
A weak password remains one of the easiest ways to gain unauthorized access. Yet, many SMEs overlook the importance of storing passwords securely. Everyone knows it's important, but in practice, it is often less well-managed than it is on paper. Password management is a fundamental part of information security. Precisely because it seems so logical, people often forget it. In this blog, you will read which mistakes to avoid, what constitutes a good password policy, and how to share passwords securely with your team.
Below are the three most common mistakes when it comes to managing and using passwords for your accounts. There are more, but to keep it concise, we have outlined the biggest ones.
If a hacker steals a password from one place, they automatically try the same combination on other services. In technical terms, this is called credential stuffing. It often works because people reuse passwords for multiple accounts. A data breach at an external service can give hackers immediate access to your accounts, potentially compromising your business systems as well.
A sticky note under the keyboard, an Excel file on a shared drive, passwords saved loosely in the browser: these are all ways to store passwords, but also ways to lose them. Anyone with access to the device or the file has access to everything inside it. There is no encryption, no control over who sees it, and often no record of who might have copied it.
This way of handling passwords requires no specialized security or IT knowledge; it is simply a matter of looking around before others gain access to your accounts.
Passwords like a company name with a year, or a predictable pattern such as "Welcome123" or "Autumn2026!", are often found on lists of standard passwords that hackers test. This is called a dictionary attack: not targeted hacking, but simply cycling through the most common passwords or trying combinations until one works. The more predictable the password, the faster they succeed.
A good password policy isn't about having as many rules as possible, but about having the right ones. This must be implemented both on paper and in your technical systems. A policy stating that passwords must be 12 characters long is fine, but if your systems only enforce 8 characters, you are less protected than your policy suggests.
In recent years, the advice has shifted from "complicated" to "long." A passphrase consisting of four separate words is harder for an attacker to crack than a short password full of numbers and symbols. For you, such a phrase is also easier to remember. When a password has to be complicated, people often use predictable tricks. For example, they add a number and an exclamation mark at the end. This doesn't actually make the password stronger, as such patterns are quickly recognized.
So, set a password for your accounts that is long and, if possible, complex enough. That makes it harder to remember, but that is what password managers are for. More on that in a moment.
You must store passwords securely; otherwise, you run the risk of them being exposed. But even more importantly, you should set a unique password for every account. Nowadays, you can no longer prevent your data from being exposed in a data breach. If you have set a unique password for every account, only the account and password involved in the breach are compromised. Hackers cannot use that information to log into your other accounts and systems because you have used a unique password everywhere. This drastically limits the impact on your business.
Now I hear you thinking: a unique password for every account? That’s impossible to remember. And the answer is, yes, that’s true. And once again, the answer is: that is what a password manager is for. It makes this way of using passwords much easier.
Passwords should be changed every few months. That sounds secure, but in practice, it is often counterproductive. This is because people tend to choose a predictable version of their old password. It is wiser to change a password only when there is a clear reason to do so, such as a data breach at a service you use or a suspicion of misuse. The publication of NIST 800-63B[1] also indicates that passwords should only be changed if there is evidence of misuse or a leak.
Sometimes you need to share something, such as a shared account for a program or system. In those cases, avoid sharing passwords via email, text message, or a shared document. You will run into the same problems as with insecure storage: you won't know who has access, and you won't be able to revoke that access later. We therefore recommend using the sharing feature of a password manager. The password is then encrypted in a shared vault, you can revoke access at any time, and you can see who still has access.
If you do not have a password manager at your disposal, it is advisable to share the account and the password via two separate channels. For example, send the password via Teams and the username via email or another medium. If the password is intercepted or left behind in a shared document, the person will not know which account it belongs to.
A password manager generates and remembers a unique, strong password for every account, so no one on your team uses weak passwords anymore. With 1Password, there is an added benefit: proactive notifications as soon as one of your organization's passwords appears in a known data breach, allowing you to intervene before it becomes a problem.
Would you like to know what password management with 1Password looks like in practice for your company? Discover 1Password at Peakproteqt.