If you make only 2 security changes this year, make them a team password manager and multi-factor authentication (MFA) on every important account. Together they block many of the most common ways attackers get in.
Why passwords alone fail
People reuse passwords. When one website is breached, attackers try the leaked email and password on other sites. A single reused password can open your email, your CRM and your website admin.
What a password manager does
- Creates a strong, unique password for every account
- Fills in logins for you, so nobody has to remember them
- Lets teammates share access without sending passwords by chat or email
- Makes it quick to remove access when someone leaves
What MFA adds
MFA asks for a second proof of identity when you log in. Even if a password is stolen, the attacker still needs that second factor. CISA says users who enable MFA are significantly less likely to get hacked.
Types of MFA compared
| Method | How it works | Protection level |
|---|---|---|
| SMS code | Code sent by text message | Basic. Can be stolen through SIM swaps |
| Authenticator app | Code from an app such as Google or Microsoft Authenticator | Good |
| Push approval | Tap approve in an app | Good, if staff check before approving |
| Security key or passkey | Physical key or device-based login | Strongest. Resists phishing |
Where to turn on MFA first
- Email accounts, because they can reset every other password
- Website and hosting admin
- Banking and payment tools
- CRM, cloud storage and social media
How to roll it out in a day
- Choose a business password manager and set up a shared vault for team logins.
- Ask everyone to move their work passwords into it.
- Turn on MFA for the accounts listed above.
- Store backup codes in the password manager.
- Make MFA mandatory for all admin accounts.
Phishing is the other big risk these tools help with. Read how to spot a phishing email, then work through the rest of our small business cybersecurity basics.