The Password Problem (And What Actually Works)
Why passwords are the weakest link in most business security — and what modern, practical password management looks like.
Passwords are the most-discussed and least-improved part of business cybersecurity. Every employee knows they should use strong, unique passwords. Almost none of them do. Every business knows password reuse is a major risk. Most do nothing systematic about it.
The good news is that the practical solutions for the password problem are now mature, affordable, and increasingly invisible to users. The bad news is that most businesses haven’t adopted them.
This is the state of password management in 2026, and what a sensible approach actually looks like.
THE PASSWORD PROBLEM
- Why Passwords Are the Weakest Link
- Password Reuse and Why It Matters
- What “Strong” Actually Means Now
- Password Managers: The Underused Solution
- Passkeys and the Beginning of the End
- The Single Highest-Impact Move
Why Passwords Are the Weakest Link
Most businesses spend significantly on firewalls, endpoint protection, and email security. The same businesses then secure their cloud applications — where the actual data lives — with passwords like “Summer2025!” used across multiple services.
The threat is well-known. Credential databases from old breaches are bought, sold, and used to attempt logins against business systems daily. If an employee used the same password on a long-forgotten website that was breached in 2021, that password is in a database somewhere being tried against your Microsoft 365 right now.
This isn’t theoretical. It is the daily reality of modern attack surfaces, and it’s why password discipline matters as much as any other security control.
Password Reuse and Why It Matters
The single most damaging password behaviour is reuse — using the same or similar passwords across multiple services. When one of those services is breached, every account using that password becomes vulnerable.
A typical employee uses dozens of services personally and professionally. Expecting them to remember a unique strong password for each is unrealistic. Without a tool that makes this easy, reuse is inevitable — and the average employee reuses passwords across many accounts.
The solution isn’t to ask people to try harder. It’s to give them a tool that removes the friction.
What “Strong” Actually Means Now
The old advice — eight characters, one uppercase, one number, one symbol — is obsolete. Modern guidance, from NIST and security researchers, has shifted:
- Length matters more than complexity. A sixteen-character passphrase is stronger than an eight-character symbol-heavy password
- Forced rotation is harmful. People respond to required password changes by making predictable variations on existing passwords. Modern guidance is to rotate only on suspected compromise
- Common words and patterns are out — anything in a typical password-cracking dictionary should be avoided
- Personal information (names, birthdays, pet names) should never be used
In practice, the cleanest answer is to not have humans pick passwords at all. Let a password manager generate them.
Password Managers: The Underused Solution
A business password manager solves the entire problem in one move. Every account gets a unique, long, random password. Users don’t have to remember them. Sharing credentials within a team is controlled and auditable. Onboarding and offboarding employees becomes a clean process rather than a scramble.
The cost is modest. The friction, after a one-week adjustment period, is lower than the friction of remembering passwords. The security benefit is enormous.
The reason this isn’t universal yet is mostly inertia. Businesses that adopt a password manager rarely go back. Businesses that haven’t adopted one usually haven’t seriously considered it.
Passkeys and the Beginning of the End
Passkeys are a newer technology that replaces passwords entirely for supported services. They use cryptographic keys stored on your device, unlocked by biometrics or a PIN. There is nothing for an attacker to phish, intercept, or guess.
Adoption is uneven. Microsoft, Google, Apple, and a growing list of major services support passkeys today. Many smaller services don’t yet. The trajectory is clear: passkeys will eventually replace passwords for most major services, and the transition has already begun.
For now, the practical recommendation is to enable passkeys where supported and use a password manager for everything else.
The Single Highest-Impact Move
If you can do only one thing about passwords this quarter: deploy a business password manager across your team, with mandatory adoption and a documented onboarding process.
A close second: enforce MFA on every account that supports it, which substantially reduces the impact of even a compromised password.
A third: prohibit password sharing through email, chat, or sticky notes — channels that leave permanent records of credentials in places that should not have them.
These three moves, taken together, eliminate the substantial majority of password-related risk in a typical SMB. They are not expensive. They are not technically complex. And they are still — somehow — uncommon.
If your team is still managing passwords with browser auto-save, spreadsheets, sticky notes, or memory, that’s a useful place to start.