Most password policies in UK small businesses were written from advice that has since been formally withdrawn. Complexity requirements, ninety-day expiry, the rule about a capital letter and a symbol. All of it made passwords worse rather than better, and the National Cyber Security Centre now says so plainly.

Here is the current position and what to actually do about it.

Stop doing three things

Stop forcing regular password changes

Expiry produces predictable behaviour. Summer2026! becomes Autumn2026!. People write them down. Support calls rise. Nothing gets safer.

Change a password when there is reason to believe it has been compromised. Otherwise leave it alone.

Stop mandating complexity rules

Requiring a capital, a number and a symbol pushes everybody towards the same handful of patterns, which is exactly what attackers model. Length matters far more than composition.

Stop treating SMS as good multi-factor authentication

It is much better than nothing and it is the weakest common option. SIM swapping is a real and practised attack in the UK, and codes can be relayed through a convincing fake sign-in page in real time.

Start doing four things

1. Long passwords, and a manager to hold them

Three random words remains sound advice for a password somebody has to remember. For everything else, a password manager generating long random strings is the right answer.

A business plan matters here. It lets you share credentials properly with an audit trail, and revoke access when somebody leaves — as opposed to the shared spreadsheet or the notebook in a drawer, which is what most businesses actually have.

2. Block known-breached passwords

Far more effective than complexity rules. If a password appears in a breach corpus, it is unusable regardless of how many symbols it contains. Microsoft Entra ID does this, and it is a setting rather than a project.

3. Authenticator apps with number matching

Number matching requires the person to type a number shown on the sign-in screen into their app, rather than simply approving. That defeats prompt bombing — the attack where somebody with a stolen password triggers repeated approvals until the user taps accept to make it stop.

It is available in Microsoft Authenticator and should be enforced everywhere.

4. Passkeys, where they are supported

A passkey is a cryptographic credential held on your device and unlocked with a fingerprint, face or PIN. Nothing shared is transmitted, so there is no secret to phish, reuse or leak in a breach.

This is a genuine step change rather than an improvement, because it removes the entire category of attack rather than making it harder. Microsoft 365, Google, Apple and a growing number of business services support them.

Multi-factor authentication makes a stolen password insufficient. Passkeys mean there is no password to steal. The second is a better position to be in.

What to do this quarter

In order of value per hour spent.

  1. Multi-factor authentication on every account, no exceptions. Including administrators, shared accounts and service accounts. The exceptions people carve out are exactly the accounts that get compromised.
  2. Turn off password expiry and turn on breached-password blocking.
  3. Enable number matching and move people off SMS where you can.
  4. Deploy a business password manager and get shared credentials out of spreadsheets and notebooks.
  5. Enable passkeys for Microsoft 365 and let people opt in. Adoption spreads by itself once a few colleagues have tried it.

The accounts people forget

Three categories that reliably sit outside whatever policy exists:

Shared accounts. The social media login, the courier portal, the supplier account. Shared with everybody, changed never, still known to three people who have left. A password manager with proper sharing solves this, and it is the fix nobody gets round to.

Service accounts. Created for an integration years ago, with a password nobody has changed and no second factor because it would break something. These are attractive precisely because they are exempt.

Administrator accounts. The most valuable credentials you have. They need the strongest protection and are the most likely to have an exception carved out for convenience.

On break-glass accounts

One point that catches businesses out. If you enforce multi-factor authentication and conditional access on every account including administrators, you can lock yourself out of your own tenancy.

Keep one break-glass administrator account excluded from conditional access, with a long random password stored physically — in a safe, not in the password manager that also depends on the tenancy — and alert on any use of it.

How this fits with certification

User access control is one of the five Cyber Essentials controls, and multi-factor authentication on cloud services is required. The measures above cover that requirement and go beyond it.

They also close the entry route behind most small business incidents, which matters more than the certificate.

If you would like this configured properly across your business — including the awkward accounts that never fit the policy — our security solutions team does exactly that. Get in touch.