What every small business needs to know about password security
With several high-profile companies falling victim to data breaches in recent months, cyber security is top of mind for businesses and consumers alike. The easiest way cyber criminals gain access to our systems is by password hacking, so here’s what you need to know to keep your data and customers secure.
Cyber criminals are getting better every day at gaining access to our personal details, online accounts and home devices via password hacks, and businesses and consumers need to up our game in order to keep up and stay secure online.
Small businesses are at particular risk, with hackers targeting customer data in recent breaches. Adding to this, businesses have the pressure of ensuring their staff and administrators are keeping system passwords secure.
Research shows that one of the most common ways cyber criminals gain access to our personal details and devices is due to weak passwords that users re-use on multiple platforms. This means that if one password is hacked, cyber criminals could gain access to multiple accounts and far more information than you realise.
According to research by Nord Security in 2022, 85 million passwords were leaked in Australia in the last year alone.
“A single password for multiple accounts is a hacker’s delight,” a Nord Security spokesperson said. โIf only one of the accounts is compromised, consider all your other accounts jeopardised.”
โ123456โ was the most common password used by Australians, with the combination recorded a whopping 308,000 times. The second most preferred password was simply โpasswordโ, which featured 191,800 times and would take a hacker just one second to crack. The analysis also found that people were fond of using their own names within passwords โ one of the biggest no-no’s when it comes to online security.

A complex passwordย containing 14 characters or more, with a combination of upper and lowercase letters, numbers, and symbols, is recommended to keep hackers at bay.
A good password will:
The Australian Governmentโs Digital Health website also recommends:
A password manager stores and manages your passwords in an encrypted database, making it easy to remember multiple passwords across each platform. It enables you to generate random, complex, and unique passwords using a password generator, stores your passwords and protects them with encryption, and reduces the number of passwords you have to remember.
MFA, also known as two-factor authentication (2FA), provides added protection by asking users to provide another method of identification, normally via a code sent by phone, text or email. This ensures that if someone attempts to login using your password, you will receive notice of the login attempt and have the chance to reject and report it if necessary.
Businesses often share passwords which can result in compromised cyber security across the whole business. It is recommended to give separate passwords to anyone with access to critical systems and enforce multi-factor authentication for each staff member. Never share passwords via online platforms such as email or keep written passwords near your devices where they can be easily found.
Always use a unique password for each account to help prevent the โdomino effectโ. This is where all accounts using the same password are compromised when the password is discovered.
NEVER use personal information in your passwords, such as birth dates or family names (including your own, your childrenโs or petโs names).
Weโve got loads of excellent cyber security tips and expert advice for businesses in our Cyber Security section. Here are a few we think you should read:
And check out this fact sheet about password security from the Australian Government.
Want more? Get our newsletter delivered straight to your inbox!ย Follow Kochieโs Business Builders onย Facebook,ย Twitter,ย Instagram, andย LinkedIn.
Comments