Simple passwords like "123456" or common identification details like birthdays and nicknames are not secure for protecting important accounts containing personal data.
There's a common myth that passwords should be changed at specific intervals. However, this isn't recommended, as frequent changes can lead to weaker passwords being used or old passwords being reused.
Of course, it is also recommended to use password management software.
Below are some recommendations from the american cybersecurity agency CISA for creating a secure password. A secure password should meet all three criteria:
1 - Password length
A secure password should be at least 16 characters long – the longer the password, the more secure it is.
2 - Random strings or passphrases
Use random strings consisting of lowercase letters, uppercase letters, characters, and numbers. For example:
cXmnZK65rf*&DaaD
Yuc8$RikA34%ZoPPao98t
Alternatively, you can use so-called "passphrases." These consist of non-contiguous words, characters, and numbers. For example:
4BlueHorseGlove!packaged
Walnut70Silver_Slipper
3 - Don't reuse
As a general rule, you should use a different password for each account. For example:
internex: cXmnZK65rf*&DaaD
Bank: 4BlueHorseGlove!packaged
Email Address: Walnut70Silver_Slipper