How to create a good password, why every employee needs a password manager, and which accounts should get MFA first.
Company accounts are most often compromised not by sophisticated attacks, but by weak passwords or passwords reused across several services. It only takes one website leaking a password — and an attacker will try the same password on your email, your accounting software or Microsoft 365.
What a good password looks like
- Length matters more than complexity. At least 12–14 characters. A passphrase is even better, for example:
window-coffee-blue-2026. - A different password for every service. Password reuse is the single biggest risk.
- Don’t use names, birth dates, your company name or combinations like
123456andqwerty. - Don’t write passwords on sticky notes, in Excel files or in messengers. If you must share a password, use a one-time, self-destructing link — for example, a ICOMP Pass secret note: the link disappears after it is read once.
Password managers
Remembering dozens of unique passwords is impossible — that’s what password managers are for. They keep passwords in one protected place, which makes using a different, strong password for every service easy.
Our team’s product — ICOMP Pass — the first secure Georgian password vault. Two-factor authentication is mandatory, the “password health” check shows weak, reused and outdated passwords, and saved passwords are checked against known breaches — without the password ever being sent anywhere.
Two-factor authentication (MFA)
MFA means that after the password, the system asks for an additional confirmation — from a phone app or a physical security key. An attacker who obtains the password is stopped by this second step.
Enable MFA first on:
- Corporate email (Microsoft 365, Google Workspace);
- Banking and accounting software;
- Remote access (VPN, Remote Desktop);
- Administrator accounts — servers, routers, hosting, domains.
💡 Tip: An authenticator app (Microsoft Authenticator, Google Authenticator) is better than SMS codes — SMS is comparatively easy to intercept.
For businesses: 3 rules
- When an employee leaves, disable all their accounts — email, VPN, CRM, file server — the same day.
- Administrator rights only for those who truly need them. Everyday work — with a regular account.
- Keep an account inventory — know which services you use and who has access.