The scene repeats itself: an email password leaked, and someone got in. It wasn't a sophisticated attack — it was the same password reused on a personal site, or typed without suspicion into a page that looked legitimate. That was enough. With no other barrier after the password, whoever stole it logged in from anywhere in the world, and no one noticed in time.

According to the 2026 report on data breaches worldwide from Verizon, stolen credentials were for years the most common way an attacker got into a system. This year that path dropped to 13% of the cases analyzed, overtaken by the exploitation of software flaws, now responsible for 31%. The drop doesn't mean passwords got safer — it means other doors are easier to force open today, and the password is still among the most used.

For whoever approves the IT budget, that changes the question. It isn't "is our password strong enough" — a strong password leaks too: typed into the wrong place, saved in the browser of a personal computer, or reused on a service that suffered a breach. The right question is what the company has in place after the password, even the strongest one, falls into the wrong hands.

Why a password alone isn't enough

A password is just something a person knows. If they know it, they can also give it away without meaning to — on a shared screen, in an attachment opened without care, on a call from someone posing as technical support. And if malicious software is installed on the employee's home computer, it copies the password the moment it's typed, without anyone noticing.

There's a type of program built for exactly this: harvesting passwords and access codes stored in browsers and apps, at scale, and feeding that material into a market for stolen data. According to the Microsoft Digital Defense Report 2025, published in October 2025 by Microsoft, fake email or another form of direct deception aimed at an employee was behind 28% of the breaches recorded in that study — and programs built to harvest credentials keep feeding that market.

The problem grows when the same password is used in more than one place. It's common: memorizing dozens of different passwords is impractical, so the employee builds the work password from the same root as the personal one. When one of those other services leaks — and small-service leaks happen every week, without making headlines — whoever holds the leaked password list tries the same combination on the corporate email, the remote access, the bank portal. It doesn't need to work on everyone; it only needs to work on one person.

Unlike an intrusion that knocks a system offline, this kind of entry makes no noise. Whoever arrives with the right password doesn't need to break anything — they just log in, the normal way, from anywhere in the world. Without a specific signal flagging that access as unusual, the company only finds out once the damage has already shown up: an out-of-pattern payment, a client complaining about a strange email, a system missing data.

The usual approach doesn't close the door

The most common way of handling this, in a company that hasn't stopped to think about it yet, is to require a "strong" password — capital letter, number, symbol — and change it every 90 days. It looks disciplined. In practice, it's nearly the opposite: when the change happens only because the calendar says so, with no real reason, people change it the easiest way to remember — swap one number at the end, write it on a sticky note, cycle back to the same password.

The US standards institute that sets the international rules for digital identity, NIST, changed that recommendation. In its most recent authentication document, published in July 2025, NIST says passwords should no longer be changed on a fixed schedule — only when there's concrete evidence they've leaked. The same document recommends at least 15 characters for a password used on its own, rather than forcing a mix of symbols and numbers: longer matters more than more complicated.

That doesn't mean "never change it." It means changing for the sake of changing isn't protection — it's work that gives a feeling of security without delivering security. What actually protects a company is noticing quickly when something leaked and reacting at that moment, not following a calendar that has no idea whether the password is compromised.

Another common approach, and a riskier one, is assuming only the leadership's email inbox deserves extra care, leaving everything else — remote access, the financial system, the network administrator account — protected by nothing but a password. That's the opposite of how it should work: the more an access point can touch money, network configuration, or sensitive data, the sooner it needs an extra layer of protection.

What has to be in place

A well-run IT environment doesn't solve this with an internal reminder to "be careful with your password." It solves it with mechanisms that keep working even when someone makes a mistake.

A second verification step beyond the password on every access that moves money, data, or configuration. Even if the right password falls into the wrong hands, that second step — a code, a notification on a phone — doesn't go to whoever stole it. The account stays locked.

Priority for whoever decides, handles money, and administers the systems. If there's only time to start with one group, start with leadership, finance, and whoever holds administrator access — those are the accounts that cost the most when compromised.

A plan for when a device changes hands. A phone lost, replaced, or stolen is routine, not the exception. The company needs a way to turn off that second verification step the same day and set it up again on a new device, without leaving the account unprotected — or unusable — for days.

Passwords changed on a sign of a leak, not on a calendar. Changing every three months for no reason wears out the team and stops nothing; changing as soon as there's a real, concrete suspicion is what actually closes the door.

A single person watching access across the whole company, instead of every system with its own separate login and no one reviewing who still has access to what they no longer use.

This is how Skills IT works: prioritizing the second verification step on the access points that decide money and configuration, and reviewing who still has access to each system before it turns into a forgotten problem.

What the company gains

The gain isn't abstract. An account protected by a second verification step stays locked even when the password leaks — and that cuts off, at the source, the kind of intrusion that still accounts for a meaningful share of the breaches recorded worldwide, according to the same Verizon study cited above.

There's a time gain that shows up in no report: the IT team stops spending hours reacting to panic — resetting everyone's password in a rush because one leaked, combing through system after system looking for unauthorized access — because the second verification step already closes most of those cases before they become an incident.

There's also a direct financial side. The same Verizon study measured, in a group of third-party vendors serving cloud customers, how long it took those companies to fix the absence of that second verification step once the gap was identified: seven days later, 58% still hadn't fixed it; ninety days later, 42%; and after eight months, nearly a third of the sample was still exposed. Every month of delay is another month with the door open, and the cost of fixing it after an incident is always higher than the cost of setting it up beforehand.

And there's a decision-making gain: when an unusual access shows up, someone knows right away that action is needed — instead of finding out weeks later, by accident, once the damage has already surfaced somewhere else.

A roadmap to get started

Before approving another round of password-strength training, it's worth putting this into practice:

  1. List the five access points that would cause the most damage if compromised. Leadership's email, the financial system, remote access, the network administrator account, and the bank usually make that list.
  2. Turn on the second verification step for those five first. Don't wait until there's time to do everyone at once; start with what hurts the most if it leaks.
  3. Define who turns off access when a phone is lost or replaced, and how quickly — without that plan, the day someone gets a new phone can turn into a week with an account missing its second step.
  4. Stop changing passwords on a fixed schedule for no reason. Change them when there's a real sign of a leak; put the saved effort into what actually protects the company.
  5. Ask who, today, still has access to systems they no longer use. A former employee, an old vendor, a closed project — every forgotten access point is a door nobody is watching.