St. Olaf College | Library & IT Services

Cybersecurity Awareness Month Week 1: Use strong passwords and a password manager

October is Cybersecurity Awareness Month.

October is Cybersecurity Awareness Month. While we need to stay vigilant because threats come at us every day and at an alarming rate, this month we join security-minded people worldwide to focus on upping our cybersecurity game. This week we focus on passwords.

You wouldn’t hand out your house keys to strangers or leave them under the doormat. The same mindset should apply to your digital life. Passwords are still the first line of defense against cybercriminals and data breaches. Yet creating, storing, and remembering dozens (or even hundreds) of them can feel overwhelming. The good news is that with a few simple habits and a password manager, you can take control of your security without the stress.

The Power of Long, Unique, and Complex Passwords

When it comes to passwords, three principles matter most:

1. Long

Longer is stronger. Today, an eight-character password can be cracked in minutes by brute force tools that try every possible combination of letters, numbers, and characters. A 16-character password, by contrast, could take billions of years to guess

HIve Systems Password Complexity Chart

2. Unique

Each account should have its own password. Reusing passwords is common, but a very risky practice. If one account is breached, attackers will try to use that same password to access your other accounts. Small tweaks, like adding a number or symbol, aren’t enough. Each password should be completely unique. A password manager makes this easy by generating unique credentials and storing them for you.

3. Complex

You can include a mix of uppercase and lowercase letters, numbers, and special characters to make your password harder to crack. However, password length will drive strength more than complexity.

+1. Consider Using Passphrases

Passphrases are short sentences or combinations of words that are easy to remember and type. These are especially helpful for passwords you enter by hand frequently. Every additional letter requires exponentially more effort to crack! So, even without complex characters, they’re much stronger than short passwords with complexity.

How Often Should You Change Passwords?

For years, the standard advice was to change your passwords regularly—annually or more often. That’s no longer best practice. The National Institute of Standards and Technology (NIST) now recommends changing your password only if you suspect unauthorized access or if the account is involved in a breach.

Why? Because frequent forced changes lead to bad habits—like recycling old passwords or creating simple ones you can easily remember. Instead, create long, strong, unique passwords and update them only when necessary.

Why Password Managers Are a Game-Changer

The advice above probably sounds daunting if you’re managing passwords on your own. The reality is that most of us have so many accounts that keeping track of them is a challenge. A password manager solves this problem.

With a password manager, you only need to remember one master password. The manager securely stores the rest in an encrypted vault. Password managers can also automatically generate strong, random passwords for every account and autofill them when you log in.

Here’s why a password manager is worth adopting:

Convenience: No more memorizing dozens of passwords.

Security: Automatically generates long, unique, complex passwords.

Time-Saving: Autofill features make logging in quick and secure.

Encrypted Vaults: High-quality managers use strong encryption and “zero-knowledge” architecture, meaning even the provider can’t see your passwords.

Password managers are much safer than notebooks, sticky notes, spreadsheets, or trying to remember passwords yourself. They also reduce your risk if one account is breached—because every other password is unique.

About Passkeys

Passkeys represent the next evolutionary leap in authentication, replacing traditional passwords entirely with a faster, virtually uncrackable alternative. Built on robust public-key cryptography, a passkey pairs a public key stored on a website’s server with a private key locked securely inside your physical device or password manager. Logging in requires no memorization or typing—just a quick biometric check like Face ID, Touch ID, or your device password or PIN. Crucially, passkeys are cryptographically bound to the legitimate domain, making them inherently immune to phishing attacks because a spoofed site simply cannot trick your device into surrendering access. Since servers never hold your secret key, a data breach at a vendor leaves hackers with zero actionable credentials, delivering the rare cybersecurity trifecta of superior protection, zero password fatigue, and frictionless convenience.

About Federated Login

Federated login—such as “Sign in with Google, Apple, or Microsoft”—is one of the simplest ways to boost your online security while reducing complexity. By consolidating your access behind trusted identity providers, you eliminate password fatigue and curb the dangerous habit of reusing credentials across multiple websites. Crucially, federated authentication relies on secure digital tokens rather than sharing raw credentials; the destination site never receives, sees, or stores your password. If that site suffers a data breach, attackers leave empty-handed because their servers never stored your password to steal in the first place. Additionally, federated login lets everyday web services piggyback on enterprise-grade security features—such as real-time threat detection, biometric passkeys, and robust Multi-Factor Authentication (MFA)—so a single, tightly fortified front door protects access to several services.

Taking the First Step

Passwords may never feel fun, but they don’t need to be overwhelming. Start by choosing a password manager and securing your most important accounts (email, banking, social media). From there, you’ll find that keeping your digital life secure becomes much easier.

By using long, unique, and complex passwords, you’re taking one of the most effective steps available to protect your identity and data. Small actions like this add up to a big impact in cybersecurity.

Want to learn more? Check out this article at staysafeonline.org. (https://www.staysafeonline.org/articles/passwords)

Remember…

About phishing simulations. We’ll conduct two phishing simulations for students in October and November. Phishing simulations for employees will continue at the monthly cadence we started in the spring. As always, if you see unusual or suspicious emails, report them as you would any other spam or phishing messages. Your vigilance keeps our community safer.

Get your cybersecurity training done. We aim for all faculty, staff, and first-year students to complete Cybersecurity 101 by the end of the month. It doesn’t take long! Employees who complete the training by the end of October will be entered into a drawing for a $20 Bon Appétit gift card. Separate courses for students and employees can be found in Moodle.

Our online Cybersecurity Town Hall is on October 26. 

Join Kendall George, information security officer for Carleton and St. Olaf Colleges, at our annual Cybersecurity Town Hall: Cybermaxxing to Securitymog the Ops. This engaging, interactive session will describe the current state of cyberthreats in higher education and the steps you can take to keep both campus and your own digital life secure. There will be ample time for questions and answers.

📅 Monday, October 26 at noon

Stay safe out there.

Kendall George

Information Security Officer

Carleton and St. Olaf Colleges