C2. Create Strong Credentials
Make passwords the system’s job, not anyone’s memory.
In plain language.
Here is the part that usually goes unsaid: you were never supposed to remember them.
“Use a long, unique password for every account” is correct advice and an impossible instruction. Nobody can do it — not your network administrator, not us. People aren’t failing this because they’re careless. They’re failing a task that was never one a person could perform.
So the practice is to stop assigning it to people. A password manager remembers. Two-step login means a stolen password isn’t enough on its own. Neither requires anyone to be vigilant on a Tuesday afternoon in October.
What’s different in a school.
This is the highest-return thirty minutes in the entire model, and it’s the reason C2 sits second rather than last. It is the one practice that keeps working when someone is tired, rushed, or new.
In a school the stakes concentrate in a few accounts: the student information system, the business office, and email. Email most of all — it’s the password-reset path for nearly everything else, which makes it the key to the whole building rather than one more door.
What this looks like in practice.
The same practice, told three ways — so a champion can pick the version they need this week.
Start with three accounts, not thirty
Turn on two-step login for the head of school, the bookkeeper, and whoever administers the student information system. Those three cover most of the realistic damage. A staff-wide rollout can follow once the champions have done it themselves and can answer questions from experience.
Passphrases beat passwords
Students consistently assume a good password looks like P@ssw0rd!. Show them why length beats symbols, and why a four-word passphrase is both stronger and easier. This is a fifteen-minute lesson that changes behavior for years.
One password manager for the household
The version families can act on: put the manager on the phone, start with email and banking, and let it generate from there. For an older relative, setting it up together is a visit worth making.
Turn on two-step login for email
Thirty minutes. Do email before anything else.
- Pick one password manager for the school. The free tiers are genuinely adequate.
- Enable two-step login on school email for the three highest-risk accounts.
- Use an authenticator app rather than text messages where the option exists.
- Check that lock screens are on for staff phones and laptops.
- Write down which accounts are done, so the next champion isn’t guessing.
Activities by grade band.
Each fits a single class period and needs no lab, no licence, and no prior technical background from the teacher.
Passphrase workshop. Students build four-word passphrases and compare them against “strong-looking” short passwords using a strength estimator. The counterintuitive result does the teaching.
Authentication factors, mapped. Students sort real login methods into knowledge, possession, and inherence, then argue which combinations resist which attacks. This is directly assessed material on both ISC2 CC and Security+, so the class period doubles as exam preparation.
The largest single-control effect measured
A Microsoft study of Azure Active Directory accounts found multi-factor authentication reduced the risk of account compromise by 99.22% across the population — and by 98.56% even when the password had already leaked. Very few security controls produce an effect that size.
Source: Microsoft research study, Azure Active Directory account population. Full reference list on the 4C overview.