Home 9 Latest News 9 Your business’s passwords are still too weak

Your business’s passwords are still too weak

Be honest. Do you still have at least one password that looks like “12345” or “password123”?

If so, you’re not alone.

But that doesn’t mean it’s OK.

Despite years of warnings from IT experts (people like me), weak passwords are still everywhere. And that’s a real problem. Because they’re one of the easiest ways for cyber criminals to break into your business systems.

You’d be amazed how many companies are still using passwords that can be cracked in less than a second.

Recent research found that the most common business password is still “123456”.

Right behind it? “123456789”, “password”, and even the ever popular “qwerty123”.

These aren’t just lazy choices. They’re open doors for hackers.

What’s worse, it’s not just huge enterprises that are getting this wrong. Small and medium sized businesses are guilty too. And they’re often hit harder when things go wrong, because they don’t always have the same resources to recover.

A single stolen password can let an attacker access your email, files, financial systems, or even customer data.

The damage? It can be serious. Both financially and to your reputation.

You might think, “But we don’t have anything worth stealing.” Trust me, you do. Even if you’re a team of five, your accounts, client data, and communications are all valuable targets. Cyber criminals don’t discriminate. They go for easy wins. And weak passwords are the easiest win there is.

Now here’s the kicker: Even if you’re not using “123456”, that doesn’t necessarily mean your passwords are secure. The research also found people using their own email address or their name as a password (eye roll). Some even used phrases like “iloveyou”.

It’s all very sweet… until a cyber criminal uses it to get into your systems.

So… what can you do to protect your business?

Start by making sure everyone uses strong, unique randomly generated passwords. That means longer phrases with a mix of letters, numbers, and symbols. Nothing predictable.

Nobody wants to remember 30 complex passwords. That’s where a password manager comes in. It can create super strong passwords for every login and store them securely, so your team doesn’t have to rely on memory (or sticky notes).

Better still, consider enabling two-factor authentication. That’s the thing where you get a code on your phone or app when logging in. Even if someone does steal a password, they can’t get in without that second code. It’s one of the easiest and most effective ways to add a layer of protection.

And if you want to future-proof your security, look at passkeys. These are a new way to log in without traditional passwords at all. Using biometrics like fingerprint or facial recognition, or secure device-based authentication. It’s safer and simpler, and it’s quickly becoming the new standard.

At the end of the day, strong passwords—or better, password alternatives—are your first line of defence. Don’t wait for a security scare to take them seriously. If your team is still using “abc123”, now’s the time for a change.

Need a hand reviewing your password policy or setting up a secure login system for your team? My team and I would love to help. Get in touch.

Recent Posts

Cyber Security Is Not Your Job. Understanding Business Risk Is.

Cyber Security Is Not Your Job. Understanding Business Risk Is.

Many business owners switch off the moment cyber security enters the conversation. They picture firewalls, software updates, security alerts and technical jargon. It feels like something that belongs firmly in the hands of IT professionals. The reality is very...

Cyber Confidence Guide and checklist.

Cyber Confidence Guide and checklist.

Welcome to the Cyber Confidence Guide Cyber security is no longer just an IT concern. It is a business priority. Whether your organisation has five employees or five hundred, protecting your systems, data and people is essential to maintaining trust, productivity and...

The 30-Minute IT Health Check Every Small Business Should Do

The 30-Minute IT Health Check Every Small Business Should Do

The 30-Minute IT Health Check Every Small Business Should Do Monthly Most IT problems don't appear out of nowhere. Backups quietly stop running, updates sit unfinished for weeks and old staff accounts stay active long after someone has left the business. A simple...

What Are Passkeys, and Should Your Business Use Them?

What Are Passkeys, and Should Your Business Use Them?

Cybersecurity made simple Passkeys: The Safer, Simpler Way to Sign In Without Passwords Passwords have been causing businesses problems for years. They get reused, forgotten, guessed, leaked, written down, shared, and typed into fake login pages by mistake. Passkeys...

How are cyber attacks effecting your insurance?

How are cyber attacks effecting your insurance?

Cyber Insurance Renewal: What’s Changed and How to Avoid Claim Denial If your cyber insurance renewal feels harder this year, you’re not alone. Right now, many businesses are facing longer forms, tougher questions, and more pressure to prove their security. As a...

Could Someone Send Emails Pretending To Be Your Business

Could Someone Send Emails Pretending To Be Your Business

Cyber Security Guide Could Someone Send Emails Pretending To Be Your Business? Email spoofing is one of the simplest ways scammers can damage trust in your business. The good news is that three DNS records — SPF, DKIM and DMARC — can make it much harder for criminals...

Continuous Digital Transformation Partnerships

Continuous Digital Transformation Partnerships

Continuous Digital Transformation Partnerships Why outsourcing is no longer about handing work off, but moving forward together For many organisations, change never really stops. You upgrade one system, and another starts to fall behind. You move to the cloud, and...

5 Microsoft 365 Settings You Should Check Today

5 Microsoft 365 Settings You Should Check Today

5 Microsoft 365 Settings You Should Check Today (Especially if Your Setup Is a Few Years Old) If your Microsoft 365 system was set up a few years ago, there’s a good chance it’s not as secure as you think. Microsoft has improved security defaults over time. But those...

Could a Cyber Criminal Send Emails Pretending to Be You?

Could a Cyber Criminal Send Emails Pretending to Be You?

Could a Cyber Criminal Send Emails Pretending to Be Your Company Today? Imagine one of your customers receives an email from what appears to be your accounts department. The branding looks correct. The signature looks genuine. The email address seems legitimate. The...