IT First Responder home
IT First Responder home

Business Password Security: Ten Practical Checks

Unique passwords are only one part of safe sign-in. Review password managers, passkeys, recovery routes and unexpected authentication requests.

Password Management

Content reviewed and updated 15 September 2026.

LESS REUSE, BETTER CONTROL

A clever password cannot fix an unsafe request

Password security is not a yearly reminder to add another symbol. It is a combination of unique credentials, safer authentication and a reliable way to spot and report unexpected requests.

A fake support caller may ask you to enter a code or approve a sign-in rather than reveal a password. Staff need an established way to verify that request, not just a rule to make passwords complicated.

Start with business email, administrator accounts and the password manager itself. These are important access points to protect and recover.

Isometric Password And Account Security Illustration.
THREE HABITS THAT SCALE
Unique

Use a different password for each account.A managed password manager can help

Resistant

Prefer phishing-resistant MFA where supported.Genuine passkeys are not ordinary passwords

Verified

Check unexpected setup requests independently.Use your established support route

Practical habits, not a guarantee against account compromise.

Ten checks for your business

1. Stop password reuse

A password exposed at one service should not unlock another.

What to check

Find and replace reused business credentials, starting with privileged and email accounts.

2. Use an approved manager

Make unique passwords manageable for staff.

What to check

Agree company ownership, access controls and recovery arrangements rather than relying on personal vaults.

3. Choose length over patterns

Use long, unique generated passwords or suitable passphrases.

What to check

Avoid predictable substitutions, company names and seasonal patterns. Follow the service’s supported requirements.

4. Add stronger authentication

Use phishing-resistant methods where the service supports them.

What to check

Prioritise administrators and sensitive accounts. Check the actual method and policy rather than assuming all MFA is equivalent.

5. Verify unexpected requests

Do not approve sign-ins or enter codes because an unsolicited caller asks.

What to check

End the conversation and contact your usual support number. A familiar sign-in page does not prove the request is authorised.

6. Reset for a reason

Respond promptly to suspected compromise.

What to check

NIST advises against arbitrary periodic password changes. Review policies with IT instead of treating 90-day rotation as a universal security improvement.

7. Protect recovery routes

Recovery email, phone numbers and spare factors matter too.

What to check

Keep them current and ensure the business can recover important accounts if an employee is unavailable.

8. Share access, not secrets

Use named accounts and delegated permissions where possible.

What to check

Where a shared credential is unavoidable, control it through the approved manager and review who can retrieve it.

9. Remove access when roles change

Permissions should follow the current job.

What to check

Include leavers, contractors, privileged roles and shared credentials in the access review.

10. Make reporting easy

A quick report is more useful than blame.

What to check

Tell staff exactly how to report a suspicious prompt or mistaken approval. Preserve the message and approximate time for investigation.

Sources & further reading

NIST: Digital Identity Guidelines, authentication and passwords

Microsoft: Authentication strengths

How fake passkey setup scams workClose access when staff leave

Are your sign-in and recovery controls joined up?

Review identity, access and authentication controls with ITFR.

Explore identity security

Useful IT ideas, straight to your inbox

Get the monthly ITFR Insights newsletter. Unsubscribe any time.

Choose interests (optional)
What interests you?

Privacy policy