Home 9 Latest News 9 Your business’s passwords are still too weak

Your business’s passwords are still too weak

Be honest. Do you still have at least one password that looks like “12345” or “password123”?

If so, you’re not alone.

But that doesn’t mean it’s OK.

Despite years of warnings from IT experts (people like me), weak passwords are still everywhere. And that’s a real problem. Because they’re one of the easiest ways for cyber criminals to break into your business systems.

You’d be amazed how many companies are still using passwords that can be cracked in less than a second.

Recent research found that the most common business password is still “123456”.

Right behind it? “123456789”, “password”, and even the ever popular “qwerty123”.

These aren’t just lazy choices. They’re open doors for hackers.

What’s worse, it’s not just huge enterprises that are getting this wrong. Small and medium sized businesses are guilty too. And they’re often hit harder when things go wrong, because they don’t always have the same resources to recover.

A single stolen password can let an attacker access your email, files, financial systems, or even customer data.

The damage? It can be serious. Both financially and to your reputation.

You might think, “But we don’t have anything worth stealing.” Trust me, you do. Even if you’re a team of five, your accounts, client data, and communications are all valuable targets. Cyber criminals don’t discriminate. They go for easy wins. And weak passwords are the easiest win there is.

Now here’s the kicker: Even if you’re not using “123456”, that doesn’t necessarily mean your passwords are secure. The research also found people using their own email address or their name as a password (eye roll). Some even used phrases like “iloveyou”.

It’s all very sweet… until a cyber criminal uses it to get into your systems.

So… what can you do to protect your business?

Start by making sure everyone uses strong, unique randomly generated passwords. That means longer phrases with a mix of letters, numbers, and symbols. Nothing predictable.

Nobody wants to remember 30 complex passwords. That’s where a password manager comes in. It can create super strong passwords for every login and store them securely, so your team doesn’t have to rely on memory (or sticky notes).

Better still, consider enabling two-factor authentication. That’s the thing where you get a code on your phone or app when logging in. Even if someone does steal a password, they can’t get in without that second code. It’s one of the easiest and most effective ways to add a layer of protection.

And if you want to future-proof your security, look at passkeys. These are a new way to log in without traditional passwords at all. Using biometrics like fingerprint or facial recognition, or secure device-based authentication. It’s safer and simpler, and it’s quickly becoming the new standard.

At the end of the day, strong passwords—or better, password alternatives—are your first line of defence. Don’t wait for a security scare to take them seriously. If your team is still using “abc123”, now’s the time for a change.

Need a hand reviewing your password policy or setting up a secure login system for your team? My team and I would love to help. Get in touch.

Recent Posts

Messaging app scams are rising.

Messaging app scams are rising.

Messaging app scams are rising. Here’s what businesses need to know. Messaging app scams are becoming a growing risk for businesses of all sizes. Tools like WhatsApp, Microsoft Teams, Signal, and SMS are used every day to keep work moving, but criminals are now using...

Why Passwords Are Still Letting Businesses Down

Why Passwords Are Still Letting Businesses Down

Why Passwords Are Still Letting Businesses Down Most businesses still rely on passwords to protect their systems. However, that approach no longer fits the way people work. Some passwords are strong. Many aren’t. Worse still, people reuse most of them somewhere else....

The hidden cyber risk in everyday web habits

The hidden cyber risk in everyday web habits

The hidden cyber risk in everyday web habits Most cyber attacks don’t start with advanced hacking. They start with everyday behaviour that feels harmless at the time. When work and personal life share the same devices, browsers, and logins, small habits can quietly...

AI at Work: Why People Still Matter More Than Ever

AI at Work: Why People Still Matter More Than Ever

AI at Work: Why People Still Matter More Than Ever   The problem many businesses are feeling   Right now, a lot of people feel uneasy about AI at work. Some worry it might replace jobs. Others feel pressure to keep up with tools they do not fully understand....

Why Multi Factor Authentication isn’t enough!

Why Multi Factor Authentication isn’t enough!

Adversary‑in‑the‑Middle Attacks: Why MFA Alone Isn’t Enough You click a link, sign in, approve the MFA prompt, and get on with your day. Completely unaware that someone else just logged into your account at the same moment. That scenario surprises many organisations,...

AI in IT Operations and Automation

AI in IT Operations and Automation

AI in IT Operations and Automation: What’s Real and What’s Just Hype AI is everywhere right now. Every tool claims to be “AI‑powered”. Every vendor promises faster fixes, fewer issues, and smarter IT. It can all start to sound impressive and confusing at the same...

Why “break‑fix IT” costs more than managed support

Why “break‑fix IT” costs more than managed support

Why “break‑fix IT” costs more than managed support When something breaks, you call IT. When it’s fixed, you pay the bill. On the surface, break‑fix IT feels sensible. You only pay when you need help. No monthly commitment. No long contracts. It can feel like the...