← All articles

Password Day 2022

A good share of a company's security gaps come through its employees, not the technology itself. Here are the password habits worth knowing.

Did you know a good share of a company's security gaps come through its employees, not the technology itself?

Passwords are a fundamental part of IT security. They're the first line of defence for user accounts, and a poorly chosen password can compromise a company's entire network — even when everything else (firewall, antivirus, backups) is in good shape.

Technological advances have made us more efficient at work, but that doesn't come without a downside. Companies are increasingly exposed, and it's important to stay ahead of the risks that come with it. Cybersecurity is a priority at MMO, which is why educating users on good password habits matters.

Here's what you need to know to keep yourself and your company safe.

5 password habits to avoid

Don't write your passwords on a sticky note. Even if it's hidden under the keyboard or in your desk drawer.

Don't save your passwords in the browser. It's not the safest way to store them — a compromised browser exposes everything at once.

Don't reuse the same password across your different accounts. And incrementing a password doesn't count as a different one (e.g., myDog1, myDog2, myDog3).

Don't use a single dictionary word. Words like *butterfly* or *sunshine* are common terms found easily in the lists attackers use.

A capital letter and an exclamation mark aren't enough. Your password isn't any safer just because it starts with a capital and ends with a "!" — automated cracking tools test those variations first.

5 good password habits

Length matters. The longer the password, the harder it is to crack. Use passphrases like *Butterfly.Sunshine.Mustard.10355*.

Use two-factor authentication. The two factors being something you know (the password) and something you have (a one-time code generator, or your phone). If an attacker gets hold of your password, they still can't get into your account without that second barrier.

Change passwords on lower-security accounts every 3 to 6 months. If an account can't be set up with multi-factor authentication, rotate it regularly.

Build a complex passphrase. Turn a phrase into a password — several words strung together with numbers, like *Butterfly.Sunshine.Mustard.10355*. "I'll never remember that," people often say when we suggest a complex password. That's exactly what the next tip is for.

Use a password manager. A password manager is like a set of encrypted digital sticky notes. You can store all your passwords securely, in one place. All it takes is a single password (complex, and protected by two-factor authentication) to unlock all the others.

What about passkeys?

More and more services now offer passkeys as an alternative to the traditional password — a method that relies on your device (fingerprint, face recognition, or a PIN) instead of a secret you have to remember. It's a trend worth watching, but as long as your internal systems still run on classic passwords, the practices above remain the essential baseline.

We get it: managing passwords and access can feel complicated. But adequate protection is far less costly — in time and in money — than dealing with a cybersecurity incident. MMO Techno can help strengthen your company's security without sacrificing your employees' convenience. Feel free to reach out with any questions.

An IT project or a question?

Talk to an MMO Techno expert. We'll give you a clear, fast answer.

Contact us