Cyber Security Awareness Month
It’s Cyber Security Awareness Month! With Autumn upon us, it is a great time to reflect on how even small changes can increase our everyday Cyber Security with minimal effort. These changes are not only good for your personal Cyber Security posture, but also protecting your organisation from cyber related threats.
Often spoken about, passwords can be the first line of defence to our online world, and the National Cyber Security Centre have designed a simple password creating method called ‘Three Random Words’.
By thinking of three completely random words and placing them together, you can create a long and strong password that is easy to remember. Add a number or special character if required.
Example: BiscuitLetterGlasses

It is important to choose words that do not relate you to in any way, nothing that includes your personal information, favourite hobbies or interests, and nothing that could be considered a common password that people often use, like the word ‘password’, a family name, or favourite sports team, etc. Choose words that are not too small, and are as random as possible think random.
There are common password lists online, and criminals use these to try and discover passwords quicker than trying to break through every combination possible. How do you know if you’re passwords remain secure? There is also a useful website, created by Cyber Security expert Troy Hunt, called, ‘HaveIBeenPwned’:
In this website, you can check if your passwords have been published online by criminals (for all to see) from organisations that have had their data stolen. To check if your email address is listed in a known data breach, type your email address on the search field within the main page and press the ‘pwned?’ search tool.
If the page turns red, scroll down to see if you recognise any of the accounts or information displayed (some may not be familiar), but if you recognise a name, then change your password on this account as soon as possible.
Additionally, make sure to change any other account passwords where you may have reused the same password, or similar. For example, the passwords: ‘BoxerKettleSavoury’ and, ‘BoxerKettleSavoury172’ are similar to each other and would warrant changing. If a criminal obtains one password from a data breach, they can try to use versions of a known password with slight differences, against other accounts that you may have, as often passwords are reused with a small difference to try and cope with remembering so many, (see ‘Life Hack’ below for further tips on this issue!).
Top Tip: Prioritise updating and securing your email account/s first. Email accounts can be the key to all the others as a password reset request is often sent to your email account. And remember – keep your business accounts completely separate from your personal accounts.
Returning to HaveIBeenPwned, another page within the website has a helpful password checking tool, where you can type a password and see if it is already known or considered a commonly used password to avoid.
For example, typing in the password, ‘password123’, and pressing the ‘pwned?’ search tool, currently states that ‘password123’ is…

It is therefore not recommended using this common password, as it is already listed in databases that criminals can use.
Remember to think random!
Life Hack: Struggling with multiple passwords? Try out a Password Manager App that can remember all your passwords for you, and make each password strong and unique without you having to remember them. To add an extra layer of security to your Password Manager App and other important online accounts, add ‘2FA’ (2 Factor Authentication).
Using multi-factor authentication methods and the techniques mentioned above to ensure your passwords strong are essential to keeping your accounts secure. Want to go the extra step? Consider adopting passkeys where available. Learn more about passkeys from the NCSC.
More information on these tools and how to increase your day to day Cyber Security can be found on the NCSC Cyber Aware website.
If you have a business and are looking to improve your cyber security, ITSUS Consulting provide expert consultancy and professional services in the areas of network and cyber security. Please reach out to our team to discuss how we can help you keep your organisation secure and resilient in our ever changing digital world.
Happy Cyber Security Month, from Natalie at ITSUS Consulting!
Natalie is a Cyber Security Consultant with over 20 years experience providing IT & cyber support and developing technology services.


