Passwords, two-factor and the admin login

When a small-business website gets hacked, it is rarely a clever attack. It is usually a login page found by a script, a password reused from somewhere else, and no second factor.
Three habits
- Unique passwords, in a manager. One password per site, generated, stored in a password manager. You should not know your passwords.
- Two-factor authentication on anything that matters. The website admin, the domain registrar, email, and the hosting account.
- Fewer admins. Every account is a door. Remove people who have left, and give others the least access that does their job.
What we do on managed sites
Admin logins are protected with two-factor authentication and rate limiting, failed attempts are monitored, and admin access is reviewed when someone leaves the business. It is boring and it works.
If you would like the rest of your setup checked, we offer a security review.
Want a hand with this?
Send a few lines and you get a plain answer within two working days.
More from the blog

Why a managed website beats a one-off build for most small businesses
A website is not a purchase, it is a running service. Here is what goes wrong with the one-off model and why paying monthly usually works out better.

Editing your own website without breaking it
Every site we build comes with a simple editor. Here is what you can safely change yourself, what to leave to us, and a few habits that keep things tidy.
