HomeBlog › Cybersecurity

Password Management for Small Business in Perth — Perth IT Care

20 June 2026·5 min min read· Cybersecurity

There's a password sitting in a leaked database right now that belongs to someone on your team. It might be the same password they're using to log into your Microsoft 365 account this morning. That's not a hypothetical — it's the most common way small business email accounts get compromised, and it's been happening to Perth businesses quietly for years.

Password management for small business in Perth doesn't need to be complicated. But it does need to happen, because the current approach — remembered passwords, shared logins, and the occasional sticky note — is genuinely putting your business at risk under the Privacy Act 1988.

How Attackers Actually Get In

Most people imagine a hacker sitting at a keyboard, furiously trying combinations until something works. That's not what happens.

What actually happens is called credential stuffing. An attacker buys a list — sometimes millions of email and password combinations — from a previous breach somewhere else entirely. A streaming service, a food delivery app, a forum from 2017. They then run that list automatically against Microsoft 365, banking portals, ATO logins, and anything else they can find.

They don't need to crack your password. They already have it. You handed it over the day you reused it.

The vulnerability isn't weak encryption on your end. It's that you used the same password for your work email as you did for a service that got breached three years ago and never told anyone properly.

The Streaming Service Scenario

Here's how it plays out in practice. A staff member signs up for a streaming service using their work email and a password they've been using since forever. That service gets breached — maybe it makes the news, maybe it doesn't. The credentials get packaged up and sold.

An attacker runs the list. Your staff member's work email matches. The password works. Your Microsoft 365 account is now being read by someone in another country, and you won't know until something goes wrong — a client gets a dodgy email from your address, money moves somewhere it shouldn't, or your Microsoft admin raises a flag.

By then the damage is done.

Check Right Now: HaveIBeenPwned

Before anything else, go to haveibeenpwned.com and type in your work email address. It'll tell you whether that address appears in any known data breaches, and which ones.

Do this for every email address in your business. Yes, including the info@ and the admin@ accounts.

If you come up clean, good. If you don't — and statistically, many businesses find at least one hit — you need to treat that account as compromised and change the password immediately.

This takes about two minutes. There's no excuse not to do it today.

What a Good Password Policy Actually Looks Like

The ACSC has been clear on this for a while now, and their guidance has shifted away from what most of us were taught.

Length beats complexity

A 16-character passphrase like correct-horse-battery-staple is harder to crack than P@ssw0rd1! despite looking less impressive. Complexity rules — uppercase, number, symbol — often just make people choose predictable patterns. Attackers know those patterns too.

Unique passwords for every account

One breach should not cascade into a dozen compromised accounts. This is non-negotiable. Yes, Password123! for your work email and Password123!2 for your ATO portal does not count as unique. (We've seen things.)

Change on suspicion, not on a schedule

Forced 90-day rotations sound disciplined, but they produce bad behaviour. People increment numbers, add a season, or rotate between two passwords. The ACSC's position is to change a password when you have reason to believe it's been compromised — not because the calendar said so.

Never reuse across accounts

If a password exists on one service, it should exist only there.

These principles align with the Essential Eight framework, which covers password policies and authentication controls as part of a broader security baseline every Australian small business should know about.

Why a Business Password Manager Is Different From Your Personal One

If your answer to "how do you manage passwords" is "I remember them" or "I use the browser," that's the problem. Browser-saved passwords don't give you the controls a business needs.

A business-grade password manager does several things a personal one doesn't:

  • Team vaults with access controls. You can give a staff member access to specific accounts without handing them the actual password. When they leave, you revoke access. No reset required across twelve services.
  • Admin visibility. You can see whether staff have enabled the tool, whether they're using weak or reused passwords, and flag issues before they become incidents.
  • Breach monitoring. When a known breach drops, the tool checks whether any of your stored credentials appear in it and alerts you — automatically, without you having to remember to check.
  • Microsoft 365 integration. The better tools integrate with your Microsoft 365 environment, which matters when your identity provider is Microsoft Entra ID.

When evaluating options, focus on those criteria: team vault management, admin controls, breach alerts, and Microsoft integration. Don't pick based on which brand runs the loudest advertising campaign.

MFA: The Safety Net When a Password Fails

Even with good password hygiene, you want a second layer. Multi-factor authentication means that a stolen password alone isn't enough to get in. The attacker also needs access to your phone, your authenticator app, or your hardware key — and they don't have those.

This is why MFA matters even if you're doing everything else right. Passwords leak. They get phished. They get shoulder-surfed. MFA limits the blast radius when that happens.

If you haven't configured MFA across your Microsoft 365 accounts yet, that's the single highest-priority item on your security list. Get in touch and we can sort it out for your business.

Need a hand with this?

Perth IT Care can sort it out for you. No jargon, no runaround.

Get in touch