← Security Center

Passwords & MFA

Attackers don't break in; they log in. Here's how to take stolen passwords off the table.

Why passwords are the #1 target

Attackers rarely "hack" their way in; they log in. Billions of stolen passwords from past breaches circulate freely, and automated tools try them against every service you use. If you reuse a password anywhere, one breached website can unlock your email, your bank, and your work accounts.

The two rules that matter most: use a different password for every account, and turn on multi-factor authentication (MFA) everywhere it's offered, starting with your email. Do those two things and you're ahead of 90% of the internet.

Build passwords that hold up

Get a password manager

Nobody can remember 80 unique strong passwords, and you shouldn't try. A password manager generates, stores, and fills them for you, locked behind one strong master passphrase. Browser-built-in managers are fine; dedicated apps add sharing and breach alerts for teams.

Multi-factor authentication (MFA)

MFA adds a second proof of identity: something you have (your phone, a security key) on top of something you know. Even if your password leaks, the attacker hits a wall.

Two MFA scams to know:Push fatigue: an attacker with your password triggers approval prompts until you tap "Approve" just to make them stop. Never approve a login you didn't start. ② Code harvesting: someone calls "from support" and asks you to read them the code you were just texted. No legitimate company ever asks for that code. Ever.

Do this today

Want MFA rolled out across your business?

We set up password managers and MFA for whole teams, with zero drama.