Password Day 2022
A good share of a company's security gaps come through its employees, not the technology itself. Here are the password habits worth knowing.
Did you know a good share of a company's security gaps come through its employees, not the technology itself?
Passwords are a fundamental part of IT security. They're the first line of defence for user accounts, and a poorly chosen password can compromise a company's entire network — even when everything else (firewall, antivirus, backups) is in good shape.
Technological advances have made us more efficient at work, but that doesn't come without a downside. Companies are increasingly exposed, and it's important to stay ahead of the risks that come with it. Cybersecurity is a priority at MMO, which is why educating users on good password habits matters.
Here's what you need to know to keep yourself and your company safe.
5 password habits to avoid
Don't write your passwords on a sticky note. Even if it's hidden under the keyboard or in your desk drawer.
Don't save your passwords in the browser. It's not the safest way to store them — a compromised browser exposes everything at once.
Don't reuse the same password across your different accounts. And incrementing a password doesn't count as a different one (e.g., myDog1, myDog2, myDog3).
Don't use a single dictionary word. Words like *butterfly* or *sunshine* are common terms found easily in the lists attackers use.
A capital letter and an exclamation mark aren't enough. Your password isn't any safer just because it starts with a capital and ends with a "!" — automated cracking tools test those variations first.
5 good password habits
Length matters. The longer the password, the harder it is to crack. Use passphrases like *Butterfly.Sunshine.Mustard.10355*.
Use two-factor authentication. The two factors being something you know (the password) and something you have (a one-time code generator, or your phone). If an attacker gets hold of your password, they still can't get into your account without that second barrier.
Change passwords on lower-security accounts every 3 to 6 months. If an account can't be set up with multi-factor authentication, rotate it regularly.
Build a complex passphrase. Turn a phrase into a password — several words strung together with numbers, like *Butterfly.Sunshine.Mustard.10355*. "I'll never remember that," people often say when we suggest a complex password. That's exactly what the next tip is for.
Use a password manager. A password manager is like a set of encrypted digital sticky notes. You can store all your passwords securely, in one place. All it takes is a single password (complex, and protected by two-factor authentication) to unlock all the others.
What about passkeys?
More and more services now offer passkeys as an alternative to the traditional password — a method that relies on your device (fingerprint, face recognition, or a PIN) instead of a secret you have to remember. It's a trend worth watching, but as long as your internal systems still run on classic passwords, the practices above remain the essential baseline.
We get it: managing passwords and access can feel complicated. But adequate protection is far less costly — in time and in money — than dealing with a cybersecurity incident. MMO Techno can help strengthen your company's security without sacrificing your employees' convenience. Feel free to reach out with any questions.