Every year I update my passwords. That is a lot easier than it sounds.
I use a password manager to create a different nonsense password at every site I register. But I need 3 that I remember; my master password (for Lastpass.com), one for logging into my computers, and another for my phone.
For the phone, I usually use old numbers from my childhood (my address number on Cordova Road, for example). But for the other two, I use abbreviations of quotes.
For example
Best if you have all four elements: Uppercase, Lowercase, numbers, symbols. For example, (not a quote) you could make a password out of that last sentence. Biyha4e:U,L,n,s. Need more help?
Here is a short video too.
For even more security, if you use Lastpass, you can limit the countries where you log in from (be careful to reset before traveling).
And more important, you can set up Two Factor Authentication (2FA) for your main sites (I do it with Google, Evernote, Facebook and Microsoft. But more about that in another post.