Hands typing on a laptop keyboard, representing setting a strong password policy for a small businessA clear password policy removes guesswork and closes one of the most common security gaps

Weak and reused passwords remain one of the most common ways a small business account gets compromised, and yet a proper password policy is one of the cheapest and easiest protections to put in place. Most businesses do not need specialist security software to fix this, they need a clear, consistently followed policy and the right tools to make following it easy.

This is a spoke in our cyber security cluster. For the full checklist this fits into, see our pillar guide on the cyber security checklist for UK small businesses.

Why Weak Passwords Are Still Such a Common Problem

Despite widespread awareness that weak passwords are risky, predictable patterns, a name followed by a number, a pet’s name, a keyboard sequence, remain extremely common because they are easy to remember. Attackers know this and use automated tools that can test thousands of common password patterns in seconds, meaning a weak password can be compromised almost instantly once an account is targeted.

What Makes a Strong Password

  • Length matters more than complexity. A long password made of several random, unrelated words is harder to crack than a shorter one with substituted symbols and numbers, and is often easier to remember.
  • Uniqueness across accounts. Reusing the same password across multiple accounts means a single breach on one service can expose every other account using that same password.
  • No personal information. Names, birthdays, and other personal details are among the first things an attacker will try, since they are often easy to find or guess.

The Business Case for a Password Manager

Expecting staff to remember dozens of unique, complex passwords without help is unrealistic, and often leads to exactly the weak or reused passwords a policy is meant to prevent. A password manager stores and generates strong, unique passwords behind a single master password, removing the burden of memorising individual credentials while still maintaining strong security across every account.

Writing a Simple Password Policy

Policy Element Recommended Approach
Minimum length At least 12 characters, ideally longer
Uniqueness A different password for every business account
Storage Password manager only, never written down or shared informally
Multi-factor authentication Required on all accounts that support it
Sharing Never shared between staff, even for shared accounts

Handling Shared Accounts

Genuinely shared accounts, such as a shared social media login, present a particular risk since the password inevitably becomes known to multiple people. Where possible, using role-based access through the platform itself, rather than a single shared password, is a safer approach. Where a shared password is unavoidable, storing it in a password manager with controlled, logged access is preferable to it being written down or sent informally.

What to Do When an Employee Leaves

Departing staff should have their access revoked immediately, not at the end of a notice period or whenever convenient. Any shared accounts they had access to should have their passwords changed as part of standard offboarding, closing a gap that is easy to overlook once someone has left.

Multi-Factor Authentication: The Essential Companion to a Strong Password

Even the strongest password can potentially be compromised through phishing or a data breach elsewhere. Multi-factor authentication adds a second verification step, meaning a stolen password alone is not enough to access an account. Enabling this across email, banking, and cloud storage accounts specifically closes one of the highest-risk gaps a small business faces.

Frequently Asked Questions

How often should passwords be changed?

Modern security guidance, including from the UK’s National Cyber Security Centre, generally favours long, unique passwords over frequent forced changes, since regular mandatory changes often lead to weaker, more predictable passwords being chosen out of convenience. Changing a password immediately after a suspected breach matters more than changing it on a fixed schedule.

Is a password manager safe to use for a small business?

Reputable password managers use strong encryption and are generally considered significantly safer than the alternatives, such as reused passwords or passwords stored in an unprotected document or spreadsheet.

Do all staff need to use the same password manager?

Using a consistent business-wide password manager, rather than leaving the choice to each individual, makes policy enforcement and offboarding significantly easier to manage.

What should happen if a password is suspected to be compromised?

The password should be changed immediately, and if the same password was used anywhere else, despite policy discouraging this, those accounts should be updated too. Enabling multi-factor authentication limits the damage even if this step is delayed.


About the author: The Business To World editorial team covers practical business, banking, investment and property guidance for UK small business owners and entrepreneurs.