Everyone knows they should have better passwords. Almost nobody wants to sit through a lecture about it. So here's the short version: the handful of things that actually matter, and how to sort them in about fifteen minutes.
Get a password manager. This is the one that changes everything. It's an app that remembers all your passwords so you don't have to. You memorise one strong password to unlock it, and it handles the rest: generating long, unique passwords for every account and filling them in for you. Suddenly "different password for everything" goes from impossible to automatic.
Go long, not weird. A passphrase like purple-canoe-battery-fence
is both easier to remember and harder to crack than P@ssw0rd1. Length beats
complexity. (Once you've got a password manager, it'll make these for you anyway.)
Never reuse the important ones. When one website gets breached, and they do constantly, attackers try that same password everywhere else. Reuse means one leak unlocks your whole life. This is the real reason the password manager matters.
Turn on multi-factor authentication (MFA), starting with your email. MFA adds a second step, a code or a tap on your phone, so a stolen password isn't enough on its own. Your email is the master key to almost everything (it's where password resets go), so protect it first.
Check if you've already been caught up in a breach. Pop your email address into haveibeenpwned.com: it'll tell you if it's turned up in a known leak, which is a good prompt to change those passwords.
Your 15 minutes: install a password manager (5 minutes), change your email password to a strong, unique one and switch on MFA (5 minutes), then let the manager flag your reused passwords and fix the worst two or three (5 minutes). That's it, you're now ahead of most organisations your size.
Want a hand rolling a password manager out across your team, or setting a simple policy everyone will actually follow?