Use a password manager, give each person their own login where possible, and share the rest through the manager rather than by message. Reused passwords are the single most common way small businesses get compromised.

The actual risk

Not somebody guessing your password, which is rare.

What happens is that a service you used years ago is breached, your email address and password appear in a list, and somebody tries that combination on hundreds of other services automatically.

If you reused the password, they are now in your email, your hosting, your listing or your bank.

That is the mechanism behind most small business compromises, and it requires nobody to target you specifically.

Which means the single most valuable change is not a stronger password. It is a genuinely different password on every account.

Why people reuse them

Because the alternative was genuinely impractical until recently.

Nobody can remember forty distinct passwords, and writing them down was the only workable option, which had obvious problems.

So people used one good password everywhere, which is a reasonable response to an impossible requirement.

A password manager removes the requirement rather than asking people to try harder, which is why it works where policies do not.

What a password manager does

The third is the point that convinces people. It is not a security chore that slows you down; it is faster than what you were doing.

A worked example

A three-person business sharing one password across their email, hosting, listing, supplier accounts and bookkeeping.

It was written on a card by the till so everybody could reach it.

An old forum account with the same address and password appeared in a breach. Somebody used the combination on their email, got in, and sent invoices to their customers with altered bank details.

Three customers paid before anybody noticed.

Recovery involved changing everything, contacting every customer, and a difficult conversation with two of them about money they had paid to somebody else.

The fix afterwards took an afternoon: a password manager, unique passwords everywhere, and two-factor on the email.

The card by the till had been the obvious problem and was not the one that caused it.

Shared accounts

The practical difficulty in a small business, and it has a proper answer.

Some services allow multiple users with separate logins, which is always the better arrangement. Each person has their own credentials and access can be removed individually.

Where a service genuinely allows only one login, share it through the password manager rather than by message or on paper.

That way it can be changed once when somebody leaves, without anybody needing to be told the new one.

What to avoid: sharing by text or email, which leaves the password sitting in message history on several devices indefinitely.

The counter-case

Where a manager is not the whole answer.

The master password still has to be remembered and still has to be strong, and losing it can mean losing everything.

Which is why the recovery arrangement matters: a recovery key stored somewhere physical and safe, and somebody else who can get in if you cannot.

For a sole trader, that means a trusted person or a sealed note somewhere secure, which feels excessive until the day it is needed.

And a manager does not help with an account somebody else controls, which is a different problem covered by knowing who holds what.

Which accounts matter most

Not all of them are equal, and starting with the important ones makes this achievable.

Email first, always, because it is the recovery route for everything else. Somebody with your email can reset most other passwords.

Then the domain registrar, then hosting, then anything financial, then the business listing.

Those five cover most of what a compromise would actually damage, and securing them properly is an hour of work.

Everything else can be migrated gradually, as and when you next happen to log into each service, rather than being treated as a project.

The card by the till

Worth addressing directly, because it is extremely common and the usual advice is unhelpful.

Telling a small business never to write a password down ignores why the card exists: several people need access and nobody can remember it.

A written password in a locked drawer is not the worst arrangement available. A written password reused across eleven accounts is.

So if a manager is genuinely not going to happen, the improvement worth making is different passwords per account, written down, kept somewhere not visible to customers.

That is considerably better than one password everywhere and considerably worse than a manager, and it is achievable this afternoon.

What makes a good password now

Different from the advice most people learned.

Length matters more than complexity. A long string of ordinary words is stronger and easier than a short one with symbol substitutions.

Forced regular changes are no longer recommended, because they produce predictable variations rather than better passwords.

And the one that matters most: it should be unique. A moderately good password used once is safer than an excellent one used eleven times.

With a manager, all of this becomes academic anyway, because the generated passwords are long and unique by default and nobody has to think about it.

Getting other people to use it

The organisational half, which is harder than the technical half.

Somebody who has used one password for a decade will not adopt a manager because it is more secure. They will adopt it because it saves them typing.

Which is the argument worth making: set it up on their phone, show them it filling in a login, and let the convenience do the persuading.

What does not work is a policy document, a lecture about breaches, or requiring it without setting it up for people.

Spend twenty minutes with each person getting it working on their own devices, and it sticks. Send an email telling them to use it, and it does not.

Starting today

  1. Choose a manager and set up the master password.
  2. Change your email password first, to something unique.
  3. Add two-factor to that account.
  4. Do the domain, hosting and financial accounts next.
  5. Add the rest as you log into them.
  6. Check for reused passwords using the manager's warning.

The sixth usually produces an uncomfortable number, and that list is worth working through in order of what each account actually controls.

The wider question of who holds which accounts is covered in who holds the keys to your site.


Frequently asked questions

What is the actual risk?

Not somebody guessing. A service you used years ago is breached, your details appear in a list, and the combination is tried automatically on hundreds of other services.

Why do people reuse passwords?

Because remembering forty distinct ones is impossible. Reuse is a reasonable response to an impractical requirement, which is why a manager works where policy does not.

What convinces people to use a manager?

That it is faster than typing. It fills passwords in, so it is not a security chore that slows you down.

How should shared accounts work?

Separate logins per person where the service allows it. Where it does not, share through the manager rather than by text or email.

Which accounts should I secure first?

Email, because it is the recovery route for everything else. Then the domain registrar, hosting, financial accounts and the business listing.

What makes a good password now?

Length over complexity, no forced regular changes, and above all uniqueness. A moderate password used once beats an excellent one used eleven times.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Same password on eleven accounts?

Email first, then the domain and hosting. That hour covers most of what a compromise would actually damage.

Start a Conversation