalykui taip pat rasite mano.vilniustech.lt skiltyje STUDIJOS. Elektroninių paslaugų platformoje BUS taip pat galite: susipažinti su kas mėnesį naujai gaunamais leidiniais >>> prenumeruoti naujienlaiškį ir pirmi  sužinoti, kokie nauji leidiniai  pasiekia biblioteką >>> rekomenduoti bibliotekai įsigyti mokslui ir studijoms VILNIUS TECH reikalingus leidinius, užpildant knygų pasiūlymo formą >>> peržiūrėti Lietuvos ir užsienio leidyklų naujausius knygų pasiūlymus >>> susipažinti su bibliotekos organizuojamais mokymais >>> rezervuoti darbo kambarius >>> užsakyti leidinius arba straipsnių kopijas iš Lietuvos ir užsienio bibliotekų naudojantis tarpbibliotekinio ar tarptautinio tarpbibliotekinio abonemento paslaugomis (TBA/TTBA), užpildant leidinių užsakymo formą >>> pateikti leidinio įtraukimo į leidybos planą paraišką  >>>
More
Women TechEU: Funding Opportunity for Women-Led Deep Tech Startups
Women TechEU: Funding Opportunity for Women-Led Deep Tech Startups
Women-led deep tech startups are invited to apply for Women TechEU, an EU-funded initiative designed to support early-stage companies led by women and help them grow into Europe’s future technology leaders. The 2026–2028 edition of Women TechEU will provide €12 million in equity-free funding to support 160 women-led deep tech startups across Europe. Each selected company will receive a €75,000 non-dilutive grant, complemented by a tailored business development programme including mentoring, coaching, training, expert guidance, investor and corporate matchmaking, and networking opportunities. The application process consists of two stages. Applicants must first complete the Eligibility Strand, a simplified eligibility check designed to confirm whether the company meets the programme’s participation requirements. Eligibility applications are accepted on a continuous basis, with weekly cut-off dates every Tuesday at 17:00 Brussels time. The Eligibility Strand remains open until 14 June 2027. Applicants that successfully pass the eligibility check will be invited to submit a Full Proposal. Four Full Proposal submission deadlines are scheduled between 2026 and 2027. Women TechEU also places a strong emphasis on addressing geographical disparities in Europe’s innovation ecosystem. Forty per cent of the budget available at each cut-off is reserved for applicants based in Horizon Europe Widening countries, including Lithuania. The programme is open to eligible women-led early-stage deep tech startups established in EU Member States and eligible Horizon Europe associated countries. Lithuanian women-led deep tech startups are encouraged to explore this opportunity and apply for financial and tailored business development support that can help accelerate their growth, strengthen investor readiness and expand their European networks. More information about the programme, eligibility requirements and application process is available on the official Women TechEU website: womentecheurope.eu.
More