SNM Support

Passwords and MFA for Small Business: The Security Baseline Every Office Needs

Friday afternoon. The office accountant gets an email "from Microsoft" saying her mailbox will be suspended unless she confirms her details. She enters her password — the same one she uses for an online store and her personal social media account. By Monday, the company's customers have received fake invoices with a new bank account number, sent from her real address. This scenario can be prevented by one measure that takes each person a few minutes to set up: multi-factor authentication. In this article you'll see why passwords alone are no longer enough, what modern password guidance says, and how to roll out MFA for small business teams without chaos.

Why a password alone no longer protects you

The problem is rarely that someone "cracks" your password. Much more often, it simply gets stolen or reused.

  • Password reuse — the same password for email, an online store, and a forum. When one of those sites is breached, your password ends up in lists that get sold and shared.
  • Credential stuffing — attackers automatically try millions of leaked email-and-password combinations against Microsoft 365, Google, banks, and VPNs. If your password is reused, sooner or later it will "fit."
  • Phishing — a fake login page that looks like the real one. However complex the password, if an employee types it in there, it's gone. We explain how to recognize these messages in 10 Ways to Spot a Phishing Email.
  • Malware — programs that record keystrokes or steal passwords saved in the browser.

The takeaway: no matter how good the password is, it's only one key. You need a second one.

Modern password rules: length over complexity

Many companies still enforce rules from 15 years ago: "at least 8 characters, an uppercase letter, a number, a special character, change every 90 days." The result is passwords like "Sofia2026!" — followed by "Sofia2026!!" three months later.

In the current version of its SP 800-63B guidelines, the U.S. National Institute of Standards and Technology (NIST) recommends a different approach:

  • Length matters more than complexity. For passwords that are the only line of defense, NIST calls for at least 15 characters; when used together with a second factor, at least 8.
  • No mandatory composition rules. "Uppercase + number + symbol" requirements don't make passwords more secure — just more predictable.
  • No forced periodic changes. Change a password when there are signs it's been compromised — not on a calendar.
  • Check passwords against lists of leaked and commonly used passwords.
  • Allow long passwords and spaces so people can use phrases.

The passphrase

The easiest way to follow these rules is a passphrase: four or five random words, such as "coffee balcony tram blue cloud." It's long, easy to remember, and far harder to guess than "P@ssw0rd1." Avoid quotes, song lyrics, and personal details.

A password manager for the whole team

Nobody can remember 40 unique passwords. So the answer isn't "a better memory" — it's a password manager.

Business editions of tools like Bitwarden and 1Password give an office:

  • a unique, generated password for every service;
  • shared vaults — for accounting or the company's social media accounts, for example — with no passwords in Excel, Viber, or on sticky notes;
  • centralized access removal when an employee leaves;
  • alerts for weak, reused, or leaked passwords;
  • autofill only on the genuine site — an extra layer of protection against phishing pages.

A single strong passphrase protects the vault, and the vault protects everything else. Make sure to turn on multi-factor authentication for the password manager itself.

MFA for small business: which methods are most secure

Two-factor (or multi-factor, MFA) authentication requires something you have — a phone, an app, or a physical key — in addition to your password. According to Microsoft, multi-factor authentication blocks more than 99% of account compromise attacks. But not all methods are equal. Here they are, from weakest to strongest.

Weakest: SMS codes

Better than nothing, but the weakest option. Text messages can be redirected through SIM-swap fraud, and the code can also be typed into a fake site. Use SMS only when a service offers nothing else.

Better: an authenticator app

Apps like Microsoft Authenticator, Google Authenticator, or the one built into your password manager generate a code that changes every 30 seconds, or send a push notification to approve. They don't depend on your mobile carrier and are a sensible standard for most offices.

Strongest: passkeys and physical security keys (FIDO2)

Passkeys and hardware keys such as YubiKey are the most secure choice. They are phishing-resistant — cryptographically bound to the real website address, so they simply don't work on a fake page. Microsoft 365, Google Workspace, and a growing number of services support them. We consider them a must for admin accounts.

Where to turn on MFA first

If you can't do everything at once, start with the accounts that unlock all the others:

  1. Company email — Microsoft 365 or Google Workspace. Email is the key to resetting every other password.
  2. Admin accounts — for cloud services, the server, the router, and the firewall.
  3. Online banking — Bulgarian banks already require strong customer authentication for payments, but review access for every user on the company profile too.
  4. VPN and remote access — a VPN protected by a password alone is an invitation to attackers. More on setting it up securely in How to Set Up a VPN for Secure Work From Home.
  5. Your domain registrar and DNS — whoever takes over your domain takes over your email and website too.
  6. Accounting software, CRM, cloud storage, and the company's social media accounts.

Watch out: MFA fatigue attacks

Attackers know about MFA by now. One of their techniques is MFA fatigue: armed with a stolen password, they send dozens of approval requests in a row until a tired or confused employee taps "Approve." Sometimes they add a phone call "from the IT department."

How to protect yourself:

  • turn on number matching — the employee must type a number shown on the sign-in screen instead of just tapping "Approve" (this is standard behavior in Microsoft Authenticator);
  • teach the team that an unexpected sign-in request means someone has their password — deny it and change the password immediately;
  • set up alerts for suspicious sign-in attempts;
  • for administrators — passkeys or physical keys only.

An office rollout plan

MFA rollouts usually fail because of poor implementation, not the technology. Here's how to make it go smoothly:

  1. Inventory — list every system and account, including shared ones.
  2. Choose methods — an authenticator app for everyone, security keys or passkeys for administrators.
  3. Pilot — start with management and two or three people; iron out the problems.
  4. Short training — 20 minutes: how to set it up, what MFA fatigue is, who to call.
  5. Backup methods and recovery codes — store them securely so nobody is locked out when a phone is lost.
  6. Make it mandatory — with a clear deadline after which sign-in without a second factor is blocked.
  7. Turn off legacy protocols — outdated email sign-in methods that bypass MFA must be disabled.
  8. An offboarding procedure — remove access, devices, and keys on the day someone leaves.

Checklist: the security baseline for every office

  • Every employee has unique passwords, generated and stored in a password manager
  • Passwords are long passphrases, with no forced calendar-based changes
  • MFA is enabled for email, banking, VPN, and cloud services
  • Admin accounts are separate and protected with passkeys or physical keys
  • Number matching is turned on in the authenticator app
  • The domain registrar account is protected with MFA
  • Recovery codes are stored in a safe place
  • There is a clear procedure for when an employee leaves

These measures are part of a bigger picture — see also Cybersecurity for small business — 10 essential measures.

Frequently Asked Questions

What's the difference between 2FA and MFA?

Two-factor authentication (2FA) uses exactly two factors — usually a password plus a code or an approval on your phone. Multi-factor authentication (MFA) is the broader term for two or more factors. In everyday use, the two terms are used interchangeably.

What happens if an employee loses their phone?

That's why a backup method matters — a second key, recovery codes, or an administrator who can temporarily reset the method. With a well-configured setup, a lost phone is a few minutes of inconvenience, not a crisis.

Do we still need to change passwords every 90 days?

According to current NIST guidance — no. Forced periodic changes lead to predictable variations of the same password. Change a password when you suspect it's been compromised, for example if it shows up in a list of leaked credentials.

Is it safe to keep all passwords in one place in a password manager?

Yes, as long as the vault is protected with a long master passphrase and MFA. Reputable password managers encrypt data so that even the provider can't read it. The risk is far lower than with reused passwords, Excel spreadsheets, or notes stuck to monitors.

How SNM Support helps

MFA and a password manager are the fastest, highest-impact security measures for an office — but only when they're rolled out properly and for everyone. We handle the whole process:

  • an audit of accounts and access — who can reach what, and where a second factor is missing;
  • setting up MFA in Microsoft 365 or Google Workspace, on the VPN, and for admin accounts;
  • deploying a business password manager and migrating shared passwords;
  • short team training and support when a phone is lost or a new employee joins;
  • ongoing support through subscription IT support.

Roll out MFA and a password manager for your whole team — get in touch with us for a free initial consultation for your office in Sofia or online.