Skip to content
English
  • There are no suggestions because the search field is empty.

Passwords and multi-factor authentication (MFA): best practice

Simple rules that stop most account takeovers

Most breaches in small businesses start with a stolen or guessed password. A few habits make you a much harder target.

Passwords

  1. Use a password manager, such as 1Password or Bitwarden. It creates and remembers strong, unique passwords, so you don't have to.
  2. One password per account. Never reuse a password. If one site is breached, the others stay safe.
  3. Make them long. A passphrase of three or four random words is stronger and easier to type than a short, complex one.
  4. Avoid the obvious: birthdays, children's or pets' names, your company name, or "Password1".
  5. Never share a password, including with IT. We will never ask you for your password. Treat anyone who does as a scam.
  6. Don't write passwords down or leave them on sticky notes. Store them in the password manager.

Multi-factor authentication (MFA)

MFA adds a second check, such as an app prompt, a code or a security key, so a stolen password alone isn't enough to get in.

Method Strength
Security key (e.g. YubiKey) or passkey ✅ Strongest. Resists phishing.
Authenticator app (Microsoft/Google Authenticator, 1Password) 👍 Good
SMS text code ⚠️ Better than nothing, but can be intercepted

Unexpected MFA prompt? If your phone asks you to approve a sign-in you didn't start, tap Deny, change your password and report it straight away. Someone probably has your password.

If you think a password has been exposed

  1. Change it immediately, along with anywhere else you used the same one.
  2. Check MFA is switched on for that account.
  3. Raise a support ticket so we can check for suspicious sign-ins.