5 tips for secure passwords: How companies protect their digital identities

Table of Contents

Secure passwords are a key line of defense against cyberattacks. The number of attacks is constantly increasing, and automated methods such as brute force or credential stuffing enable attackers to quickly compromise weak or reused credentials. For companies, data leaks, identity theft, and unauthorized access to business-critical systems are now among the greatest operational risks.

In a corporate context in particular, a single compromised password can have far-reaching consequences —from downtime and data loss to compliance violations. The following guide shows how secure passwords strengthen information security and why systematic password strategies are indispensable for organizations.


Why strong passwords are essential in business

Insecure or reused passwords are among the most common gateways for cyberattacks. Automated tools test thousands of login combinations per second; stolen access data from data leaks is checked en masse against other services.

This creates risks for companies such as:

  • Data loss and financial damage

  • Failure of business-critical processes

  • reputational damage

  • Violations of compliance and data protection requirements (e.g., GDPR)

Strong passwords and clear guidelines are therefore among the fundamental measures of organizational IT security.


5 key tips for secure passwords

1. Use long and complex passwords

The longer a password is, the more resistant it is to brute force attacks. We recommend using at least 12–16 characters, combining:

  • upper and lower case letters

  • numbers

  • special characters

Avoid personal information, dictionary terms, or patterns such as "123456." A strong password is always random, unique, and unpredictable.


2. Use passphrases instead of single words

Passphrases combine several random words to form a long password that is difficult to guess—for example:

"Forest!Coffee7StonePlanet"

This method is easy to remember and also increases password security. The decisive factors are length and unpredictability, not complexity for its own sake.


3. Use a different password for each account

Reusing passwords is one of the biggest risks. If a password is compromised on one service, attackers will test the same credentials on other systems—a classic scenario for credential stuffing.

The following are often affected:

  • email accounts

  • Cloud services (e.g., M365, Google Workspace)

  • CRM/ERP systems

  • Collaboration platforms such as Teams, Slack, or Jira

A unique password for each account prevents a chain reaction of compromised identities.


4. Use password management tools—and enforce central policies

A password manager helps generate strong passwords, store them securely, and fill them in automatically. Employees only need to remember one master password, while the tool ensures consistency and security.

Advantages in a business context

  • Reduction of human error

  • Controlled, secure sharing of access data

  • Transparency regarding passwords used

  • Centralized management of permissions

Important for companies: centralized enforcement of password policies

Modern password management tools make it possible to enforce company-wide guidelines, including:

  • minimum length

  • complexity rules

  • Password history

  • Reuse prohibitions

This means that security guidelines are not only recommended, but technically enforced—a crucial factor for consistent password security in large teams.


5. Enable multi-factor authentication (MFA) – preferably with TOTP authenticator apps

MFA supplements the password with a second factor and provides protection even if a password has been compromised.

Typical MFA methods:

  • Authenticator apps (Time-based One-Time Password / TOTP)

  • hardware token

  • FIDO2 security key

  • SMS codes (only as a last resort, as they are significantly less secure)

Important recommendation: TOTP instead of SMS

Many attacks exploit vulnerabilities in the mobile network or social engineering to intercept SMS TANs. Authenticator apps (TOTP) are therefore considered significantly more secure, as they function independently of the network and use cryptographically generated one-time codes.

Companies should activate MFA across the board—especially for:

  • email

  • cloud services

  • VPN and remote access

  • administrator accounts

  • business-critical applications


How often should passwords be changed?

Modern security standards (NIST, BSI) recommend a pragmatic approach:

  • No forced, regular changes, as this often leads to weaker passwords

  • Change immediately if there is any suspicion of compromise.

  • Companies should also define clear guidelines, e.g.:

    • Password change when roles change

    • Offboarding requirements

    • Comparison against lists of compromised passwords

    • Compliance with technical guidelines (minimum length, history, reuse prohibitions)


Best practices for sustainable password security

  • Never share passwords via email, chat, or on pieces of paper.

  • No storage in plain text (no Excel lists, no unsecure note-taking apps)

  • Use central password managers

  • Activate MFA consistently – preferably TOTP-based methods

  • Conduct regular security awareness training

If these measures are implemented company-wide, the risk of successful attacks decreases significantly.


Conclusion: Strong passwords create security – axsos supports you in this endeavor.

Strong passwords, professional password management, and a consistent MFA strategy form a solid foundation for protecting digital identities. Complemented by clear guidelines, continuous awareness, and modern security tools, this creates resilience that effectively protects organizations.

axsos supports companies in designing password strategies, guidelines, and technical processes in such a way that security is not only created but also maintained in the long term. Review your internal structures and strengthen your organization's information security in the long term.

Share:

Scroll up

Jamil Isayyed

Jamil is an experienced digital process professional, has a rich international background in the information technology and services industry spanning Germany, Greece and Palestine. He holds a Bachelor's degree in Computer Science and a Scrum Master certification from the Scrum Alliance with a focus on Computer Software Engineering. Jamil is passionate about leading and building high-performance teams that deliver exceptional experiences and create valuable opportunities for clients. In addition to his main role, he is the Director of Axsos Academy GmbH. In this role, he leads a dynamic German-Palestinian bootcamp designed to help young people enter the IT market and build a successful career.

Bernd Length

Bernd Länge has been working in the IT industry for over 20 years and advises clients and interested parties on cyber security issues as well as on the development and implementation of information security management and data protection. In this role, he acts as an external data protection and information security officer for clients. It is important to him to take a pragmatic approach and work closely with clients, partners and vendors to ensure that clients' enterprise security is up to date.

Martin Müller

As a technology enthusiast and committed leader, he has been helping companies in the IT sector to shape the future of work for over 20 years. Thanks to his quick thinking and ability to develop effective solutions, he is able to formulate a clear vision of what our future way of working will look like. Step by step, he overcomes challenges and drives us forward into the future. However, he does not accomplish these tasks alone. He has a competent team that he trusts completely and can rely on. Together they overcome every hurdle! Through positive, critical thinking, the second-best solution often leads to incremental success - after all, even an empire wasn't built in a day. This approach makes him unique in his role and he looks forward to working with you on the path to the future.

Rolf Stephan

His enthusiasm for information technology led Rolf to study computer science and graduate from the University of Karlsruhe, now the KIT / Karlsruhe Institute of Technology. Rolf has been working in the IT sector ever since and knows the industry inside out - both nationally and internationally. For more than 25 years, he has focused on international cooperation between experts across all cultures. He also pursued this approach in the first company he founded, AD Solutions AG, which quickly developed into a renowned international IT service provider with several branches in Germany, Switzerland, Austria and the USA. Rolf Stephan has been General Manager since 2010 and CEO of AXON IVY AG, headquartered in Switzerland, since 2021. He has been an investor, shareholder and Chairman of the Supervisory Board of Axsos AG since 2009.

Frank Müller

Frank is a passionate IT expert and visionary entrepreneur. He loves and believes in peace and freedom. For him, these values are more than just words. They are the result of great awareness, responsibility and a solid foundation. His foundation is his faith in Jesus and his unconditional love for people. Frank builds his great visions on this foundation, such as his commitment to peace in the Holy Land. He is not afraid to realize creative and unconventional ideas, such as founding a medium-sized company that spans four countries and cultures and offers its employees a great deal of freedom. Founding a bootcamp academy in the midst of the coronavirus pandemic is certainly one of these ventures. Through these efforts, Frank creates new innovations and added value for his customers and the people who travel with him. With more than 32 years of IT experience and 15 years as an entrepreneur, Frank helps other entrepreneurs focus on their core business and translate their needs into technology opportunities and implementations. His team and he can translate these requirements into a customized IT strategy, processes and technologies. Frank always has a heart for the people he supports and wants to encourage them to break new ground and develop their potential. Frank is open to exchanging ideas with people who see values not as CSR or marketing chatter, but as the basis of their actions. He seeks contact with people who want to change the world for the better. He also welcomes those who are looking for support from him or his team on their journey into the cloud, digitalization or the use of AI.