Here’s a fun fact that will ruin your morning coffee: 81% of data breaches involve weak or stolen passwords. And yet, when I audit small business security setups, I still see “CompanyName2024” protecting everything from email accounts to financial software.
Let’s fix that. Here are five password mistakes I see constantly—and what to do instead.
1. Using the Same Password Everywhere
I get it. You have 47 accounts and one brain. But when you use the same password for your Instagram and your business banking, you’re playing a very dangerous game of dominoes.
When one service gets breached (and they do, regularly), hackers immediately try those credentials on banking sites, email providers, and business tools. It’s called credential stuffing, and it works embarrassingly well.
The fix: Use a password manager like Bitwarden, 1Password, or Dashlane. You remember one strong master password; the software generates and stores unique passwords for everything else. Most have business plans that let you securely share credentials with team members without actually revealing the passwords.
2. Making Passwords “Complex” Instead of Long
You know those requirements that demand uppercase, lowercase, numbers, and symbols? They’ve trained us to create passwords like “P@ssw0rd!” which feels secure but is actually crackable in seconds.
Length beats complexity every time. A 20-character passphrase like “correct-horse-battery-staple” is exponentially harder to crack than “Tr0ub4dor&3” and infinitely easier to remember.
The fix: Aim for 16+ characters minimum. Use random word combinations or let your password manager generate truly random strings. If you must create a memorable password, think phrases, not puzzles.
3. Skipping Two-Factor Authentication
Two-factor authentication (2FA) is like adding a deadbolt to your door. Even if someone steals your key (password), they still can’t get in without the second factor—usually a code from your phone.
Yet most business owners I talk to haven’t enabled it on their most critical accounts. “It’s annoying,” they say. You know what’s more annoying? Explaining to your clients that their data was stolen because logging in took an extra ten seconds.
The fix: Enable 2FA on everything that offers it, prioritizing email, banking, and any cloud services storing sensitive data. Use an authenticator app (Google Authenticator, Microsoft Authenticator, or Authy) rather than SMS codes when possible—text messages can be intercepted.
4. Never Checking if Your Credentials Have Been Leaked
Billions of username/password combinations are floating around the dark web from past breaches. Yours might be among them, and you’d never know unless you look.
The fix: Visit Have I Been Pwned and enter your email addresses. If they appear in breaches, change those passwords immediately—and any other accounts where you reused them. Many password managers now include breach monitoring and will alert you automatically.
5. Sharing Passwords via Email or Slack
“Hey, can you send me the login for the social media account?” Five minutes later, that password is sitting in an email thread that could be compromised, forwarded, or discovered during an audit.
The fix: Use your password manager’s secure sharing feature, or a tool designed for this purpose. The password should never exist in plain text in your communication channels. When team members leave, you can revoke access instantly without changing every shared credential.
Start With One Change Today
You don’t need to overhaul everything at once. Pick the mistake that made you wince the hardest and fix that one first. Set up a password manager this week. Enable 2FA on your email tomorrow morning. Small improvements compound into real security.
If you’re unsure where your business stands on security basics—or you need help implementing these practices across a team—that’s exactly what we help with at On Your Side Technologies. Sometimes an outside perspective catches the gaps you’ve been walking past every day.
Your passwords are the keys to your business. Treat them that way.
Want to talk it through? I keep a few virtual coffee spots open each month — grab one while they’re available → Book a virtual coffee
Photo by Glenn Carstens-Peters on Unsplash




