Most small businesses run on a few passwords reused across every account, shared by memory or written down. The risk is not that someone guesses one. It is that a service you signed up for years ago gets breached, and the password from that service is the same one protecting your domain, your hosting, and your email.

How it actually goes wrong

Not a hacker targeting your business. Something far more mundane.

A company you used once is breached and its user list ends up circulating. Your address and password are in it. Automated systems then try that combination against hundreds of other services. If you used the same password for your email, that account is now accessible, and email is the master key because almost every other account can be reset through it.

You are not singled out. The attempt is automated and indiscriminate, which is precisely why small businesses are affected as often as large ones.

The accounts that actually matter

Not everything needs equal attention. A small number of accounts control everything else.

AccountWhat losing it means
Business emailThe master key. Nearly every other account can be reset through it
Domain registrarThe website and email can be pointed anywhere. The hardest to recover
HostingThe site itself, and any databases and mailboxes on it
Business profile and listingsYour public presence and your reviews
Banking and paymentsObvious, and usually already better protected

Five accounts. Securing those properly is most of the available benefit, and it is a realistic afternoon of work rather than an ongoing programme.

What makes a password strong

Length, more than complexity. A long passphrase of unrelated words is both harder to break and easier to type than a short string of substituted characters.

The old advice about mixing symbols and numbers produced passwords that were hard for people and not especially hard for computers. Current guidance favours length, and it favours never reusing one, which matters more than the composition of any individual password.

The genuinely important rule is that the five accounts above each have a different password from each other and from everything else. Reuse is the failure that turns one breach into all of them.

Where to keep them

A password manager, which is the one tool in this area worth adopting. It generates long unique passwords, stores them encrypted, fills them in, and means you only remember one.

The common objections are worth answering plainly. Putting everything in one place feels risky, and the alternative is reuse, which is demonstrably worse. If you forget the master password most services offer a recovery mechanism you set up in advance. And they work across phones and desktops, which is where the practical benefit shows.

The alternative that people actually use, a written list, is not absurd for a very small business provided it is kept somewhere physically secure rather than under the keyboard. It fails when staff change and when you need a password while on a job site.

The step that matters more than passwords

Two-factor authentication, which asks for a code from your phone in addition to the password.

This is the single most effective change available, because it means a stolen password on its own is not enough. Even if your password appears in a breach, the account holds.

Switch it on for email first, then the registrar, then hosting. Where offered a choice, an authenticator application is more secure than codes by text message, though text-based is far better than none. And save the backup codes somewhere separate from your phone, because losing the phone without them is a genuinely difficult situation to recover from.

Shared accounts and staff

Most small businesses share one login for everything, which is understandable and creates two problems. Nobody can tell who did what, and when someone leaves, the only remedy is changing a password everyone uses.

Where a service supports multiple users, use them. Most business platforms do, at no extra cost. It takes a few minutes per person and it means removing access when someone leaves is one action rather than a scramble.

Keep a short list of which accounts each person can reach. Reviewing it when someone joins or leaves takes five minutes and it is the step that gets skipped in the fortnight after a departure, which is exactly when it matters.

The afternoon worth spending

That last one catches people. Recovery addresses pointing at a former employee or a mailbox nobody reads turn a routine reset into a serious problem, and it is the kind of thing nobody discovers until the day it matters.


Frequently asked questions

What is the biggest password risk for a small business?

Reuse. A service you used once gets breached, and automated systems try that same combination against hundreds of other services. If it matches your email password, nearly every other account can be reset through it.

Which accounts should I secure first?

Business email, the domain registrar, hosting, your business listings, and banking. Those five control almost everything else, and securing them properly is an afternoon rather than a programme.

Are password managers safe?

They are considerably safer than the alternative, which in practice is reusing a handful of passwords. They generate long unique passwords, store them encrypted, and mean you only have to remember one.

What makes a password strong?

Length more than complexity. A long passphrase of unrelated words beats a short string with substituted characters, and never reusing one matters more than the composition of any single password.

Is two-factor authentication worth the hassle?

It is the single most effective change available, because a stolen password alone is then not enough. Switch it on for email first, then your registrar and hosting, and save the backup codes somewhere separate from your phone.

How should staff share access?

Use separate user accounts where the service supports them, which most business platforms do at no extra cost. It means removing access when someone leaves is one action rather than changing a password everyone relies on.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Not sure who can still access your accounts?

We audit access across your domain, hosting, email, and listings, and lock down the five accounts everything else depends on.

Start a Conversation