Small business

97% of identity attacks come down to passwords

Microsoft's latest security report found that more than 97% of identity attacks are password attacks.

1 min readOriginally posted on LinkedIn

Microsoft's latest security report found that more than 97% of identity attacks are password attacks — someone guessing, buying, or already holding a password that works.

Which is why "Zero Trust" stopped being an enterprise buzzword and started being basic hygiene for a 20-person office.

The idea is simpler than the name. The old model trusted anyone already inside the network. Zero Trust checks every sign-in, every time, no matter who you are or where you're sitting. One locked front door versus a badge check on every floor.

Most small firms I talk to assume this is a big project. It usually isn't, and if you're on Microsoft 365 you already own the pieces. Multifactor on every account, no exceptions. Rules that block sign-ins from places your team doesn't work. Devices checked for encryption and updates before they touch company data. Admin accounts treated differently from everyone else's.

Microsoft's own guidance puts multifactor at blocking over 99.2% of account compromise attacks. They now require it to log into their own admin portals — they stopped asking nicely.

The alternative math is the ugly part. A week of scrambling, clients asking who saw their files, and a cyber renewal that suddenly comes with questions.

Worth an hour of review before your next renewal.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions