To create strong passwords for business accounts, use a long passphrase — four or five unrelated words, at least 15 characters — for the two or three logins you must type from memory, and a randomly generated password for everything else. Length matters more than symbols. The current NIST guidance has dropped forced complexity rules and scheduled password resets entirely.
That is the short version. The longer version is the part almost nobody writes about: in a small business, the passwords that get you breached are rarely the ones you chose. They are the ones you shared.
Why does normal password advice fail a small business?
Almost every guide on this topic assumes one person with one set of personal accounts. A five-person business does not look like that. It looks like one WhatsApp Business number that two people answer, one hosting control panel, one Google Workspace admin login, one WordPress admin account, one Facebook Business Manager, and a payment dashboard only the owner touches.
Nobody memorises those. They get typed into a WhatsApp group, or a note on somebody’s phone, or the back of an invoice.
I build CRM systems, Google Sheets automations and internal tools for small businesses, and the handover is where I see this every time. The client has a strong password on their own email and a shared one on the account that holds the customer data. Creation was never the weak point. Sharing was.
What actually makes a password strong in 2026?
Length. Almost nothing else. The rules changed, and most advice online has not caught up.
NIST Special Publication 800-63B, the US federal standard that most security policies are eventually copied from, is explicit in section 3.1.1.2. Verifiers “SHALL require passwords that are used as a single-factor authentication mechanism to be a minimum of 15 characters in length.” Where multi-factor authentication is in use, the minimum drops to eight characters. Services should permit at least 64 characters.
Two further instructions in the same section matter more than the length numbers, because they reverse what people were taught for twenty years:
- No forced character mixes. NIST states that verifiers “SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types) for passwords.”
- No scheduled resets. NIST states that verifiers “SHALL NOT require subscribers to change passwords periodically” — but SHALL force a change where there is evidence the password has been compromised.
- Breach checking instead. New passwords SHALL be compared against a blocklist of “commonly used, expected, or compromised passwords.”
CISA’s public guidance says the same thing in plainer language: passwords should be long, random and unique to each account.
Why did complexity rules get dropped?
Because they made passwords predictable. Tell a person they need a capital letter, a number and a symbol, and a very large share of them will capitalise the first letter, put the number at the end, and use an exclamation mark. Password-cracking software knows this pattern better than the person using it does. Swapping “a” for “@” and “o” for “0” is the first thing any cracking dictionary tries.
A fifteen-character phrase of ordinary words is harder to crack than an eight-character password full of symbols, and it is the only one of the two you have any chance of typing correctly on a phone keyboard.
How do you create strong passwords for business accounts?
Start by cutting the problem down. You are not trying to remember forty passwords. You are trying to remember three.
Step 1: Decide which passwords you will memorise
There are only three logins that genuinely have to live in your head, because they are the ones that unlock everything else:
- Your laptop or phone unlock.
- Your primary business email account.
- Your password manager’s master password.
Everything else — hosting, WordPress, the CRM, the ad account, the bank dashboard — is stored, not memorised. Trying to remember those is exactly what produces one mediocre password reused across all of them.
Step 2: Build each one as a passphrase
A passphrase is four or five unrelated words strung together. The method:
- Pick words that have no connection to each other. The moment the words form a sensible sentence, you have lost most of the strength. A phrase built from a kitchen object, a colour, a tool and a piece of weather is far better than four words that belong in the same story.
- Do not use anything quotable. No song lyrics, no film lines, no religious verses, no proverbs. Anything that exists as a phrase somewhere on the internet exists in a cracking dictionary.
- Do not use personal facts. Names, your car, your street, your date of birth — all of that is on your own Facebook profile.
- Add one separator and one number, placed consistently. Choose a rule once — for example, a hyphen between every word and a two-digit number in the same position each time — and apply it to all three passphrases. Consistency is what makes it typeable at speed.
- Count the characters. Fifteen is the floor, not the target. Four average words plus separators usually clears twenty.
- Never use an example you read online. Including anything in this article. Published example passwords go into cracking lists within days.
Step 3: Test it before you rely on it
Type the new passphrase ten times in a blank text box, then once on your phone keyboard. If you cannot type it cleanly, it is too long or the word order is awkward, and you will end up writing it down somewhere unsafe within a week. Fix it now rather than later.
Step 4: Turn on multi-factor authentication
A strong password with no second factor is still one leaked database away from being useless. Enable MFA on email, hosting, the bank and the business social accounts first — those four cover most of the damage anyone could do. Prefer an authenticator app over SMS codes.
Which passwords should you never try to remember?
All of the rest. For every account outside those three, generate something random and long, store it, and never look at it again. A generated 20-character string is stronger than the best phrase you could invent, precisely because your brain was never involved.
Our free Smart Password Generator produces these in the browser — set the length to 20 or more, generate, paste it straight into the account and into your password manager. Do not retype it by hand; copying is the point.
The same goes for the things people forget are passwords at all: database users, FTP accounts, API keys, webhook secrets, and the admin account your developer created during a build. In my own client work those are generated at maximum length every time, because no human ever types them.
Which password belongs where? A quick reference
| Account type | How to create it | Where it lives | When to change it |
|---|---|---|---|
| Device unlock | Memorised passphrase, 15+ characters | Your head only | On suspicion of compromise |
| Primary business email | Memorised passphrase + MFA | Your head only | On suspicion of compromise |
| Password manager master | Memorised passphrase, longest of the three | Your head, plus a sealed written copy stored physically | Rarely |
| Hosting, WordPress, CRM, ad accounts | Generated, 20+ characters | Password manager | When a team member leaves |
| Shared team accounts | Generated, or replaced with individual logins | Shared vault, never chat | Immediately on any departure |
| API keys, database and FTP users | Generated, maximum length | Password manager or server config file | On rotation or staff change |
| Guest Wi-Fi | Simple but long; it is not protecting data | Printed or a QR code on the wall | Every few months |
How should a small team share a business password?
The honest answer is that the best way to share a password is to not share one.
Most platforms a small business runs on already support multiple users with different permission levels, and almost nobody uses the feature. WordPress has user roles — an editor does not need the administrator login. Google Workspace gives every staff member their own account. Facebook Business Manager assigns people to assets without handing over the owner’s password. Most hosting panels support additional users too.
Creating a separate account for each person takes about two minutes per platform and removes the sharing problem completely. It also means that when someone leaves, you delete one user instead of changing eight passwords and hoping you remembered them all.
Where a genuinely shared login is unavoidable — a payment gateway with a single seat, a marketplace account, a WhatsApp Business number on one device — three rules hold:
- Never send it in chat. WhatsApp, Telegram, Slack and email keep that message forever, on every device that was ever in the conversation — including the phone of the person who left last year. Use a shared password-manager vault.
- Keep a list of who has it. If you cannot name every person who knows a password, you do not control that account.
- Write it down once, physically, and lock it away. A sealed envelope in a drawer is a legitimate backup for the two or three passwords that would end the business without you. A sticky note on the monitor is not the same thing.
For guest Wi-Fi, skip the sharing question entirely — generate a Wi-Fi QR code with our QR Code Generator and print it for the wall. Visitors connect by scanning, and the password stops being read aloud across the office a dozen times a day.
What about handing credentials to a developer or agency?
Create them a named account with the lowest access level the work requires, and delete it when the project ends. If a file genuinely has to change hands — a migration export, a config file — send it through a link that expires rather than a permanent email attachment; our Simple File Share Tool is one way to do that. Then rotate anything that was in the file. Treat any credential that has travelled outside your own systems as temporary.
What should you do when someone leaves the team?
NIST removed the ninety-day reset rule, but it kept the requirement to force a change when there is evidence a password is compromised. A departure is that evidence, for every shared login that person could see.
A workable offboarding list for a small business, in order:
- Disable their individual accounts — email first, then everything tied to that email for password resets.
- Change every shared password they had access to, using generated values.
- Remove them from Business Manager, ad accounts and any marketplace or bank dashboard.
- Revoke API keys and app passwords they created.
- Check which devices are still signed in, and sign them all out. Most platforms have an active-sessions screen; changing a password does not always end an existing session.
- Check the recovery phone number and recovery email on your main accounts. A departing staff member’s number left sitting in a recovery field is the single most common thing I find.
Frequently asked questions
How long should a business password be?
At least 15 characters where the password is the only factor, and at least 8 where multi-factor authentication is switched on, according to NIST SP 800-63B section 3.1.1.2. For generated passwords, 20 or more is sensible because you never type them.
Is a passphrase really safer than a complex password?
Yes, when it is long enough and the words are unrelated. A twenty-character phrase of ordinary words has more possible combinations than an eight-character password with symbols, and it survives being typed on a phone. NIST now prohibits services from forcing character-type rules at all.
Should a small business force staff to change passwords every 90 days?
No. NIST SP 800-63B states that verifiers shall not require periodic password changes, because forced resets push people toward small predictable edits. Change a password when there is a reason: a breach notification, a lost device, or a team member leaving.
Is it safe to share a password over WhatsApp?
No. The message stays in the chat history on every device in that conversation indefinitely, including devices belonging to people who have left the business. Use a shared password-manager vault, or give each person their own login instead.
Do I still need a password manager if I use passphrases?
Yes. Passphrases solve the two or three logins you have to type from memory. A password manager solves the other forty, which should be randomly generated and never memorised at all.
The part that matters
Three memorised passphrases, everything else generated and stored, individual logins instead of shared ones wherever the platform allows it, and a departure checklist you actually run. That is the whole system, and it takes an afternoon.
Most small businesses do not have an access problem because they picked bad passwords. They have one because nobody ever decided who is supposed to have access to what — and that only surfaces during a handover, an audit, or the week after someone resigns.
If your business data is spread across spreadsheets, WhatsApp threads and a half-configured CRM, and you want it consolidated into one system with proper per-user access, that is the work I do. I build custom CRMs, Google Sheets automations and business workflow systems for small teams. Get in touch through the contact page and tell me what your current setup looks like.