Read carefully, because that statistic is about first contact only. Across the full attack chain, credential abuse still appears in thirty nine percent of breaches. Attackers get through the door with an unpatched vulnerability, then immediately pivot to harvesting passwords, because that is how they move through the rest of the building.

The number that should actually get your attention is different. Small organizations faced a median of seven credential leak events last year. Not one. Seven.

What that means for a business with no IT staff

Your passwords are already circulating somewhere. Not as a hypothetical. As a near certainty, given that infostealer malware is surfacing thousands of corporate credentials per month from organizational email domains.

There is a further finding worth understanding. Seventy three percent of ransomware victims had an associated credential leak within the same year, and half of those saw the leak within ninety five days before the attack.

Credential exposure is not usually the attack. It is the thing that happens three months before the attack.

You are not defending against somebody guessing your password. You are defending against somebody who already has one, from a service you forgot you signed up for, and is checking where else it works.

The three failures that actually cause this

Not complexity. Not how often you change them. Three specific things.

Reuse. One password across several accounts means one breach compromises all of them. This is how the majority of small business compromises actually happen, and it is entirely a reuse problem rather than a strength problem. A twenty character password reused in four places is worse than four mediocre passwords used once each.

Insecure sharing. The account credentials sent over text message to a contractor in 2023. The spreadsheet named logins. The sticky note. Every one of these persists long after the person needed access, in a place nobody controls.

No offboarding. Somebody leaves, or a project ends, and nobody changes anything. In a small business this is nearly universal, because there is no process and nobody whose job it is.

Notice that none of these are solved by picking better passwords.

What to do, in order

Two things, and the order matters because the first makes the second manageable.

Get a password manager. Any of the reputable ones. The specific product matters far less than having one at all. It generates unique credentials for every account, stores them encrypted, fills them automatically, and gives you a shared vault instead of a text message.

Set it up over an afternoon by adding accounts as you use them rather than trying to import everything at once. The critical ones first: email, banking, domain registrar, website hosting, accounting software.

Your email account is the most important credential you own, because it is the reset mechanism for everything else. Somebody with your email has everything, eventually.

Then turn on two factor authentication. Same priority order. Email, banking, domain, hosting, money movement.

Not all second factors are equal

This is where most guidance stops too early, and the difference matters.

If you do nothing else from this piece, put an authenticator app on your business email today.

Why hardware keys stop the attack that fools everyone

A convincing fake login page captures your password and then asks for your two factor code. You enter it. The attacker relays both to the real site within seconds and is now inside. An authenticator app cannot prevent this, because a code is a code regardless of who asked for it. A hardware key can, because it checks the domain before responding, and a fake domain gets nothing. That is the entire difference, and it is the reason to spend thirty dollars on your email account.

The part nobody plans for

Here is the question specific to a business with one or two people, and it has nothing to do with attackers.

If you were unavailable for three weeks starting tomorrow, could anybody access the bank account, the domain registrar, the hosting, and the email?

For most solo operators the honest answer is no. Every credential is in one head or one device. The business is functionally unrecoverable if something happens to that person, which is a business continuity failure rather than a security one, and it is far more likely to occur than a targeted attack.

The fix is straightforward. Every reputable password manager offers emergency access, where a person you designate can request the vault and receive it after a waiting period you set. Configure it for a spouse, a business partner, or an attorney.

This takes about ten minutes and it is the single most valuable thing in this piece for a business of one.

Offboarding, in a business with no process

When somebody stops working with you, whether an employee, a contractor, or an agency.

  1. 01Remove their access from the shared vault the same day, not eventually
  2. 02Change any password that was shared directly rather than through the vault
  3. 03Remove them from your email platform, project tools, and cloud storage
  4. 04Check whether they had access to social accounts or your business profile
  5. 05Confirm nothing critical was in a personal account only they can reach

Point five is the one that causes lasting damage. A contractor who registered the domain under a personal account, or set up an ad account they own, leaves you with a real problem years later.

The ninety minute version

If this is more than you want to think about, this is the compressed form.

  1. 01Install a password manager and add your five most critical accounts
  2. 02Change any password you know you have reused
  3. 03Put an authenticator app on your email and your bank
  4. 04Configure emergency access for one trusted person
  5. 05Buy a hardware key for your email account
  6. 06Write down which accounts exist and where, and store that in the vault

That is one evening. It closes the three failure modes above, it handles the continuity problem, and it puts you ahead of most businesses your size.

The reason this is worth doing is not that an attacker is targeting you specifically. It is that credential leaks are routine, automated, and constant, and the businesses that get hurt are the ones where a leaked password from a forgotten service still works somewhere that matters.