The HaveIBeenPwned database contains over 12 billion compromised credentials. Your employees' email addresses and passwords are almost certainly in there — either from a data breach at a service they use, or from a company that stored passwords insecurely.
This isn't hypothetical. Credential stuffing attacks — where attackers take leaked username/password combinations and try them against other services — are automated, cheap, and devastatingly effective when people reuse passwords.
Password security training isn't about teaching people to make complex passwords. It's about changing the underlying behaviour: unique credentials for every account, stored in a password manager.
What the Training Needs to Cover
Why password reuse is the real problem. Most people understand that weak passwords are bad. Fewer understand that a strong password reused across multiple accounts is nearly as dangerous. If one service you use is breached and your credentials are leaked, every other account using those credentials is now compromised. Credential stuffing is the primary mechanism by which "I was breached at LinkedIn" becomes "my work email was compromised."
How password managers work. The reason people reuse passwords is that unique, strong passwords are impossible to remember at scale. A password manager solves this: one strong master password protects a vault of unique, randomly generated credentials for every site. Options like 1Password, Bitwarden (open source, free tier available), and Dashlane are well-established.
Many businesses hesitate to mandate password managers because of the upfront effort. The training needs to address this directly: the time investment to set up a password manager is a one-time cost. The alternative — a breach that exposes customer data and requires breach notification — costs orders of magnitude more.
Multi-factor authentication (MFA). Even a strong, unique password can be compromised through phishing. MFA adds a second factor — an authenticator app code, a hardware key, or an SMS code (in order of security) — that means a stolen password alone isn't sufficient to access the account. Training should cover: what MFA is, how to set it up on key accounts, and which accounts matter most (email first, then anything with financial access or sensitive data).
What to do when credentials are compromised. Employees need to know how to check if their credentials have been exposed (HaveIBeenPwned is the standard tool), what to do if they find an exposure, and who to notify at work if they suspect their work credentials are affected.
Common Training Mistakes
Focusing on password complexity rules rather than password managers. "Your password must be 12 characters with uppercase, lowercase, number, and special character" creates passwords like "Password123!" — technically compliant, practically weak. Teaching people to use a password manager and generate random credentials is more effective.
Not providing a recommended tool. If you train people on password managers but don't specify which one the business recommends and supports, you get fragmented adoption. Pick one, procure it at a business level if budget allows, and make the recommendation explicit.
One-and-done training. Password security training needs reinforcing. When a major breach is announced (which happens regularly), send a short reminder module. When you roll out MFA on a new system, tie a training refresher to the rollout.
SecureAZ's password security module covers credential hygiene, password manager setup, MFA activation, and breach response in a single 12-minute module — with a quiz and certificate on completion.