Password Security Awareness Campaign Guide
How to run a password security awareness campaign that actually changes habits — passphrases, MFA adoption, and password manager rollouts.
Password awareness campaigns have a reputation for being ignored. Most people already know they should use strong passwords — they just don't. A campaign that changes habits focuses on three shifts: passphrases over passwords, multi-factor everywhere, and password managers as the default. This guide walks through how to run one.
The three shifts
- Passphrases over passwords. "Correct horse battery staple" is stronger and more memorable than "P@ssw0rd1!". Reframing this alone raises resistance to brute-force attacks dramatically.
- Multi-factor authentication on everything. A stolen password without MFA is a breach; with MFA it is a nuisance. The campaign's job is adoption, not education.
- Password managers as the standard. Users cannot invent and remember dozens of unique passwords. The tool is the answer. Roll it out with rollout support, not just a link.
Campaign structure
Week 1 — Reframe the problem
Short video from IT leadership: attackers don't guess passwords, they buy them. Publish the top ten most-breached passwords in your industry — often eye-opening.
Week 2 — Passphrases
Guide people through generating a passphrase they can actually remember. Show, don't tell. Pin the guidance to every login screen if you can.
Week 3 — MFA everywhere
Track and publish MFA adoption rates by department (aggregate, not individual). Give team leads a checklist of the top ten personal apps that support MFA — this is where the culture spreads home.
Week 4 — Password manager rollout
Provide the manager, provide the training, provide 30 minutes of paid time to set it up. Anything less will be under-adopted.
Messages that land
- "Three random words is stronger than eight scrambled characters."
- "MFA turns a stolen password into a failed login."
- "You can't remember 200 passwords. Your password manager can."
- "Reuse is the risk. One breach becomes every breach."
What to measure
- MFA enrolment percentage before, during, and after the campaign.
- Password manager active users as a proportion of the workforce.
- Reduction in password-reset ticket volume once the manager beds in.
- Reduction in weak or reused passwords surfaced by identity tooling.
Related resources
Turn this topic into a complete campaign
Safety Campaign Hub generates posters, toolbox talks, safety alerts, and digital displays around any topic in minutes.
Related resources
How to Run a Security Awareness Campaign
Turn dry security policies into engaging, measurable campaigns. Covers phishing, password hygiene, physical security, and reporting culture.
SecurityPhishing Awareness Campaign: How to Build One That Works
A step-by-step phishing awareness campaign — baseline simulations, teachable-moment messaging, reporting culture, and metrics that actually shift behaviour.
SecurityInsider Threat Awareness: Campaign Blueprint
Design an insider threat awareness campaign that raises signal without creating suspicion — warning signs, reporting channels, and a no-blame culture.