My e-mail address was found in yet another data breach recently. This time on a site named ToonDo. I'm not overly concerned about this since that site does not contain critical data about me, but more importantly: I do not use the same password anywhere else. I only have to change it there.
Still, I talk to people almost daily who use the same password on multiple websites. Taking the time to move away from this practice appears overwhelming for many people.
I wrote this post a couple of years back to help with this. If you're struggling with password management, maybe you can schedule time in your calendar, over a weekend or at least over the holidays, to think more about how you want to handle your passwords?
If you are an employer or manage a team, then do set aside time to go through these issues in a controlled setting. Not after the breach happens.