Password & MFA for SMBs: The First 3 Steps (2026)
A practical guide for small businesses with no IT staff: which accounts to protect first, what password managers cost, and how MFA methods compare.
Account management means deciding, as a company, how logins and identity verification work across the services you use. In small businesses, breaches usually start not with sophisticated attacks but with reused passwords and departed employees whose accounts were never disabled. This guide covers the first three steps for companies without dedicated IT staff, including cost ranges and decision criteria.
Why passwords alone are not enough
Passwords rely on information only the owner should know. In practice, username and password pairs leaked from one service circulate as lists that attackers try against every other service. If one password is reused, a breach at an unrelated website can become an entry point into your business email or cloud accounting system.
- Reuse: one leak cascades across every service
- Shared accounts: no audit trail, and passwords never change when staff do
- Browser-saved passwords: nothing to hand over or recover when a laptop leaves or fails
- Sticky notes and shared spreadsheets: never collected at offboarding, never updated
None of these are solved by telling people to be careful. They need a mechanism. For how these fit into overall priorities, see Security first steps for small businesses.
Step 1: Rank accounts by the damage a takeover would cause
Trying to lock down every account at once tends to break day-to-day work and get abandoned. Start by ordering accounts by potential damage and working down the list.
| Priority | Example accounts | Damage if compromised |
|---|---|---|
| Highest | Executive and finance email, online banking, corporate cards | Direct financial loss via transfers or invoice fraud |
| High | Microsoft 365 / Google Workspace admin, cloud accounting and payroll | Access to all company mail and HR and payroll data |
| High | Website and e-commerce admin, domain and DNS control | Site defacement; domain hijacking is hard to reverse |
| Medium | Business systems, chat, file sharing | Leakage of customer data and internal documents |
| Low | External research services, news sites | Limited impact — but still never reuse passwords |
Domain and DNS accounts are the most commonly overlooked. It is not unusual to find a domain registered under one employee's personal email that nobody else can access. Track these in the same inventory you use for IT asset management.
Step 2: Adopt one password manager
There is a hard limit to how many passwords a person can remember. The current standard approach is to let a tool generate and store them, so the only thing anyone memorizes is a single master password.
| Approach | Rough cost | Suits |
|---|---|---|
| Free tier of a consumer tool | Free | Trying it out solo; sharing features are limited |
| Business password manager | Roughly USD 2–6 per user per month | 10+ staff needing team sharing, permissions, instant offboarding |
| Built-in features of Microsoft 365 / Google Workspace | Included in existing licenses | Companies already standardized on one cloud platform |
| A spreadsheet | Free | Not recommended — weak on encryption, auditing, and offboarding |
When comparing business tools, the deciding factor should be whether an administrator can revoke a departing employee's access immediately — not price. A patchwork of personal accounts leaves company credentials sitting on former employees' devices.
Step 3: Turn on multi-factor authentication where it matters most
Multi-factor authentication (MFA, or two-step verification) adds a second proof of identity beyond the password, so a leaked password alone is not enough to get in. Methods differ in both strength and friction.
| Method | Strength | Friction and caveats |
|---|---|---|
| SMS codes | Low to medium | Easy to start; vulnerable to number takeover, but far better than nothing |
| Authenticator app codes | Medium to high | Free; decide the phone-replacement migration procedure in advance |
| Push approval | Medium to high | One tap to approve; watch for accidental approval under repeated prompts |
| Passkeys / security keys | High | Resistant to phishing sites; issue two keys in case one is lost |
Rather than a company-wide rollout, enable MFA on the top tier from step 1 first: executives, finance, and administrator accounts. That alone closes the paths with the largest losses. Also decide the recovery path up front — lost or replaced phones locking everyone out is a real and common incident. Print recovery codes and store them in a safe, and keep at least two administrators.
Three gaps that get missed
- Shared accounts: for logins used by several people, it becomes unclear whose device receives the MFA prompt. Split into individual accounts, or move them into the password manager's sharing feature
- Incomplete offboarding: the core business system gets disabled, but cloud storage and third-party SaaS stay live. Build the disable list in advance (Offboarding cloud accounts)
- Vendor accounts: logins issued to a web agency or accounting firm often remain valid long after the contract ends. Make revocation part of contract closeout
Rollout checklist
- Have you inventoried every service and account the company uses?
- Do you know who controls the domain, DNS, and server accounts?
- Have you sorted accounts into roughly three tiers by potential damage?
- Have you chosen a password manager where an admin can revoke access on departure?
- Is MFA enabled on executive, finance, and administrator accounts?
- Have you decided the MFA recovery path (where codes are stored, backup admins)?
- Have you identified shared accounts and decided whether to split or share them properly?
- Do you have a list of accounts to disable at departure, transfer, or contract end?
- Do you know who does what if a leak happens (Responding to a data breach)?
FAQ
Should passwords be changed on a fixed schedule?
Blanket forced rotation is increasingly discouraged, because it tends to push people toward simpler strings or trivial changes like incrementing a trailing digit. It is generally more effective to require long, unique passwords that are never reused, enable multi-factor authentication, and change credentials promptly when a leak is reported or when someone leaves or changes roles.
If everything is in one password manager, isn't a breach of that tool catastrophic?
It does not remove risk entirely, but the likelihood of harm is considerably lower than continuing with reused passwords and sticky notes. That assumes three things: a sufficiently long master password, multi-factor authentication on the manager itself, and recovery material stored somewhere safe.
Does every employee need MFA?
Extending it to everyone is the right end state, but rolling it out to all staff at once tends to cause disruption, so a phased approach starting with executives, finance, and administrator accounts is more realistic. Expanding next to services where a takeover spreads widely — email and cloud storage — is a manageable order.
What should we budget?
Business password managers commonly fall in the range of roughly USD 2–6 per user per month, varying by plan and features. MFA via an authenticator app can be started at no additional cost; hardware security keys add a per-key hardware cost of roughly USD 25–60. The bigger investment at rollout is usually time — inventorying accounts and documenting recovery procedures — rather than money.
What if an employee has no smartphone?
Some staff are reluctant to use a personal phone for work. In that case, options include issuing a hardware security key or using an authenticator application that runs on the PC. If personal devices will be used, agreeing in advance on the scope of business use and who covers any costs avoids friction later.
Summary
Account management is not about buying an expensive product. It is three habits stacked: inventory what you have, stop reusing passwords, and add MFA where the damage would be greatest. Put every company account into a single table, sort by potential damage, and apply a password manager and MFA to the top entries. That alone closes most of the typical intrusion paths aimed at small businesses; company-wide rollout can follow. For the wider picture, see The complete guide to IT risk for small businesses.
Related free tools (no sign-up, instant results)
Feel free to contact us
Contact Us