Why I Finally Switched to a Password Manager
The Password Habits That Finally Caught Up With Me
For years I ran the same handful of passwords across dozens of accounts, tweaking a number or a punctuation mark here and there when a site insisted I change it. I told myself I'd remember them because they all followed a pattern only I would know. Then a service I used got breached, and within days I was getting login attempts on accounts that had nothing to do with that service, just because I'd reused a version of the same password everywhere. That was the point I stopped treating password habits as a minor inconvenience and started treating them as one of the biggest gaps in my own security.
What Changed Once I Started Using a Password Manager
Switching over felt like a chore I kept putting off, mostly because I assumed it would slow me down every time I logged into something. In practice it did the opposite. I now have a genuinely random, unique password on every account I own, and I never have to remember a single one of them beyond the master password that unlocks the vault. Logging in got faster, not slower, because the manager fills the details in for me the moment I land on a login page I've used before.

The bigger shift was psychological. I stopped feeling that low background anxiety about whether an old password of mine was floating around in some leaked database somewhere. If one account does get compromised, it's isolated. Nothing else I own shares that password, so there's nothing for an attacker to try next.
It also changed how I think about new accounts. I used to hesitate before signing up for a new service because it meant coming up with yet another password to remember, which often meant reusing something I already had. Now I don't think about it at all. The manager generates something long and random, saves it, and I move on. Creating an account went from a small chore to something that takes seconds, which sounds trivial but adds up over the dozens of accounts most of us end up with over a few years.
The Features I Actually Use Day to Day
I settled on NordPass after comparing a few options, mainly because of how it handles the parts I actually use rather than the parts that look good in a features list. The password generator creates long, random strings I'd never come up with myself, and it autofills them without me having to copy and paste anything, which is the habit that used to get me into trouble in the first place.
The breach monitoring is the feature I didn't expect to rely on so heavily. It flags if any of my saved logins show up in a known data breach, which means I find out and change that one password within days rather than months later when something actually goes wrong. I also use the secure notes feature for things like Wi-Fi passwords and software licence keys, so they're not scattered across sticky notes and random text files anymore.
What I'd Say to Someone Who Thinks They Don't Need One
The most common thing I hear is some version of "I don't have anything worth stealing," which misunderstands what's actually at risk. It's rarely about one dramatic hack. It's about a scammer finding a password from an old breach, testing it against your email and banking logins, and getting in because you reused it somewhere convenient. I've written before about the difference between using a password manager and just memorising everything, and the short version is that human memory simply isn't built to hold dozens of genuinely random strings, so we end up choosing patterns that are easier to guess than we think.
The other thing worth saying is that a strong password habit doesn't cancel out other risks. Phishing emails are still designed to trick you into typing your password into a fake login page, manager or no manager, so it's worth knowing what a convincing fake actually looks like rather than assuming your inbox will always flag it for you.
Setting It Up Properly Took Less Time Than I Expected
I'd built this up in my head as a weekend project, and it took me under an hour to import my existing passwords, set a strong master password, and install the browser extension and phone app. The slow part, if there is one, is going back through your accounts over the following weeks and swapping out the old reused passwords for freshly generated ones as you log into each site naturally. I didn't try to do it all in one sitting. I just let the manager flag weak or duplicate passwords and worked through them a few at a time.
The one piece of advice I'd pass on is to actually write down your master password somewhere safe and offline while you're getting used to the system, rather than trusting yourself to remember a brand new phrase under pressure. It's the single password you can't afford to lock yourself out of, so it deserves a bit more care than the rest. Once it's memorised properly, that note can go.
If you want a fuller walkthrough of the other basics I'd put in place alongside this, I've pulled them together in a free Safety Toolkit. And for wider guidance on protecting your accounts from the UK's national authority on the subject, the NCSC has clear advice worth reading too.
Looking back, the actual effort was tiny compared to how much background stress it removed. I'm not managing dozens of half-remembered passwords in my head anymore, and that's one less thing that can quietly go wrong.
