The Bitwarden Blog
Cybersecurity Advice for Small Businesses from the NCSC
The National Cyber Security Centre (NCSC) is currently highlighting cybersecurity advice for small and medium-sized businesses. Recognizing that many SMBs do not have a budget for a dedicated IT security team, the campaign shares practical recommendations for keeping data secure and preventing unauthorized access. On its SMB security web page, the NCSC notes: “there are some simple steps you can take to ensure you have the basics in place.” Indeed! In fact, the first two recommended actions listed for SMBs are appropriately password-centric:
Action 1: Use a strong and different password for your email using 3 random words
Action 2: Turn on 2-Step Verification (2SV) for your email
The web page goes on to offer a number of resources for SMBs to stay ‘cyber aware’. One of them is a PDF, practical tips for protecting your organization online. Overall, the PDF is very good:
Emphasizes the importance of creating different passwords for each account
Encourages the use of strong passwords
Recommends utilizing two-step verification
Recommends keeping all devices up-to-date
Encourages the backing up of data and key contacts
But, there’s one recommendation worth pausing over: that users should save passwords in their browser. Bitwarden advises individuals and organizations to look beyond their browser and instead prioritize stand-alone password managers. While any password manager is better than no password manager, the security built into third-party password managers is unparalleled. In some cases, browser-based password managers don’t use master passwords to encrypt all logins.
Further, the NCSC should consider recommending password managers directly on its web pages - versus requiring readers to download documents and comb through them. Password managers are a security gamechanger.
.png?eu=898e06b0e3ceaa840639a8816b20686bb66a56feac0434d83931b5a649fa9b8420a2100076c12cb87d6f0bddd5b44bb831902d3410efd3de93b51ea6be3ca2095ad253bf65b07007077ec7f8b3f302436d951d0cf48bcb5ba33f71d0e0b6e3781e57152bfe2bbbd5e9ab3c60e1812f67e9e4a57b61cba120a4561e17c1076ea539eac78b7000bd8ae64eaca5bbed4ad3c2b269184799ad66642d4d4950b06abcbab45d317a6f4718378acb58cf1cf6ef6e793e202c5a47e8343c8556ff693491b7faf209da7f78b4a0c863268fc7fc80ef4ba97824b3cd22b6e6632f616ee842e9e914a8840b665fc269bdca0ee66c666013c75ed06069b64e0ad852c6b01bfc5fa32873746f9da9441583cb9f37d0c256db85709b2bacf47ca4&a=w%3D213%26h%3D97%26fm%3Dpng%26q%3D75&cd=2022-06-22T22%3A39%3A38.166Z)
Overall Bitwarden Assessment: Good
Calls out importance of strong passwords
Cites need for 2FA/MFA to further support password security
Overall security advice is up-to-date
Could improve overall layout so password security advice is clear, digestible, and easy-to-find
Learn what advice other leading cybersecurity agencies offer, and how they compare, in The State of Password Security Report, released earlier this year.
Ready to try Bitwarden? Start a free business trial to help your team stay safe online or sign up for a free individual account.
On this page
Back to Blog