Password Hygiene for Small Offices: A No-Nonsense Guide
Most small-office breaches start with a reused or shared password. Six rules that matter, three that do not, and how to roll them out without a revolt.
Small offices rarely get hacked by clever attackers breaking encryption. They get caught because someone reused a password that leaked from another site, or because five people share one login and one of them left a year ago. Password hygiene is not about complexity rules. It is about a handful of habits that close the doors attackers actually use.
The six rules that matter
- One password per service, never reused. When any website you have ever used is breached, attackers try the same email and password everywhere else. Reuse is the single biggest risk, far bigger than a weak password.
- Use a password manager. Nobody can remember forty unique passwords. A reputable manager generates them, stores them encrypted and fills them in. It turns rule one from impossible into automatic.
- Long beats clever. For the few passwords you must remember (the manager itself, your computer), use a passphrase of four or five unrelated words. Length does more than symbols.
- Turn on two-factor authentication everywhere it exists, starting with email, because email resets every other password. Prefer an authenticator app or a hardware key over text messages where the service offers them.
- No shared accounts. Every person gets their own login. Shared logins make it impossible to know who did what, and impossible to remove one person's access when they leave.
- Remove access on the day someone leaves. Not the next week. Keep a list of the services each person uses so that offboarding is a checklist rather than a memory exercise.
Three rules you can drop
- Forced changes every 90 days. They push people towards predictable patterns (Spring2024!, Summer2024!). Change a password when there is a reason to: a breach, a suspicion, a departure.
- Complexity puzzles. Requiring one capital, one digit and one symbol produces passwords that are hard to remember and easy to guess. Length and uniqueness matter more.
- Security questions with true answers. Your mother's maiden name is public. If a service insists, treat the answer as another random password and store it in the manager.
Rolling it out without a revolt
Start with the owner or manager, because people follow what leaders do. Pick one password manager for the office and pay for the business version, so shared credentials that genuinely must be shared (a supplier portal, say) live in a shared vault with access you can revoke. Give everyone an hour to move their work passwords into it, and sit with the people who are nervous. Then turn on two-factor, email first.
Check your email first
If you do only one thing this week, make sure every work email account has a unique password and two-factor turned on. Email is the key to everything else: whoever controls it can reset passwords, read client correspondence and impersonate you. Offices that treat email as a filing system have even more to lose, because years of records sit behind that one login.
What to do when something leaks
Change the affected password, then every other service where it was reused, then check the account for forwarding rules or connected apps you did not set up. Note what happened and when. The same care you apply to sensitive client records, like the applicant documents in tenant screening records, depends on the accounts that guard them.