HomeBlog › Security

Technologies & IT Services · Montreux · Swiss Riviera

Passwords and two-factor authentication: the minimum that changes everything

A breakdown, a question?

Three habits are enough to stop the vast majority of account hacks. None requires you to be a technician, and the most effective one takes ten minutes to set up.

Published on 11 August 2026 · 4 min
  • Written without jargon
  • A question we are often asked
  • Updated when the tools change
Eramis
FREN

When an account is hacked, it is almost never because someone “guessed” the password. It is because the same password was used elsewhere, on a site whose user database was stolen. Hackers then try these e-mail and password pairs everywhere, automatically.

1. A different password for each service

This is the most important rule, and the only one that is really tedious without a tool. If your email password is also the one for an online shop, your email is only as secure as that shop.

2. A password manager

It is the tool that makes the rule workable. It creates long, random passwords, remembers them, fills them in for you, and shares them cleanly between colleagues. You only need to remember one: the manager’s own, a long one that you use nowhere else. A phrase of four or five unrelated words does the job very well.

3. Two-factor authentication

As well as the password, the service asks for proof that you have your phone: an approval in an app, or a six-digit code. A stolen password is no longer enough. Prefer an authenticator app to SMS, which is easier to intercept. Turn it on first for your e-mail, because that is what all your other accounts are reset through, then for your bank, accounting and remote access.

What is no longer any use

  • Changing your password every three months: you end up adding a digit at the end. Change it when there is a doubt, not by the calendar.
  • Clever substitutions, “0” for “o”: hackers’ tools know them all.
  • The notebook in the desk drawer: at home, it’s defensible; in a business, it isn’t.

Passkeys

More and more services offer to replace the password with a passkey: you log in with your device’s fingerprint or PIN, and there is nothing left to steal or to type into a fake site. When it is offered, accept.

In a business

A shared password manager avoids the Excel file of passwords and lets you cut off all of a person’s access on the day they leave. Two-factor authentication is a must for everyone, management included: it is often the most targeted account.

In short: one password per service, a manager to remember them, two-factor authentication on your email. We set it up with each person on the team: see Cybersecurity.

Ten minutes per person

Two-factor authentication and a password manager set up with each member of the team.

See the service