Security

Password Security Awareness Campaign Guide

How to run a password security awareness campaign that actually changes habits — passphrases, MFA adoption, and password manager rollouts.

Updated 29 July 2026
9 min read

Password awareness campaigns have a reputation for being ignored. Most people already know they should use strong passwords — they just don't. A campaign that changes habits focuses on three shifts: passphrases over passwords, multi-factor everywhere, and password managers as the default. This guide walks through how to run one.

The three shifts

  1. Passphrases over passwords. "Correct horse battery staple" is stronger and more memorable than "P@ssw0rd1!". Reframing this alone raises resistance to brute-force attacks dramatically.
  2. Multi-factor authentication on everything. A stolen password without MFA is a breach; with MFA it is a nuisance. The campaign's job is adoption, not education.
  3. Password managers as the standard. Users cannot invent and remember dozens of unique passwords. The tool is the answer. Roll it out with rollout support, not just a link.

Campaign structure

Week 1 — Reframe the problem

Short video from IT leadership: attackers don't guess passwords, they buy them. Publish the top ten most-breached passwords in your industry — often eye-opening.

Week 2 — Passphrases

Guide people through generating a passphrase they can actually remember. Show, don't tell. Pin the guidance to every login screen if you can.

Week 3 — MFA everywhere

Track and publish MFA adoption rates by department (aggregate, not individual). Give team leads a checklist of the top ten personal apps that support MFA — this is where the culture spreads home.

Week 4 — Password manager rollout

Provide the manager, provide the training, provide 30 minutes of paid time to set it up. Anything less will be under-adopted.

Messages that land

  • "Three random words is stronger than eight scrambled characters."
  • "MFA turns a stolen password into a failed login."
  • "You can't remember 200 passwords. Your password manager can."
  • "Reuse is the risk. One breach becomes every breach."

What to measure

  • MFA enrolment percentage before, during, and after the campaign.
  • Password manager active users as a proportion of the workforce.
  • Reduction in password-reset ticket volume once the manager beds in.
  • Reduction in weak or reused passwords surfaced by identity tooling.

Related resources

Turn this topic into a complete campaign

Safety Campaign Hub generates posters, toolbox talks, safety alerts, and digital displays around any topic in minutes.