Knowledge base

August 12, 2025

SME passwords: Secure or dangerous?

 

Many SMBs say, “If it works and is secure, it’s good.” But in practice, password management within organizations often turns out to be one of the biggest weak links in security.
We regularly see situations such as:

  • 📄 Passwords in Excel on the server

  • 📩 Sharing via WhatsApp or email

  • 🗒️ Login information on post-its

  • 🚫 No Multi-Factor Authentication (MFA)

  • 🔄 Simple passwords that rarely change

  • 👤 Ex-employees who still have access

This may seem practical, but it creates major risks for data breaches, phishing and cyberattacks.

The top 8 password problems in SMEs

  1. Everyone knows each other’s passwords – conveniently, until one leaks.

  2. Sharing through insecure channels such as WhatsApp or email – easily intercepted.

  3. Ex-employees with access – unnecessary open doors for data abuse.

  4. Login data on paper – physically and digitally a risk.

  5. Expired passwords become simpler – “Welcome2024!” is not a secure choice.

  6. No 2FA/MFA – one leaky password = direct access.

  7. No visibility into who has access to what – increases the likelihood of misuse.

  8. Rely on browser memory – handy until your laptop is stolen.

 

The implications for your business

These mistakes seem small, but often have major consequences:

  • Higher risk of data breaches (and fines of up to 4% of your revenue under the AVG).

  • Loss of customer confidence after a security incident.

  • Productivity loss when recovering from a hack or phishing attack.

  • Financial loss due to downtime and repair costs.

 

The solution: login without passwords

At ALTA-ICT, we help SMBs transition to modern, secure login without passwords.
Our approach:
✅ Logging in with fingerprint or facial recognition
✅ No more remembering passwords
✅ Secure access via Microsoft 365 & modern workplace
✅ ISO27001, ISO9001 and NEN7510 certified

 

Why take action now?

The recent NIS2 directive and stricter AVG enforcement mean that SMBs no longer have an excuse for using insecure password practices. Investing in secure login methods is not only wise, it is mandatory for many industries.

 

Practical example

A healthcare customer switched to passwordless login with HelloID through ALTA-ICT. Result:

  • 0 password resets in 6 months (previously 30 per month)

  • 100% MFA adoption

  • 90% faster login times

 

Conclusion

Passwords aren’t necessarily the problem – insecure use is. By moving to passwordless and MFA-based solutions, you protect your business, comply with the law and work more efficiently.

💡 S chedule a free consultation
Visit: alta-ict.co.uk/ModerneWerkplek

 

Reference

¹https://www.linkedin.com/posts/altaict_whatsapp-hackers-chrome-activity-7352578020777361408-iiSu

Want to know more?

Get in touch
ALTA-ICT wachtwoordloos inloggen visual met paarse toets en netwerkachtergrond