Strong passwords matter: simple steps to protect your business

Today, passwords remain a key line of defence for your accounts, from email and banking to employee systems. But despite growing awareness, many people continue to rely on weak, easy-to-guess passwords—putting sensitive information at risk.

Weak passwords are still everywhere

Every year, cybersecurity experts analyze millions of leaked credentials, and discover unsafe passwords are still being used to “secure” accounts!

Here are the top 10 most common (and weakest) passwords in Canada today, based on data from NordPass, a password management service:

  • admin
  • 123456
  • gallant123
  • password
  • 1hateyou
  • 12345678
  • 123456789
  • ZZZzzz111
  • 12345
  • Password

These “easy to remember” passwords can be cracked in less than a second, making them a top target for hackers.

If any of your passwords look anything like this—or include simple patterns, common words, or predictable sequences—it’s time for an upgrade!

What makes a strong password today?

Guidance regarding passwords has evolved significantly in recent years. Experts now agree that length matters more than complexity.

Here’s what current best practices recommend:

Use long passphrases instead of short passwords

  • Aim for at least 12–15 characters, or longer where possible (The Better Business Bureau, BBB, recommends creating a password of at least 12 characters combining upper- and lower- case letters, numbers and symbols)
  • Consider using a passphrase (e.g., a short sentence or a series of random words)
    • Example: CoffeeTrainMapleRiverSky

Passphrases are harder to crack and easier to remember than short, complex combinations. 

Note: Most websites use strict, automated password validation rules. If you do not include at least one uppercase, one number and one symbol, the system will block you from creating the account, regardless of how long or secure your passphrase is. You can easily satisfy these requirements without losing the security and memorability of a passphrase by adding characters at the ends (example: !CorrectHorseBatteryStaple9) or using symbols as word separators (example: Purple-Turtle-Climb-Mountain-7). 

Make every password unique

Reusing passwords across multiple accounts is one of the biggest risks.

If one account is compromised, hackers can use the same credentials to access others, a tactic known as “credential stuffing”.

Avoid predictable information

Stay away from:

  • Names (family, pets, business)
  • Birthdays or anniversaries
  • Simple substitutions (such as “P@ssw0rd”)

These are among the first guesses cybercriminals will try.

Consider a password manager

Password managers can:

  • Generate strong, unique passwords
  • Store them securely
  • Reduce the need to remember multiple credentials

This is one of the easiest ways to significantly improve your online security.

Add an extra layer: multi-factor authentication (MFA)

Even the strongest password can be compromised. That’s why experts strongly recommend enabling multi-factor authentication (MFA) wherever possible adding a second step (like a code or app verification) to confirm your identity.

A weak password is like leaving the door to your business unlocked

Strengthening your passwords—and your overall login security—is a simple step that can help protect your finances, your data, and your peace of mind.

Need further assistance?

You have questions or need personalized support? Our Business Advisors are here to help:

1-833-568-2342 | hrnow@cfib.ca 

Not a CFIB member? Join today to unlock a wide range of valuable resources designed specifically for small business owners.