The most common cause of data breaches isn't sophisticated hacking - it's weak, reused, or stolen passwords. For Perth businesses, getting password management right is one of the highest-return security investments you can make.
The Problem With How Most Businesses Handle Passwords
Walk into most Perth small businesses and you'll find the same patterns: passwords written on sticky notes, shared login credentials for critical systems, staff reusing the same password across business and personal accounts, and no process for revoking access when someone leaves.
Each of these is a serious risk. When a data breach exposes passwords from one service (which happens constantly), attackers immediately try those same credentials on business email, banking, and accounting systems. This is called credential stuffing - and it's largely automated and highly effective against businesses using reused passwords.
What Makes a Strong Password in 2026
The old advice - mix uppercase, lowercase, numbers, and symbols - is outdated. Modern guidance from the Australian Cyber Security Centre (ACSC) recommends:
- Length over complexity - a passphrase of four random words (“correct-horse-battery-staple”) is more secure than a short complex password and far easier to remember
- Unique passwords for every account - reuse is the real enemy, not password complexity
- Never use personal information - names, birthdays, and business names are guessed first
In practice, the only realistic way to have unique strong passwords for every account is a password manager - no human can memorise dozens of unique 20-character passwords.
Business Password Managers Worth Considering
For Perth businesses, these are the most practical options:
- Bitwarden for Business - open-source, very affordable, excellent security track record. Allows shared vaults for team credentials alongside personal vaults. Strong choice for most SMBs.
- 1Password Business - polished interface, excellent for teams, strong admin controls. Good option if ease of use is a priority for less tech-savvy staff.
- Keeper Business - strong enterprise features, good Australian support presence.
Avoid free consumer password managers for business use - they lack the admin controls, audit logging, and shared vault features businesses need.
Managing Shared Credentials
Many businesses have accounts that multiple staff need to access - social media, shared inboxes, supplier portals. A business password manager handles this through shared vaults - one set of credentials stored centrally that authorised team members can access and use, without ever seeing the actual password. When staff change, access is revoked from the vault without needing to change the underlying password everywhere.
What to Do When Staff Leave
This is where many Perth businesses are most exposed. When a staff member leaves, their access to every system needs to be revoked promptly. A password manager makes this systematic:
- Disable or delete the employee's Microsoft 365 account (this kills access to email, Teams, SharePoint, and anything using single sign-on)
- Remove them from all shared password vault groups
- Change any passwords they had sole access to
- Revoke any MFA app tokens registered to their device
Having a written offboarding IT checklist prevents things from being missed in the rush when someone leaves.
MFA Is the Safety Net
Even with a password manager, enable multi-factor authentication everywhere it's available. If a password is somehow stolen or leaked, MFA is what stops an attacker from using it. Treat MFA and a password manager as a pair - not alternatives to each other.
Frequently Asked Questions
Is a long passphrase actually more secure than a complex short password?
Yes, current guidance favours length over complexity, a passphrase of four random words is both harder to crack and far easier for a person to actually remember than a short password full of symbols. The old advice of mixing cases, numbers, and symbols into a short password is considered outdated now.
Can we just use a free password manager for the whole team?
We wouldn't recommend it for business use, free consumer password managers generally lack the admin controls, audit logging, and shared vault features a team needs. A business-grade option like Bitwarden for Business or 1Password Business isn't expensive and gives you proper oversight.
How do shared logins work with a password manager, like a shared social media account?
A business password manager handles this through shared vaults, one set of credentials stored centrally that authorised staff can use without ever actually seeing the password itself. When someone leaves or changes role, you remove them from the vault rather than having to change the password everywhere they might have written it down.
If we have a password manager, do we still need MFA?
Yes, they're not alternatives to each other. A password manager makes sure passwords are strong and unique, but MFA is the backup that stops a stolen or leaked password from being enough on its own to get an attacker in.
Password manager rollout and MFA enforcement are both part of the cybersecurity protection we provide Perth businesses.
Cybersecurity Services →Want to tighten up password security across your Perth business?
Call 0433 087 091 - we'll recommend and deploy the right password manager for your team size and budget.
Get in TouchFor related reading, see our guides to Cybersecurity Checklist for Perth Small Businesses and EDR vs Antivirus: What Perth Businesses Need to Know.