Skip to main content
株式会社オブライト
Business DX2026-07-287 min read

Password & MFA for SMBs: The First 3 Steps (2026)

A practical guide for small businesses with no IT staff: which accounts to protect first, what password managers cost, and how MFA methods compare.


Account management means deciding, as a company, how logins and identity verification work across the services you use. In small businesses, breaches usually start not with sophisticated attacks but with reused passwords and departed employees whose accounts were never disabled. This guide covers the first three steps for companies without dedicated IT staff, including cost ranges and decision criteria.

Why passwords alone are not enough

Passwords rely on information only the owner should know. In practice, username and password pairs leaked from one service circulate as lists that attackers try against every other service. If one password is reused, a breach at an unrelated website can become an entry point into your business email or cloud accounting system.

- Reuse: one leak cascades across every service
- Shared accounts: no audit trail, and passwords never change when staff do
- Browser-saved passwords: nothing to hand over or recover when a laptop leaves or fails
- Sticky notes and shared spreadsheets: never collected at offboarding, never updated

None of these are solved by telling people to be careful. They need a mechanism. For how these fit into overall priorities, see Security first steps for small businesses.

Step 1: Rank accounts by the damage a takeover would cause

Trying to lock down every account at once tends to break day-to-day work and get abandoned. Start by ordering accounts by potential damage and working down the list.

PriorityExample accountsDamage if compromised
HighestExecutive and finance email, online banking, corporate cardsDirect financial loss via transfers or invoice fraud
HighMicrosoft 365 / Google Workspace admin, cloud accounting and payrollAccess to all company mail and HR and payroll data
HighWebsite and e-commerce admin, domain and DNS controlSite defacement; domain hijacking is hard to reverse
MediumBusiness systems, chat, file sharingLeakage of customer data and internal documents
LowExternal research services, news sitesLimited impact — but still never reuse passwords

Domain and DNS accounts are the most commonly overlooked. It is not unusual to find a domain registered under one employee's personal email that nobody else can access. Track these in the same inventory you use for IT asset management.

Step 2: Adopt one password manager

There is a hard limit to how many passwords a person can remember. The current standard approach is to let a tool generate and store them, so the only thing anyone memorizes is a single master password.

ApproachRough costSuits
Free tier of a consumer toolFreeTrying it out solo; sharing features are limited
Business password managerRoughly USD 2–6 per user per month10+ staff needing team sharing, permissions, instant offboarding
Built-in features of Microsoft 365 / Google WorkspaceIncluded in existing licensesCompanies already standardized on one cloud platform
A spreadsheetFreeNot recommended — weak on encryption, auditing, and offboarding

When comparing business tools, the deciding factor should be whether an administrator can revoke a departing employee's access immediately — not price. A patchwork of personal accounts leaves company credentials sitting on former employees' devices.

Step 3: Turn on multi-factor authentication where it matters most

Multi-factor authentication (MFA, or two-step verification) adds a second proof of identity beyond the password, so a leaked password alone is not enough to get in. Methods differ in both strength and friction.

MethodStrengthFriction and caveats
SMS codesLow to mediumEasy to start; vulnerable to number takeover, but far better than nothing
Authenticator app codesMedium to highFree; decide the phone-replacement migration procedure in advance
Push approvalMedium to highOne tap to approve; watch for accidental approval under repeated prompts
Passkeys / security keysHighResistant to phishing sites; issue two keys in case one is lost

Rather than a company-wide rollout, enable MFA on the top tier from step 1 first: executives, finance, and administrator accounts. That alone closes the paths with the largest losses. Also decide the recovery path up front — lost or replaced phones locking everyone out is a real and common incident. Print recovery codes and store them in a safe, and keep at least two administrators.

Three gaps that get missed

- Shared accounts: for logins used by several people, it becomes unclear whose device receives the MFA prompt. Split into individual accounts, or move them into the password manager's sharing feature
- Incomplete offboarding: the core business system gets disabled, but cloud storage and third-party SaaS stay live. Build the disable list in advance (Offboarding cloud accounts)
- Vendor accounts: logins issued to a web agency or accounting firm often remain valid long after the contract ends. Make revocation part of contract closeout

Rollout checklist

- Have you inventoried every service and account the company uses?
- Do you know who controls the domain, DNS, and server accounts?
- Have you sorted accounts into roughly three tiers by potential damage?
- Have you chosen a password manager where an admin can revoke access on departure?
- Is MFA enabled on executive, finance, and administrator accounts?
- Have you decided the MFA recovery path (where codes are stored, backup admins)?
- Have you identified shared accounts and decided whether to split or share them properly?
- Do you have a list of accounts to disable at departure, transfer, or contract end?
- Do you know who does what if a leak happens (Responding to a data breach)?

FAQ

Should passwords be changed on a fixed schedule?

Blanket forced rotation is increasingly discouraged, because it tends to push people toward simpler strings or trivial changes like incrementing a trailing digit. It is generally more effective to require long, unique passwords that are never reused, enable multi-factor authentication, and change credentials promptly when a leak is reported or when someone leaves or changes roles.

If everything is in one password manager, isn't a breach of that tool catastrophic?

It does not remove risk entirely, but the likelihood of harm is considerably lower than continuing with reused passwords and sticky notes. That assumes three things: a sufficiently long master password, multi-factor authentication on the manager itself, and recovery material stored somewhere safe.

Does every employee need MFA?

Extending it to everyone is the right end state, but rolling it out to all staff at once tends to cause disruption, so a phased approach starting with executives, finance, and administrator accounts is more realistic. Expanding next to services where a takeover spreads widely — email and cloud storage — is a manageable order.

What should we budget?

Business password managers commonly fall in the range of roughly USD 2–6 per user per month, varying by plan and features. MFA via an authenticator app can be started at no additional cost; hardware security keys add a per-key hardware cost of roughly USD 25–60. The bigger investment at rollout is usually time — inventorying accounts and documenting recovery procedures — rather than money.

What if an employee has no smartphone?

Some staff are reluctant to use a personal phone for work. In that case, options include issuing a hardware security key or using an authenticator application that runs on the PC. If personal devices will be used, agreeing in advance on the scope of business use and who covers any costs avoids friction later.

Summary

Account management is not about buying an expensive product. It is three habits stacked: inventory what you have, stop reusing passwords, and add MFA where the damage would be greatest. Put every company account into a single table, sort by potential damage, and apply a password manager and MFA to the top entries. That alone closes most of the typical intrusion paths aimed at small businesses; company-wide rollout can follow. For the wider picture, see The complete guide to IT risk for small businesses.

Feel free to contact us

Contact Us