The Scariest Thing in Your Business is a Reused Password

It's October, so let's talk about something truly frightening, especially for a practical IT guy like me, who likes simple solutions.


You may not like what I'm about to tell you because there’s a lot of talk about hackers, but what’s scarier is using the same password on multiple different accounts.


Most small business break-ins aren't as dramatic as you may think. Nobody is typing furiously in a dark hoodie in a remote, dimly lit underground bunker like this stock photo. Usually, it happens when a password is leaked from one website and gets tried on others. It works because the password was the same. 


One of those others is typically your email, your bank, or your accounting software. Cybercriminals target what will benefit them most quickly and what will hurt you most: your money and your credit, and if you run a business, your reputation is usually next. 


CISA, America’s Cyber Defense Agency, recommends long, unique passwords for every account, and most people can use a simple password manager to manage them. The best part? The fix is simple, and it doesn't require being "techy." I know, easy for me to say, but it’s true!

What a password manager does for a small business

A password manager is basically a secure digital vault where you remember one strong master password, and it handles the rest. 

Here’s how it works:

  • Password managers create strong, unique passwords for every account: one leak can't open other doors. Think of it as a separate key for every door instead of one key that opens everything.

  • They fill passwords in automatically: it’s often faster than typing, and let’s be honest, less memory-intensive.

  • Password managers store your Multi-Factor Authentication (MFA) codes: These are the six-digit codes that are required in addition to your logins. Yes, they can be frustrating, but the extra few seconds are well worth it.

  • They let you share logins securely with employees, a bookkeeper, or your IT provider: no more texting passwords or pasting them into emails. This alone is a game-changer for small businesses that run lean.

That last one matters more than most people realize: a password sent over text or email lives in that thread forever.




"But what if the password manager gets hacked?"

I knew you’d ask, and I’m so glad you did!

This is the most common question I get, and it's a fair one. Reputable password managers encrypt your vault so that even the company can't read it. Reassuring, right? No tool is perfect, but a good one is far safer than sticky notes, spreadsheets, or using the same password everywhere. I know that one might hurt a little, but think of it as moving your valuables from under the doormat to a safe.

How to start using a password manager in four steps:

  1. Pick a reputable manager. Choose one with business or team plans if you have employees. Ask your IT provider if you're unsure. I happily answer questions like this all the time. I personally recommend Keeper!

  2. Create a strong master password. Make it a long passphrase you've never used anywhere else. 

  3. Start with your most important accounts. That means email, banking, accounting, and anything with customer data. Don't try to do everything in one sitting. It can get overwhelming. It’s better to make progress than to avoid it.

  4. Start turning on MFA everywhere you can, including for the password manager itself. Then store those codes in the manager, so they're easy to find.

A quick story

One of my clients shifted from no password management to using Keeper (if you want to know more about it, shoot me an email here). Now, what was once a tense exchange of sharing confidential information through text or insecure methods became incredibly easy and secure between employees. 


By using a password management system like Keeper, they can store information like credentials with MFA codes, shared financial information, and shared logins all from a single easy-to-use location, and with confidence!

Why your insurance company cares about this

If you carry cyber insurance, expect questions about passwords and MFA on your application or renewal. Insurers increasingly require these basics, and gaps can affect your coverage or your premium. We'll dig into this in a later post in this series. 


If you're unsure what your policy requires, my cybersecurity insurance guidance is a good place to start, especially with AI on the rise. Many business owners are surprised to learn they don’t have coverage, or that their existing policies don’t include a clause for downtime caused by a cybersecurity event.

A note for teams

If you have employees, a password manager also solves an awkward problem. Are you ready? What happens when someone leaves? We’ve all wondered. We’ve likely all had employees move on. With shared vaults, you can remove their access in one place instead of hoping nobody kept a list of passwords. That alone is worth the effort to set up.

Not sure where the rest of your setup stands? The IT Gap Check is a self-guided assessment that shows where your policies and systems are strong and where they need work. You'll get a clear view of your priorities without having to talk to anyone.


The bottom line

You don't need to be an expert, and you don't need to fix everything today. Start with a password manager, use it for your most important accounts, and build from there. It's one of the highest-impact, lowest-effort security habits you can put in place.


Have a question or want a hand getting started? Get in touch here, and I’ll be happy to give you the best guidance for your unique situation.


Up next in this series: What Are Passkeys? All Treat, No Trick!


About the author:
Kevin Dutkiewicz is the founder of TechBrews, providing practical IT and cybersecurity guidance to small businesses in Stow and across Northeast Ohio.

Next
Next

Small Steps Create Big Shifts