Security
Passwords are dying: passkeys, MFA & small-business security in 2026
Eight years ago we wrote a post telling people to use passwords with mixed case, numbers, and symbols. That advice still holds, but it's no longer the conversation.
In 2026, the conversation is: stop using passwords as your only line of defence.
The bad news
- The average breached password in 2025 was eleven characters with mixed case and a symbol. Cracked in under a minute by modern GPU rigs.
- Phishing emails are now AI-generated. They're grammatically perfect, personalised, and sometimes voice-cloned over the phone.
- Reused passwords are still the #1 cause of small-business breaches. One leak, every account compromised.
The good news: passkeys are finally usable
Passkeys (the FIDO2 standard) replace your password with a cryptographic key stored on your device, unlocked with your face, fingerprint, or PIN. They are:
- Phish-proof. A passkey only works on the real domain. Fake login pages get nothing.
- Faster. No typing. Tap, face-scan, in.
- Supported everywhere that matters. Google, Microsoft, Apple, Amazon, GitHub, most banks, and yes, WordPress.
If your platform offers passkeys, turn them on this week.
The 2026 small-business security baseline
The non-negotiable five:
- A password manager for everyone in the business. 1Password, Bitwarden, or Apple Passwords. Generated, unique passwords for every account.
- Multi-factor authentication on everything. Authenticator app (not SMS, SIM-swapping is real).
- Passkeys wherever the platform supports them. Especially email, banking, and your CMS.
- Email security: SPF, DKIM, DMARC, BIMI properly configured. Stops scammers spoofing your domain.
- Staff training on AI-generated phishing. "If it asks you to click, transfer, or share, verify by phone first."
What we set up for clients on Care plans
Every site on our WordPress Care Packages gets:
- Forced 2FA for all admins.
- Limit-login rules and IP-block automation.
- Brute-force monitoring with email alerts.
- File-integrity scans daily.
- A WAF in front of the login page.
It's not glamorous. Neither is having all your customer data on a Russian forum.
The bottom line
Password strength used to be the answer. In 2026, passkeys plus MFA plus a manager is the answer. If you're not there yet, fix it before you need to.