Passwords are the keys to your business, and most people carry too few keys for too many doors. The two biggest problems are passwords that are simple to guess and the same password used in lots of places. When one website is breached, attackers take those leaked passwords and try them everywhere else, which is why reuse turns one small leak into a big problem.
Length beats complexity
A long passphrase of a few random words is both stronger and easier to remember than a short jumble of symbols. The current NCSC advice of stringing together three random words is a good, human way to make a strong password.
Never reuse passwords for important accounts
Your email, banking, and main business logins should each have their own unique password. Email especially, because whoever controls your email can reset the password on almost everything else.
Use a password manager
A password manager creates and remembers a strong, different password for every account, so you only need to recall one master password. It removes the impossible job of memorising dozens of unique logins, which is the real reason people reuse them.
Assume some of yours have already leaked
Data breaches are constant, and old passwords circulate widely. If you have used the same password across sites for years, treat it as already exposed and change it on your important accounts first.
Change a password when there is a reason, not on a timer
Forcing frequent changes just pushes people toward weak, predictable patterns. Modern advice is to use strong unique passwords, and change one promptly if you suspect it has been exposed or a service reports a breach.
Red flags to watch for
- The same password used for email, banking, and business tools.
- Passwords based on the business name, a date, or something on your desk.
- Common choices like Password1, Welcome123, or the season and year.
- Passwords written on a note stuck to the monitor or shared in a group chat.
- A short password of eight characters or fewer on an important account.
- One member of staff's login shared between several people.
Check yourself
0/41.Which of these is the strongest and most practical password for your work email?
2.Why is reusing the same password across several sites so risky?
3.What is the main benefit of using a password manager?
4.Which account is most important to protect with a strong, unique password?
This is general guidance, not a substitute for advice on your specific setup. Want a hand putting it into practice? Talk to us or see our care plans.
