Hexifer

Your password probably isn't the problem

Strong passwords are only one small part of business security. The account, the access around it and what happens after a mistake usually matter more.

Hexifer · 14 August 2026 · 6 min read

Most conversations about cybersecurity eventually end up at passwords.

Make them longer. Add a number. Add a symbol. Don't use your dog's name.

None of that is bad advice. But for a business, passwords are only one small part of a much bigger picture.

A company can have strong passwords and still leave itself surprisingly exposed.

The account matters more than the password

Imagine an employee uses a genuinely strong, unique password for their Microsoft 365 account.

Good start.

But there is no multi-factor authentication. An old employee still has an active account. Someone has shared access to a mailbox they no longer need. A phishing email leads a member of staff to a convincing fake Microsoft login page.

Suddenly, the strength of the original password isn't doing much.

This is why good business security is less about finding one perfect security product and more about getting lots of relatively ordinary things right.

The UK's National Cyber Security Centre recommends using multi-factor authentication for important accounts and services. MFA adds another check beyond simply knowing the password, making a stolen password considerably less useful to an attacker.

Access quietly builds up

This is something businesses often don't notice.

Someone joins the company and gets access to the systems they need. Six months later they move roles and get access to a few more. Later, they're added to another shared folder.

The old permissions aren't always removed.

Multiply that across an organisation and you can end up with people having access to far more information than their job actually requires.

Then someone leaves.

Was their account disabled? Were active sessions revoked? What happened to shared passwords? Were they removed from third-party platforms as well as Microsoft 365?

These aren't particularly exciting cybersecurity questions.

They're also exactly the questions that matter.

Updates are security work too

Software updates can be irritating, especially when they appear five minutes before a meeting.

But updates frequently contain fixes for known security vulnerabilities.

That includes operating systems, browsers, applications, network equipment and other software businesses rely on.

Keeping systems supported and patched isn't glamorous. It is basic maintenance, but basic maintenance is a surprisingly important part of cybersecurity.

Then there are the people

You cannot completely remove human error.

Someone will eventually click something they shouldn't.

The better question is what happens next.

Can one compromised account give somebody access to everything? Is MFA enabled? Can suspicious activity be detected? Can access be quickly revoked? Are important files backed up appropriately?

Security should assume mistakes can happen and limit what those mistakes can turn into.

Cybersecurity is usually less dramatic than it looks

There doesn't need to be a hooded hacker on six monitors.

For many businesses, improving security starts with much simpler questions:

Who has access to what? Are important accounts protected with MFA? Are devices kept updated? What happens when somebody joins or leaves? Are backups actually usable? Would staff recognise a suspicious login request?

That's the less exciting side of cybersecurity.

It's also the side worth getting right.

Got something in mind?Let's talk about it.