clic para entrar
← back to blog
Tech tips for business

Passwords and 2FA: the bare minimum to turn on today

Passwords and 2FA: the bare minimum to turn on today

The year 2018 will be remembered for a string of massive data breaches that exposed millions of emails, passwords, and personal details of users around the world. The most revealing part wasn’t the scale of the attacks, but how basic most of the failures were: reused passwords, keys that were far too simple, and accounts with no second layer of protection. In other words, much of the damage didn’t come from sophisticated hackers, but from doors that were left practically wide open.

For a Mexican small business, that’s good news, because it means you don’t need a big-corporate budget to protect yourself. With two or three well-established habits, you avoid the vast majority of scares: unauthorized access to your email, your online banking, your administrative systems, and your customers’ information. This article gets straight to the point: the bare minimum you should turn on today, no jargon, and designed so that any team can apply it.

Most attacks on small businesses don’t start with anything elaborate; they start with a guessed or reused password. When someone uses the same key for their email, their invoicing system, and their social media, all it takes is one leak in a single place to expose them everywhere.

The problem gets worse with keys that are easy to remember (and therefore easy to guess) and with the habit of sharing them over chat or sticking them on a monitor. In a business with several people, every careless account is a potential entry point to your information.

  • Never reuse the same password across two different services; one leak shouldn’t spread to the rest.
  • Prioritize length over convoluted complexity: a long, easy-to-remember phrase is usually more secure than eight characters with symbols.
  • Avoid obvious data: names, birthdays, the company name, or sequences like 123456.
  • Don’t share keys over chat or leave them in plain sight; if several people need access, use a tool built for that.
Digital padlock protecting access to a company's accounts
A second layer of verification turns a leaked password into a scare without consequences.

2FA: your second lock

Two-factor authentication (2FA) is, today, the measure with the best effort-to-benefit ratio out there. The idea is simple: in addition to the password, entering an account requires a second factor, usually a temporary code on your phone. That way, even if someone gets your key, they can’t get in without that second element that only you have.

If tomorrow you can do only one thing for your business’s security, turn on two-step verification on your email.

Email deserves absolute priority because it’s the master key: almost every other account is recovered from there. After email, turn on 2FA for your administrative systems, your online banking, and any platform where you store customer data. Whenever possible, prefer an authentication app over codes sent by text message, since it offers an additional layer of trust.

A password manager so you don’t rely on memory

Asking your team to invent and remember a different, long key for every service isn’t realistic, and that’s where a password manager comes in. These tools generate strong keys, store them encrypted, and fill them in for you when you log in to each site. Your people only need to remember one master password.

For a business, the benefit goes beyond convenience: you can control who has access to what, revoke permissions when someone leaves the team, and stop sharing keys through insecure channels. It’s the kind of decision that brings order to your processes and gives you reliable information about who accesses each system.

Secure your access step by step

You don’t need to transform everything at once. Security, like custom software, works best when you start with the essentials and move forward little by little:

  • Today: turn on 2FA for the business’s main email and for the accounts of the people with the most access.
  • This week: choose a password manager, and change the keys for critical services first (email, banking, administrative systems).
  • This month: define a simple, written rule for the whole team (don’t reuse keys, don’t share them over chat, turn on 2FA wherever possible).
  • On an ongoing basis: when an employee leaves, revoke their access the same day.

Basic security isn’t a luxury or a topic reserved for experts: it’s a handful of habits that, well established, save you from the vast majority of scares. If you want to put them in place with order, at Normandia Web we help small businesses secure their access and systems without slowing down operations; tell us how your team works and we’ll design it with you, starting with the first step.

Ready to put it to work in your company?

Tell us what’s costing you time, money or control. We’ll help you figure out where to start.

Start your consultation →