← All articles

Individuals · Micro Businesses · Small Businesses · Sole Traders

Passwords: would you use the same key for everything?

We all understand locks and keys.

You would not normally use the same key for your house, car, office and filing cabinet. If somebody copied it, they could get into everything.

Yet many of us do the digital equivalent by using the same password for our email, banking, accounting software and other online accounts.

Why? Because nobody can remember dozens of complicated passwords—and adding another number or exclamation mark does not make the problem disappear.

Fortunately, there is now a more practical answer.

One account, one password

If you use the same password more than once, a security failure somewhere unimportant can become a problem somewhere very important.

Criminals obtain lists of email addresses and passwords from compromised websites and automatically try them elsewhere. If the password used for an online shop is also used for your email or accounting software, one stolen password may unlock several doors.

Every important account should therefore have its own password.

That sounds sensible. It also sounds impossible to remember.

Let a password manager remember them

A password manager acts rather like a secure key cabinet.

It can create and store a different, strong password for every account. You only need to remember the main password that opens the manager.

Many phones, computers and browsers already include one. There are also established specialist password managers. The important points are to choose a reputable provider, keep your devices updated and protect the password manager itself carefully.

This is generally safer than:

  • reusing one memorable password;
  • keeping passwords in an unprotected spreadsheet or document;
  • writing them on a note beside the computer; or
  • changing the same password slightly for each website.

The National Cyber Security Centre also recommends password managers as a practical way to create and manage strong, unique passwords.

What about passkeys?

You may increasingly be offered the option of using a passkey.

A passkey allows you to sign in using a trusted phone, computer or tablet—usually by confirming your identity with a fingerprint, face recognition or the device’s PIN.

There is no password for you to type, remember or accidentally enter into a convincing fake website. This makes passkeys both easier to use and much harder to steal through phishing.

The National Cyber Security Centre now recommends choosing a passkey wherever one is available.

You do not need to understand the technology behind it. If a reputable service you already use offers to set up a passkey, it will usually be the safer option.

Add another lock where you can

Where passkeys are not available, turn on two-step verification or multi-factor authentication.

This means that a password alone is not enough to enter the account. You may also need to approve the login on another device, use an authentication app or enter a separate code.

It is not perfect, but it creates another obstacle for anyone who has obtained your password.

Start with your email account. Anyone who controls your email may be able to reset passwords for many of your other services. After that, protect online banking, accounting software, payroll systems and any account containing personal or confidential information.

Also check that the email address and telephone number used for account recovery are still correct. There is little point fitting a strong lock if the spare key has been left somewhere unsafe.

Do you know who has access?

Business security is not only about the strength of a password.

Each employee should normally have an individual login rather than sharing one account. This makes access easier to control and means you can remove it promptly when somebody changes role or leaves.

It is worth asking three simple questions:

  • Who can access our important systems?
  • Do they still need that access?
  • Could we recover the account if the usual person was unavailable?

You do not need a complicated security project to answer them. A short, sensible review is much better than assuming everything is all right.

A practical starting point

If you do nothing else, begin with these five steps:

  1. Protect your main email account.
  2. Stop using the same password for different services.
  3. Use a reputable password manager.
  4. Choose passkeys where they are offered and two-step verification where they are not.
  5. Review who can access your important business systems.

Passwords and access controls are particularly important when using online accounting systems. They are one part of the wider question we consider in Is cloud accounting safe?

When we help clients choose or set up cloud accounting software, we will also explain the available access settings and help make sure the right people can see the right information.

That is considerably easier than changing all the locks after a key has gone missing.

Now, where did I put my car keys?

Need the current answer?

Talk it through with someone who understands the context.

Call 01427 611177