When a small business gets broken into online, the story is almost never a genius hacker. It's a password that was used on two sites, one of which got breached three years ago. Or a text message that said "verify your login" and someone did.
Two habits stop the large majority of these. Neither costs much, and both can be set up in an afternoon. I'll go through what they are, which accounts to do first, and how to handle the messy reality of shared logins.
Why Reused Passwords Are the Real Attack
Every few months, some big service leaks its user database. Those email-and-password pairs end up in lists that attackers run against every other service automatically. It's called credential stuffing, and it doesn't target you specifically. It targets everyone who reused a password.
If your Gmail password is the same as your old Pinterest password, and Pinterest was breached, someone has already tried it on your Gmail. The only reason it might not have worked is luck.
You can check whether your email shows up in known breaches at haveibeenpwned.com. Most people are in at least one. That's not a reason to panic. It's a reason to stop reusing passwords, which is what a password manager makes possible.
Habit One: A Password Manager
A password manager is an app that generates a different, random password for every site and remembers them for you. You remember one strong master password. That's the whole idea.
Which one doesn't matter much. Bitwarden is free and excellent. 1Password is polished and worth the small fee. Apple and Google both have built-in ones that are fine if you live entirely in one ecosystem. Pick one and use it.
What matters is actually migrating:
- Install it on your phone and computer, and add the browser extension.
- Start with the five accounts below. Log into each, change the password to a generated one, and save it.
- From then on, every time you log into something else, let the manager save it and change the password when you have a minute.
Don't try to do all 200 accounts in a day. Do the important ones now and let the rest happen naturally over a month.
Habit Two: Two-Factor Authentication
Two-factor authentication (2FA, or MFA) means a password alone isn't enough. You also need a code from your phone. If someone has your password from a breach, they still can't get in.
The versions, from weakest to strongest:
| Method | How it works | Good enough? |
|---|---|---|
| Text message codes | A code is texted to you | Better than nothing, but phone numbers can be hijacked |
| Authenticator app | An app generates rotating codes (Google Authenticator, Authy, or your password manager) | Yes, for most businesses |
| Passkeys / security keys | Your phone or a physical key approves the login | The best option, and it's getting easier |
Use an authenticator app or passkeys wherever you can. Fall back to text codes only when that's all the service offers. And save the backup codes each service gives you somewhere safe, because losing your phone without them is a very bad day.
The Five Accounts to Lock First
Don't try to secure everything. Secure the accounts that could be used to take over everything else.
- Your email. Every other account resets its password through your email. If someone owns your inbox, they own all of it. Do this one first, today.
- Your domain registrar. Whoever controls the domain controls your website and email. I covered why in who actually owns your website.
- Your bank and payment processor. Square, Stripe, PayPal, and the bank itself. Obvious, but often still on a text-code 2FA or none at all.
- Your Google Business Profile. A hijacked profile can have its phone number and address changed, sending your customers to someone else.
- Your website admin. WordPress, Shopify, Wix, whatever it is. Most platforms support 2FA now. Turn it on.
That's the short list. Social media accounts are next, especially if they're where customers message you.
The Shared Login Problem
Here's what actually happens in small businesses: the Instagram password is on a sticky note, three employees know the Square login, and the former manager still has access to the Facebook page.
Fixing that without breaking everything:
- Give people their own accounts wherever the service allows it. Google, Meta, Shopify, Square, and most bookkeeping tools support multiple users with different permissions. Use that instead of sharing one login.
- For services that only allow one login, put the credential in a shared vault in your password manager and share it with the specific people who need it. When someone leaves, remove them from the vault and change the password. Ten minutes.
- Do a quarterly cleanup. Look at who has access to what. Remove anyone who left. You'll find at least one every time.
This is the same principle as the email scam post: most attacks rely on people, not technology, and the fix is a process, not a product.
The Bottom Line
You don't need to be a security expert. You need every important account to have its own random password, stored in a manager, protected by a second factor. That single change puts you ahead of most of the businesses on your street.
Start with your email. Then the domain. Then the bank. An hour of setup this week is cheaper than any version of the alternative.
Want to know what an attacker can see about your business from the outside? Get a free audit and I'll flag the exposed accounts, outdated software, and missing protections.
Want help applying this to your business?
Get a free website audit and a personalized action plan. No pressure, no sales pitch.
Get a Free Audit