Cyber Security Basics · Lesson 2 of 10
Quick answer: How to reduce account takeover risk with unique passwords, password managers, passkeys and multi-factor authentication.
Passwords protect email, Microsoft 365, banking, accounting systems, websites and cloud applications. They are also one of the most common routes into a business when they are weak, reused or stolen.
Why password reuse creates risk
If an employee uses the same password for multiple services, one breach can expose several accounts. Criminals routinely test stolen email addresses and passwords against other online services. Every important business account should therefore have a unique credential.
Use a password manager
A password manager stores credentials securely and can generate long, unique passwords. This is more practical than expecting employees to remember dozens of different passwords. Businesses should provide an approved approach rather than encouraging staff to save passwords in spreadsheets, shared notes or unprotected documents.
What about passkeys?
Passkeys are increasingly available as an alternative to traditional passwords. They can reduce the risk of phishing because the credential is tied to the genuine service rather than being something a user types into any page that looks convincing. Where a service supports passkeys, they are worth considering, particularly for important accounts.
Turn on multi-factor authentication
Multi-factor authentication, commonly called MFA or 2-step verification, requires an additional proof of identity. This may be an authenticator app, security key, device prompt or biometric check. MFA significantly reduces the value of a stolen password.
Which accounts should use MFA?
- Email and Microsoft 365 or Google Workspace.
- Online banking and payment services.
- Accounting and payroll systems.
- Website, domain and DNS administration.
- Cloud storage and CRM platforms.
- Remote access and VPN services.
- Password managers.
- Administrator accounts.
Do not approve unexpected authentication prompts
An MFA request that appears when you are not signing in should be treated as suspicious. Attackers sometimes send repeated prompts hoping a user will eventually approve one. Staff should only approve an authentication request when they have just initiated the login themselves.
Protect administrator accounts more strongly
Administrator accounts can make major changes to systems, so they should not be used for ordinary email and web browsing. Keep admin access separate, use strong authentication and review who holds those privileges.
What to do after this lesson
Review your ten most important online accounts. Confirm that each uses a unique password or passkey and that MFA is enabled. If passwords are being reused, change the highest-risk accounts first.
Frequently asked questions
Should employees write passwords down?
An approved password manager is normally a better business solution. The goal is to avoid reused, shared or easily exposed credentials.
Is MFA still needed if we use strong passwords?
Yes. MFA adds another layer of protection if a password is guessed, phished or exposed in a breach.
Are passkeys better than passwords?
Passkeys can provide stronger resistance to phishing and remove the need to type a reusable secret, but support varies by service. Use them where appropriate and continue protecting any remaining password fallback.
Useful UK guidance
Put the lesson into practice
39Security helps small businesses turn cyber security guidance into practical controls and owned actions.
- Take the free cyber security assessment
- View practical cyber security training dates
- Explore Cyber Essentials readiness support
- See managed cyber security services
- Read the small business cyber security FAQ