Passwords are still the front door to most of your accounts, and weak or reused ones are behind a large share of breaches. Two habits fix most of the risk: unique passwords and multi-factor authentication.
Use a long, unique password for every account
About 73% of passwords are duplicates, which means one leak can unlock several of your accounts. Give every account its own password. Longer is stronger, so favor a passphrase of several words over a short, complex string you cannot remember. Do not write passwords on notes near your desk, where anyone passing by can read them.
Use a password manager
Nobody can remember a different long password for dozens of accounts, and you should not try. A password manager stores them in an encrypted vault and fills them in for you. You remember one strong master password, and it handles the rest. We can help you roll one out across your team.
Turn on multi-factor authentication
Multi-factor authentication (MFA) asks for a second proof of identity after your password, usually a code or a tap on your phone. Even if someone steals your password, they cannot get in without that second step. Turn it on for email, banking, remote access, and any account that holds sensitive data.
Choose stronger MFA where you can
Not all MFA is equal. Text-message codes are better than nothing, but they can be intercepted. In late 2020, Microsoft urged people to move off phone-based codes and use an authenticator app or a physical security key instead. Those options are harder to bypass, and we can set them up for your organization.
Lock down administrator accounts
Administrator accounts are a top target, because they can change settings and create new accounts. Removing admin rights from everyday user accounts would prevent an estimated 98% of critical Windows vulnerabilities from being exploited. Give people only the access their job needs, and keep separate accounts for administrative work.
Quick checklist
- Every account has its own long password.
- A password manager holds them, not sticky notes.
- MFA is on for email, banking, and remote access.
- MFA uses an app or security key rather than text messages where possible.
- Daily work happens on standard accounts, not admin accounts.
Want help putting this in place? Call Robb Technology Group at (806) 370-4700 or email support@robb.tech.
Related Articles
Set Up Multi-Factor Authentication (MFA)
Multi-factor authentication (MFA) adds a second check when you sign in, so a stolen password alone will not get someone into your account. We recommend the Microsoft Authenticator app. Here is how to set it up. Step 1: Install the app on your phone ...
Password Best Practices
Strong passwords are one of the simplest ways to protect your accounts and your company. These habits make a real difference. Length beats complexity A long password is harder to crack than a short, complicated one. Use a passphrase of several ...
Cybersecurity Essentials for Your Business
Most cyber attacks that hit small and midsize businesses come down to a handful of avoidable gaps. This guide walks you through the basics that protect your business and the people who depend on it. Each section below is a short read you can share ...
Common Cyber Threats Every Business Should Know
You do not need to be a security expert to protect your business, but it helps to know what you are up against. Most attacks fall into a handful of familiar patterns. Here are the ones most likely to reach a small or midsize business, in plain terms. ...
RTG Client Welcome & Support Guide
Welcome aboard. You now have one team running your network, phones, security, and cameras. One vendor. One bill, one number, one crew. This guide covers how to reach us, how support works, how fast we respond, and how to get the most out of working ...