Poor password practices are still behind a large proportion of successful attacks on small businesses. Not because businesses are careless, but because the habits that created the risk — reusing passwords, sharing credentials across services, keeping default logins — were formed before those risks were well understood. This guide covers the practical steps that make the most difference with minimal disruption.
Unique passwords and password managers
The single highest-impact change most small business owners can make is to use a unique password for every service. The reason is simple: data breaches happen constantly at third-party services — not necessarily yours, but the thousands of online services that store your email address and password. When a breach occurs and credentials are leaked, attackers run automated tools that try the same email and password combination across hundreds of popular services. If you reuse passwords, one breach can compromise many accounts.
A password manager makes unique passwords practical. It generates, stores, and fills in complex unique passwords for each service, so you only need to remember one strong master password. Reputable options include Bitwarden (free and open source), 1Password, and Dashlane. All of them encrypt the stored passwords before they leave your device.
For any service that holds financial, customer, or admin data — banking, accounting software, your hosting control panel, your website CMS — the password should be long (16+ characters), unique, and not based on any personal information. If you are generating a new password rather than using the password manager's generator, combine four or more random words rather than substituting characters in a dictionary word.
MFA and admin separation
Multi-factor authentication is covered in more detail in our MFA for Business Email guide, but the principle applies across all your business logins. Enable MFA on every service that offers it, prioritising email, hosting, banking, and any service with payment or customer data. An authenticator app (Google Authenticator, Microsoft Authenticator, Authy) is more reliable and secure than SMS codes.
Admin separation means not using your day-to-day login account for admin tasks. In WordPress, this means having a standard editor or author account for routine content work, and a separate admin account (with a different password and email address) for settings changes and plugin management. If the editor account is compromised through a phishing attack, the attacker does not automatically gain admin access to change settings or install plugins.
Shared access cleanup
Review who has login access to your critical business systems. Former staff, contractors, freelancers, and ex-partners sometimes retain access to hosting control panels, WordPress admin, social media accounts, or cloud services long after they stopped working with the business. A quarterly access review — comparing the current user lists in each service against your current staff and contractors — takes 20–30 minutes and removes a category of risk that is otherwise invisible.
- Use a password manager — Bitwarden is free and reliable.
- Enable MFA on all accounts with financial, customer, or admin access — use an authenticator app.
- Change any reused passwords immediately, starting with banking and hosting.
- Create a separate WordPress admin account for admin tasks, distinct from your daily editor login.
- Run an access review quarterly: check who can log into hosting, WordPress, social media, and cloud services.
- Remove access for former staff, ex-contractors, and anyone who no longer works with the business.
Most small teams can reduce login risk without buying a full security platform.
Open the free cyber tools hub