Skip to main content

Security essentials

Password Security

A good password is unique to one account and difficult to guess. A reputable password manager makes that practical across many business services.

Plain-English guidance · Last reviewed 24 July 2026

On this page

The business case

Why it matters

When one reused password is exposed, attackers can try it against email, hosting, social media and other services. Small variations based on the service name are often predictable.

Length and unpredictability matter more than forced cosmetic substitutions. Strong passwords still need MFA and a protected recovery route because phishing, malware and session theft can bypass the password itself.

Know the exposure

Common risks

01

Password reuse

One compromised service becomes a route into unrelated accounts using the same or slightly altered credential.

02

Shared secrets

Credentials passed through email or chat cannot be cleanly attributed, rotated or revoked for one person.

03

Unsafe recovery

Security questions, personal inboxes and exposed backup codes can undermine a strong primary password.

Investigate, do not ignore

Warning signs

  • The same password pattern is used for several business services
  • Teams share administrator credentials in documents, email or chat
  • Password changes are forced so often that users add predictable counters
  • Browser or provider alerts report a reused, exposed or unusual credential
  • A former employee knows a password that has not been rotated or replaced with individual access

Reduce likelihood and impact

Practical steps

  1. 01

    Adopt a reputable password manager

    Use it to generate, store and fill a unique credential for each service, with controlled business sharing where genuinely required.

  2. 02

    Prefer long, unpredictable values

    Generate random passwords or suitably long passphrases rather than personal facts, keyboard patterns or repeated substitutions.

  3. 03

    Use individual accounts

    Avoid shared administrators. Give each person the minimum role needed so access can be reviewed and revoked independently.

  4. 04

    Add MFA and protect recovery

    Use strong MFA where supported and secure the email, backup codes, devices and helpdesk processes used to recover the account.

  5. 05

    Change for a reason

    Replace default, reused or suspected credentials promptly. Do not rely on routine changes that encourage predictable patterns without reducing exposure.

Defined website support

How AHANIX can help

AHANIX can help replace shared or weak access practices for website, hosting, domain and related web-service accounts.

  • Create individual website administrator access with suitable roles
  • Support credential rotation and MFA during a web-account handover
  • Document which business owner controls each web-service recovery route

Clear limits

What this cannot guarantee

  • A strength score cannot prove a password is secret, unique or safe from phishing, malware and provider compromise.
  • AHANIX tools run locally for the stated check, but users remain responsible for secure storage, sharing and account recovery.

Continue with existing resources

Relevant tools and guides

These links use existing AHANIX tools and guides for the next useful check or deeper explanation.

Common questions

Password security questions

How long should a password be?

Longer is generally stronger when the value is unpredictable. Use the service’s supported length and a password manager to generate a unique value rather than aiming for one universal number.

Should passwords be changed every month?

Change default, reused, exposed or suspected passwords promptly. Routine changes without evidence can encourage predictable patterns; follow any specific organisational or regulatory requirement that applies.

Is a passphrase safer than a password?

A long, randomly generated passphrase can be both strong and memorable. A short phrase, quotation or personal sentence may still be predictable.

A scoped next step

Create a unique password in your browser

Use the AHANIX generator, then store the result in a reputable password manager and enable MFA.

Open the Password Generator

Continue in the Security Centre