Common password mistakes in companies (and how to fix them)

Your security is only as strong as your worst habit

We've reviewed hundreds of SMB security audits and the same mistakes always show up. Good news: they all have a fix and most are free.

1. Reusing the same password across services

A single breach (LinkedIn, Adobe, Dropbox…) compromises every account. Fix: a unique, randomly generated password per service.

2. Sharing credentials over chat or email

They stay in logs, backups and personal devices forever. Fix: share through an encrypted vault with permissions.

3. Not revoking access when someone leaves

25% of former employees keep access for months. Fix: automated offboarding from your manager dashboard.

4. Using "Summer2026!" or similar

They satisfy the policy but an attacker cracks them in seconds. Fix: generator with 16+ characters and entropy above 80 bits.

5. No 2FA on critical accounts

Email, banking, hosting panel, cloud. Fix: turn on 2FA and store TOTP codes inside the manager.

6. Passwords on sticky notes or shared docs

Yes, it still happens in 2026. Fix: migrate to encrypted vaults; CSV import takes 5 minutes.

7. Never auditing

If you don't measure, you don't improve. Fix: monthly review of weak, reused and breached passwords with the strength checker.

This week's action plan

  1. Audit your 20 most critical accounts.
  2. Enable 2FA on all of them.
  3. Replace weak passwords with generated ones.
  4. Move everything to a manager with shared vaults.

Start the cleanup with Lock Down Keys →