Security

Passwords, two-factor and the admin login

3 March 2026 · LMJ Web Design

When a small-business website gets hacked, it is rarely a clever attack. It is usually a login page found by a script, a password reused from somewhere else, and no second factor.

Three habits

  1. Unique passwords, in a manager. One password per site, generated, stored in a password manager. You should not know your passwords.
  2. Two-factor authentication on anything that matters. The website admin, the domain registrar, email, and the hosting account.
  3. Fewer admins. Every account is a door. Remove people who have left, and give others the least access that does their job.

What we do on managed sites

Admin logins are protected with two-factor authentication and rate limiting, failed attempts are monitored, and admin access is reviewed when someone leaves the business. It is boring and it works.

If you would like the rest of your setup checked, we offer a security review.

Want a hand with this?

Send a few lines and you get a plain answer within two working days.

Get in touch