Half of what your students know about passwords is out of date, and so is a lot of what the rest of us were taught. Three complete lessons on what actually holds: why length beats symbols, why a second step is not a finished job, and what order to fix things in when an account is taken.
● Instant download · Lifetime access · Editable & print-ready
Change it every month. Make sure it has a symbol. The 2025 standard dropped both, and most classroom material has not caught up. This unit was rebuilt on it. Students learn why length and being uncommon do more work than symbols: a careful site stores salted hashes rather than passwords, so a stolen file still has to be cracked by guessing.
How Passwords Get Cracked, Proving It's Really You, Taking an Account Back. Day 2 sorts sign-in setups into password only, can be bypassed, and phishing-resistant — a texted code and a push with no number to match land in the middle, and a passkey or a physical key lands at the end. Day 3 is the one nobody teaches: what the attacker still has after the password changes, and what order to fix it in.
This is the defense half of the cybersecurity line. Phishing covers how someone talks you out of a password and Cyber Attacks covers what gets onto the device — this is the only unit about setting the account up so it survives, which is why it works either as a follow-on or entirely on its own.
A volunteer's phone fills with sign-in approval requests she never started. Late at night she taps Yes to make them stop, and the pantry's email is gone. Students say what those requests prove about the password, why the second step did not stop the attacker anyway, and name one change that would have — number matching, a passkey or a security key. Two pages, six points, keyed.
Page one of four real files out of the download, exactly as they print.
Twelve to thirteen slides a day, low text, with the diagrams drawn as real vector shapes rather than flat images. Recolor them to match your room, or delete any of them.
A two-page packet per day with a word bank at the top and real room to write. Editable Word and print-ready PDF, and every one has a complete key.
Two long-form cases about organizations that do not exist. Students name what the attacker still had after the password changed, say why the email had to be fixed first, and defend the order.
Six items, three options and a line for the reason. Day 1's sign-up page has three rules that are already right, so a student who deletes everything loses points. The answer boxes are on the same page — nothing to cut out, laminate or post.
Symbols and numbers beat a long simple password — that is the belief in the room, and it is wrong. Length and being uncommon usually do more work.
Rebuilt on the 2025 password guidance, which dropped forced symbols and scheduled changes. Most classroom material still teaches the rules that were retired.
Every written question ships with what to look for, a model response, what else to accept, and what to reject.
Five minutes of bell ringer, 14 of slides and notes, 19 of activity, 7 for the exit ticket. The pacing gate puts each day at 39 to 40 minutes of work.
Written for a general-education class. Nothing to prepare beyond hitting print, and every day stands alone as a sub plan.
No activity asks a student to type or share a real password, including into an online strength checker, and no page names a real password manager, authenticator app, bank or phone company.
Reviews help me a lot, and they help other teachers pick the right resources for their classes. It takes about a minute.
Leave a reviewInstant download right after checkout. You get editable PowerPoint and Word, print-ready PDF of everything, and the links for the self-grading Google Forms™.
No. This is a general-education digital-literacy unit written for a teacher who has never taught the subject. The READ FIRST guide says exactly what to print and when, and every page has a key.
No. No activity asks a student to type or share a real password, including into an online strength checker, and no page names a real password manager, authenticator app, bank or phone company. The unit teaches defense and deliberately does not explain how any attack is carried out.
No. Each day's activity is one printed sheet, two pages and seven points, with the answer boxes on the same page the student writes on. Students work it alone first, then check with one partner. There is nothing to cut, laminate, post or store between classes.
It sits after the three lessons, not inside them. The quiz is 28 points and about 25 minutes, and all three periods are full lessons. Run it as a Day 4 in class or set it as a take-home with the Google Form. Either way you already have a grade for every student from the three exit tickets.
The Skills Map names the standards that match rather than claiming alignment: 2026 CSTA HS-SYS-SE-31, HS-SYS-SE-32 and HS-SYS-SE-33, with the 2017 codes beside them wherever CSTA's crosswalk maps one; Common Core RI, W and SL for grades 9-10 and 11-12; and ISTE 1.2.d. A Convert to YOUR State's Standards page is included.
Yes. The Cybersecurity Unit Bundle holds this unit plus Phishing & Social Engineering, Deepfakes & AI Scams, Cyber Attacks & Malware, and Encryption & Cryptography — 17 days in one download, for less than the five bought separately.