Passwords and multi-factor authentication (MFA): best practice
Simple rules that stop most account takeovers
Most breaches in small businesses start with a stolen or guessed password. A few habits make you a much harder target.
Passwords
- Use a password manager, such as 1Password or Bitwarden. It creates and remembers strong, unique passwords, so you don't have to.
- One password per account. Never reuse a password. If one site is breached, the others stay safe.
- Make them long. A passphrase of three or four random words is stronger and easier to type than a short, complex one.
- Avoid the obvious: birthdays, children's or pets' names, your company name, or "Password1".
- Never share a password, including with IT. We will never ask you for your password. Treat anyone who does as a scam.
- Don't write passwords down or leave them on sticky notes. Store them in the password manager.
Multi-factor authentication (MFA)
MFA adds a second check, such as an app prompt, a code or a security key, so a stolen password alone isn't enough to get in.
| Method | Strength |
|---|---|
| Security key (e.g. YubiKey) or passkey | ✅ Strongest. Resists phishing. |
| Authenticator app (Microsoft/Google Authenticator, 1Password) | 👍 Good |
| SMS text code | ⚠️ Better than nothing, but can be intercepted |
Unexpected MFA prompt? If your phone asks you to approve a sign-in you didn't start, tap Deny, change your password and report it straight away. Someone probably has your password.
If you think a password has been exposed
- Change it immediately, along with anywhere else you used the same one.
- Check MFA is switched on for that account.
- Raise a support ticket so we can check for suspicious sign-ins.