- VoIP & Phone Systems
VoIP Features: Call Recording, Auto Attendant & More
12 Apr, 2026
Test how strong your password is against common attack methods. Real-time analysis with entropy scoring, crack-time estimates, and improvement suggestions.
Your password never leaves your browser. All analysis runs locally in JavaScript — nothing is sent to any server.
This tool runs entirely in your browser. Your password is never transmitted, stored, or logged. You can verify this by disconnecting from the internet — the tool will still work.
| Recommendation | Details | Why It Matters |
|---|---|---|
| Minimum Length | At least 12 characters | Length is the single biggest factor in password strength |
| No Complexity Rules | Don’t force symbols/numbers | Forced complexity leads to predictable patterns like P@ssw0rd |
| Use Passphrases | Three or more random words | Easier to remember, harder to crack than short complex passwords |
| Check Against Breaches | Block known compromised passwords | Millions of passwords are publicly available from data breaches |
| Multi-Factor Authentication | Enable MFA on all accounts | Even a strong password isn’t enough if credentials are phished |
| Password Manager | Use one for all accounts | Allows unique, long passwords without memorisation burden |
| No Forced Rotation | Only change if compromised | Regular rotation encourages weak, incremental password changes |
| Account Lockout | Throttle after failed attempts | Prevents online brute-force attacks against login pages |
Based on the UK National Cyber Security Centre (NCSC) password guidance. Contact Cloudswitched for help implementing password policies and MFA across your organisation.
Try our other free security assessments and IT planning tools.
Length matters more than complexity — a 14+ character passphrase of unrelated words typically resists brute-force attacks far better than a short password with symbols. Avoid dictionary words, personal details, and reused passwords across accounts, since credential stuffing from data breaches remains one of the most common attack methods.
A short password using only lowercase letters can often be brute-forced in seconds to minutes with modern hardware, while an 8-character mixed-case password with numbers might take hours to days. A properly random 14+ character passphrase can push cracking time into centuries, which is why length is the single biggest factor.
Yes — password managers let staff use unique, complex passwords for every account without needing to remember them, which directly reduces the risk from credential reuse and phishing. Most UK SMEs adopt a business password manager (typically £2-£5 per user monthly) alongside multi-factor authentication.
Yes — even strong passwords can be exposed through phishing, breaches, or malware, and MFA blocks the vast majority of account takeover attempts even when a password is compromised. This checker tests password strength alone, but MFA should be treated as a mandatory second layer, not optional.
Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.