Content reviewed and updated 15 September 2026. Password security is not a yearly reminder to add another symbol. It is a combination of unique credentials, safer authentication and a reliable way to spot and report unexpected requests. A fake support caller may ask you to enter a code or approve a sign-in rather than reveal a password. Staff need an established way to verify that request, not just a rule to make passwords complicated. Start with business email, administrator accounts and the password manager itself. These are important access points to protect and recover. Use a different password for each account.A managed password manager can help Prefer phishing-resistant MFA where supported.Genuine passkeys are not ordinary passwords Check unexpected setup requests independently.Use your established support route Practical habits, not a guarantee against account compromise. A password exposed at one service should not unlock another. Find and replace reused business credentials, starting with privileged and email accounts. Make unique passwords manageable for staff. Agree company ownership, access controls and recovery arrangements rather than relying on personal vaults. Use long, unique generated passwords or suitable passphrases. Avoid predictable substitutions, company names and seasonal patterns. Follow the service’s supported requirements. Use phishing-resistant methods where the service supports them. Prioritise administrators and sensitive accounts. Check the actual method and policy rather than assuming all MFA is equivalent. Do not approve sign-ins or enter codes because an unsolicited caller asks. End the conversation and contact your usual support number. A familiar sign-in page does not prove the request is authorised. Respond promptly to suspected compromise. NIST advises against arbitrary periodic password changes. Review policies with IT instead of treating 90-day rotation as a universal security improvement. Recovery email, phone numbers and spare factors matter too. Keep them current and ensure the business can recover important accounts if an employee is unavailable. Use named accounts and delegated permissions where possible. Where a shared credential is unavoidable, control it through the approved manager and review who can retrieve it. Permissions should follow the current job. Include leavers, contractors, privileged roles and shared credentials in the access review. A quick report is more useful than blame. Tell staff exactly how to report a suspicious prompt or mistaken approval. Preserve the message and approximate time for investigation. NIST: Digital Identity Guidelines, authentication and passwords Review identity, access and authentication controls with ITFR.A clever password cannot fix an unsafe request

Ten checks for your business
1. Stop password reuse
What to check
2. Use an approved manager
What to check
3. Choose length over patterns
What to check
4. Add stronger authentication
What to check
5. Verify unexpected requests
What to check
6. Reset for a reason
What to check
7. Protect recovery routes
What to check
8. Share access, not secrets
What to check
9. Remove access when roles change
What to check
10. Make reporting easy
What to check
Sources & further reading
Are your sign-in and recovery controls joined up?
Business Password Security: Ten Practical Checks
Unique passwords are only one part of safe sign-in. Review password managers, passkeys, recovery routes and unexpected authentication requests.

LESS REUSE, BETTER CONTROL
Unique
Resistant
Verified








