Associated KonsultantsCybersecurity & Risk Consulting Better Business Bureau Accredited Business (opens in a new tab)

Insights · September 2026

When the advice isn’t the problem

I get asked about password managers and multi-factor authentication (MFA) more than anything else — by clients, and by people who are not clients and are never going to be. It comes up at the end of meetings that were about something else entirely.

What strikes me is that almost everyone asking has already heard why it matters — from their bank, their insurer, a son-in-law in technology, and in several cases from me. They ask anyway, week after week.

That tells me the obstacle is not information.

It asks them to change something that has always worked

Using a password manager asks a person to stop doing something that has apparently worked for years.

They remember their passwords. They have a good one — a strong one, with the substitutions and a number or symbol at the end — and they use it in a few places they trust. It has never failed them, and nobody has emptied their bank account. From where they sit, that is years of evidence.

The response I hear most often is “that sounds too complicated for me to remember, plus I don’t trust having all my passwords stored in one place.”

So when I explain how much easier and safer the alternative is, I am not correcting a misunderstanding. I am asking someone to override their own experience — a much harder thing to ask, and it deserves a better answer than “because it’s best practice.”

Why that experience misleads

Password reuse doesn’t fail gradually. There is no early warning, nothing that gets slower or louder first.

And it usually doesn’t fail because of anything you did. It fails because a company you gave that password to — a retailer, a forum, a service you signed up for in 2014 and forgot — is breached. Your password is now on someone else’s spreadsheet, beside your email address, and it gets tried everywhere else. Not by a person; by software, patiently, across thousands of sites.

That is what makes reuse dangerous rather than merely untidy. A single strong password used in six places isn’t six protected accounts. It’s one account with six doors, and you don’t control most of them.

The objections, taken seriously

“That’s all my eggs in one basket.” It is, and it’s the objection I take most seriously, because I used it myself for years. You are concentrating the risk. What you get in exchange is that the basket is defended — encrypted, locked behind a passphrase only you know.

If that’s the worry, make it the question you choose by: pick one that has been independently audited, publishes the results, and encrypts your vault so the company itself can’t read it. Several clear that bar. I won’t tell you which one I use, because mine isn’t better than the others that qualify.

“It’s a nuisance.” Yes, though not much of one after the first week or two. I won’t pretend the friction is imaginary. It costs a few seconds several times a day — less than remembering which version of your password you used, or where you put the list. What it buys is that a stolen password, on its own, stops being enough to get in, and you can change it in minutes.

“I’ll lock myself out.” This is the real fear behind most of the resistance, and it is almost never addressed. It’s the one thing worth extra time at setup, and most password managers walk you through it — recovery codes, a second device, sensible places to keep them.

“My passwords are strong.” Strength was never the common failure. Reuse is. A twenty-character password that turns up on a breached list is exactly as useful to an attacker as a four-character one — everywhere you used it.

Why I tell clients these are foundational

Because it is more than my opinion about good practice. The major security standards treat access control — password management and multi-factor authentication together — as basic hygiene rather than an advanced measure.

It sits in the baseline tier of the Center for Internet Security’s Critical Security Controls — the framework Associated Konsultants scores every client against. Cyber insurance applications now ask about it directly, and when a control moves onto a form you sign, it has stopped being advice.

Not all multi-factor authentication is equal

A code sent by text message is the weakest common form — a phone number can be moved to another device by someone who persuades a carrier they are you. An app that generates codes is better. A passkey or a physical security key is better still.

Any of them is enormously better than none. But if you turned on text-message codes some years ago and considered the matter closed, you bought less than you think — and upgrading is an afternoon, not a project.

Microsoft has now set a date on it: in Entra ID, passkeys become the default from September 2026, and Microsoft’s own SMS and voice delivery retires on February 1, 2027.

What I’d want you to take away

Very little in security is universal. Most of it depends on what your business actually has to protect, which is why I spend so much time telling people that a threat in the news is not automatically theirs.

These two are the exception. They don’t depend on your industry, your size, or what happened to somebody else last week — and they are worth the discomfort precisely because so little else in this field applies to everyone.

If you’d like a straight answer about where your own organization stands, that’s what an assessment is for.

Twenty minutes.

No cost, no presentation. We work out whether there’s a fit — and if there isn’t, I’ll say so and point you somewhere better.

Book a 20-minute call