Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Free Cyber ServicesSecure by design Secure Our WorldShields UpReport A Cyber Issue

Cybersecurity & Infrastructure Security Agency logo America’s Cyber Security Defense Agency National Coordinator For Critical Infrastructure Security and ResilienceCybersecurity & Infrastructure Security Agency logo America’s Cyber Security Defense Agency National Coordinator For Critical Infrastructure Security and Resilience
CISA Logo

Search

 

America's Cyber Defense Agency
 
  • Topics
    Cybersecurity Best Practices
    Cyber Threats and Advisories
    Critical Infrastructure Security and Resilience
    Election Security
    Emergency Communications
    Industrial Control Systems
    Information and Communications Technology Supply Chain Security
    Partnerships and Collaboration
    Physical Security
    Risk Management
    How can we help?
    GovernmentEducational InstitutionsIndustryState, Local, Tribal, and TerritorialIndividuals and FamiliesSmall and Medium BusinessesFind Help LocallyFaith-Based CommunityExecutivesHigh-Risk Communities
  • Spotlight
  • Resources & Tools
    All Resources & Tools
    Services
    Programs
    Resources
    Training
    Groups
  • News & Events
    News
    Events
    Cybersecurity Alerts & Advisories
    Directives
    Request a CISA Speaker
    Congressional Testimony
    CISA Conferences
    CISA Live!
  • Careers
    Benefits & Perks
    HireVue Applicant Reasonable Accommodations Process
    Hiring
    Resume & Application Tips
    Students & Recent Graduates
    Veteran and Military Spouses
  • About
    Divisions & Offices
    Regions
    Leadership
    Doing Business with CISA
    Site Links
    CISA GitHub
    CISA Central
    Contact Us
    Subscribe
    Transparency and Accountability
    Policies & Plans

Free Cyber ServicesSecure by design Secure Our WorldShields UpReport A Cyber Issue

Breadcrumb
  1. Home
  2. Secure Our World
  3. Require Strong Passwords
Share:
Secure Our World Hero Image

Require Strong Passwords

Enforcing a password manager protects your business.

Strong Passwords Mean Safer Business Accounts

Small to medium businesses are a regular target for malicious hackers and a common entry point for digital thieves is stolen or weak passwords.  

But the good news is, you can keep your business safe by requiring employees to use strong passwords and password managers.   

Set the example by using long, random and unique passwords on all your personal and business accounts—and use a password manager to remember them! Then work with your IT staff or provider to require employees to use strong passwords to access your systems. This will keep your data safe and protected. 

Encourage your customers and vendors to also take steps to protect their online accounts, especially when they do business with your organization. 

Encourage Strong Passwords in the Workplace

Create a safer workplace by establishing smart employee password practices.

1. Require strong, unique passwords.

Keep your networks secure by enforcing strong password policies. Strong passwords are:

  • Long—at least 16 characters long (even longer is better).
  • Random—like a string of mixed-case letters, numbers and symbols (the strongest!) or a passphrase of 4 –7 random words.
  • Unique—used for one and only one account.

Speak with your IT department or security manager to require strong passwords. Often, you can create settings that require user passwords to meet certain standards and criteria (such as length). Given the current threat environment, review the policies around customer password strength, and consider increasing those requirements to help them protect themselves. 

2. Provide an enterprise-level password manager for your employees.

An enterprise password manager can be a good step to increase security for a smaller company. A good password manager creates, stores and fills in passwords automatically so you only have to remember one strong password—for the password manager itself.  

Providing a company password manager will make it easier for your employees to use strong passwords and protect themselves, your business and your customers. Read more about password managers here. 

As you grow, you will probably want to move to an identity and access manager (IAM) with single sign-on (SSO) where an identification method enables users to log in to multiple applications and websites with one set of credentials. Check out CISA’s guidance on SSO for SMBs. However, a password manager is a good first step. 

3. Require that default credentials be changed on all software and hardware products.

Many hardware and software products come “out of the box” with default usernames and passwords that are easily exploited. These default passwords may be physically labeled on the device or even readily available on the internet. Require that staff change all default credentials.

Other Ways to Protect Your Business

Online criminals are always looking for easy targets. Businesses that don’t take basic precautions are at risk. Take the following steps to make it harder for malicious actors to access your data or trick an employee into allowing access to your systems.

decorative image of business owner

Secure Your Business

Protect your business, your employees and your customers with easy and effective safety habits and policies.

decorative figure: coworkers looking at a computer

Teach Employees to Avoid Phishing

Phishing happens when criminals trick employees into opening malicious attachments or sharing personal info. Implement training to teach employees how to identify and report suspicious activity.

decorative figure: woman at work

Require Multifactor Authentication

Use more than a password when signing into accounts—such as a texted code, authenticator app or biometrics—to make them much safer than a password alone! MFA protects accounts by requiring additional authentication to prevent access by others.

decorative figure: cashier at the store

Update Business Software

Defects in software, routers, VPNs and apps can give criminals an opening to your accounts. Software manufacturers publish patches, but you must install them to be protected! Don’t use outdated software. Keep business software up to date.

Related Content

SOW Cybersecurity Awareness Month 2024

October is Cybersecurity Awareness Month

Download the free Cybersecurity Awareness Month 2024 toolkit!

woman working on her computer

Weak Security Controls and Practices Routinely Exploited for Initial Access

Share this with your IT provider/staff and encourage best practices to protect your systems.

decorative photo: individual working

Choosing and Protecting Passwords

By choosing good passwords and keeping them confidential, you can make it more difficult for an unauthorized person to access your information.

Social More than a Password Instagram Graphic

More than a Password

Multifactor authentication can make you, and your business, much safer than a password alone. Learn how!

Colleagues gathered around a computer

Cyber Guidance for Small Businesses

Ready for more? 

Get an action plan for your leadership team to implement—before a hacker attempts to steal your info or compromise accounts.

Cyber Guidance for Small Businesses

Return to Secure Our World

Return to top
  • Topics
  • Spotlight
  • Resources & Tools
  • News & Events
  • Careers
  • About
Cybersecurity & Infrastructure Security Agency
  • Facebook
  • X
  • LinkedIn
  • YouTube
  • Instagram
  • RSS
CISA Central 1-844-Say-CISA SayCISA@cisa.dhs.gov
DHS Seal
CISA.gov
An official website of the U.S. Department of Homeland Security
  • About CISA
  • Budget and Performance
  • DHS.gov
  • FOIA Requests
  • No FEAR Act
  • Office of Inspector General
  • Privacy Policy
  • Subscribe
  • The White House
  • USA.gov
  • Website Feedback