Password Hygiene for Small Teams, Explained Without Jargon
By ABD Web Tools Editorial · 2026-02-16 · 8 min read
Small teams get breached in boring ways. Not through zero-days, but through a shared login posted in a chat channel two years ago, a password reused from a service that leaked, or an account belonging to someone who left in March. None of that requires an expensive programme to fix. It requires about a week of unglamorous decisions.
Entropy in one paragraph
Entropy measures how many guesses an attacker needs on average. Every extra character multiplies the search space; every predictable substitution barely dents it. A four-word passphrase drawn randomly from a large dictionary is far stronger than an eight-character password with a capital, a digit and an exclamation mark — and much easier to type.
That is why modern guidance favours length over composition rules. Rules like 'must contain a special character' push people towards Password1! and its cousins, which attackers try first.
Reuse is the real vulnerability
The dominant attack is credential stuffing: take usernames and passwords from a public breach and try them everywhere. It costs almost nothing and works because people reuse passwords. A unique password per service turns one leak into one problem instead of twelve.
Advertisement
The manager is not optional
Unique passwords are impossible to remember, so a password manager is what makes the policy realistic. Choose one that supports shared vaults for team credentials, and require it for every work account. The habit to enforce is simple: if a credential is not in the manager, it does not exist.
- One personal vault per person, one shared vault per function.
- No credentials in chat, tickets, spreadsheets or code comments.
- Rotate anything that has ever been sent in plain text.
Two-factor, ranked by usefulness
Hardware security keys are the strongest and stop phishing outright. App-based one-time codes are a large improvement over nothing. SMS codes are the weakest common option because of SIM-swap attacks, but still better than a password alone. Start with authenticator apps everywhere, then add keys for administrators and finance.
Offboarding is a security control
Maintain a written list of every service the team uses and who has access. On someone's last day, revoke access from that list rather than from memory. Shared credentials that person knew should be rotated the same day. This one habit closes the most common long-lived hole in small organisations.
A one-week rollout
Day one: inventory every service and account. Day two: choose and deploy the manager. Day three: import and replace reused passwords, starting with email, banking and domain registrar. Day four: enable two-factor on those same tier-one accounts. Day five: document the policy in a single page everyone can read in two minutes, and set a calendar reminder to review it quarterly.
What not to bother with
Forced 90-day rotation for everyone leads to predictable increments and weaker passwords. Rotate on suspicion of compromise, on offboarding, and for shared credentials — not on a timer.
Frequently asked questions
How long should a password be?
At least 12 characters for ordinary accounts and 16 or more for administrative ones, or a randomly generated passphrase of four to five words.
Are password managers safe to trust?
Reputable managers encrypt your vault locally so the provider cannot read it. The risk of using one is far smaller than the risk of reuse.
Is writing passwords on paper acceptable?
For a handful of recovery codes stored in a locked drawer, yes. For daily credentials, a manager is safer and more practical.
How do we handle a shared social media login?
Use the platform's native team access features where they exist; where they do not, keep the credential in a shared vault with two-factor bound to a team-owned device.
Advertisement