17/06/2026
๐จ THE NEWS: The NCSC is encouraging businesses to move beyond passwords
๐ What happened: The National Cyber Security Centre is now recommending passkeys wherever services support them, with two-step verification used where passkeys are not yet available. Passkeys are designed to make sign-ins easier for users and harder for attackers to phish, guess or reuse.
Why it matters for SMEs:
Passwords remain one of the most common weak points in business security. If staff reuse passwords, use weak passwords, or rely on MFA that is not properly enforced, attackers have an easier route into email, Microsoft 365, cloud systems and business applications.
The key point is simple: identity security is no longer just about having a password policy. It is about making access safer, simpler and harder to compromise.
Hereโs what to take from it:
โ
Passwords are still a risk, especially when reused across personal and business accounts
โ
Passkeys can reduce phishing risk by making fake login pages far less effective
โ
MFA remains essential, particularly where passkeys are not yet available
โ
Identity controls should be reviewed as part of your wider cyber security strategy
Hereโs your practical playbook:
โ
Review which systems still rely heavily on passwords
โ
Enable MFA across all key business accounts
โ
Use passkeys where they are supported, especially for high-risk logins
โ
Enforce strong admin access controls for Microsoft 365 and cloud platforms
โ
Remove dormant accounts and review leaver access regularly
โ
Check conditional access policies, sign-in risk and privileged account protection
Contact us today:
๐ +44(0)20 3457 2089
๐ twc-it-solutions.com
๐ง [email protected]