Account security is more than a strong password
A long password matters. Reusing the same password across accounts can let a breach at one service put other accounts at risk. Avoiding reuse is a practical first step.
Two extra protections
A password manager makes it easier to create and store a different strong password for every account. Turn on multi-factor authentication (MFA); a stolen password alone may then not be enough to sign in.
Where available, consider a passkey. It is tied to a specific service, unlike a password that can be reused elsewhere. Keep your recovery details current, too.
Start with your email and financial accounts. NIST: Good passwords, MFA, and passkeys.