Password Security in 2020 – Part 2

Feb 17, 2020 | Cyber Security, IT News

In our last blog, we covered some generalized password advice that everyone should know. Unfortunately, there is no such thing as a password that can’t be hacked. Phishing scams and malware infections are ongoing problems, and now that we’re in 2020, these serious cyberthreats are on the rise and quickly making traditional password security depreciated.

But the good news is, current efforts to phase out passwords are also giving rise to additional security methods that can (and should) be used in conjunction with standard account protection practices. In today’s article, we’re outlining some very necessary steps to take in addition to simply coming up with a strong password.

Every Account Should Have 2FA.

We briefly covered what two-factor authentication, or 2FA, means when we were discussing some of the features offered by Microsoft Azure’s security dashboard. The typical and most commonly seen 2FA method is a simple text message with an authentication code sent to your phone or other mobile device. It’s rather basic and by no means foolproof, as even mobile data can be intercepted to steal your 2FA confirmation. However, it’s an extra hurdle for a malicious actor to overcome and has proven to be effective. In most cases, it works. And if nothing else, you’re more likely to be left alone in lieu of an easier target. So, make sure you use it!

Consider Using a Password Manager.

Harken to our earlier statement about avoiding the temptation to use the same password across multiple accounts. If you really have a lot of passwords (and yes, many of us do these days), consider using a strong password manager such as LastPass or Dashlane. How a password manager typically works is you enter all of your existing account logins into the manager. Then, the manager strongly encrypts them all, and when you need to log into an account, you simply sign in through your password manager which has its own password and log-in process.

Do you remember what we said about creating a long password? You want your manager’s password to be especially long and complex, as it’s going to be housing everything. And you want to make sure that account has 2FA protection as well. This is the ultimate solution for keeping all your accounts in one place in as secure a manner as possible.

There is an important caveat to password managers to remember, however. If your device that uses a password manager is ever physically stolen, so is access to all of your accounts. Additionally, even the most popular manager can have bugs and possible exploitations. That being said, should you still use one? The answer is yes.

Never Share Your Passwords.

Password Security in 2020 - Part 2

Photo Credit: People photo created by freepik – https://www.freepik.com/free-photos-vectors/people

This should sound like a no brainer, but the truth is, “social engineering” (more commonly known as phishing) has become frighteningly complex over the last decade. Scammers have become exceptionally good at exploiting human psychology, and it’s getting easier and easier to be tricked into giving up a password or a “secret question” answer to someone.

Whether it’s a coworker, someone claiming to be from tech support, or even your own boss, your password is yours, and you should never divulge it under any circumstances. This is critical to not only your own personal data security, but also that of your entire organization.

Protect Yourself From Malware.

If social engineering is the man trying to talk you into opening your safe, malware is the man who uses dynamite to blow it open. (And phishing can be used to trick you into holding the stick of dynamite, by downloading the malware in the first place.)

Malware comes in many different varieties. Some are “keyloggers” which record your actual keystrokes, which in turn reveals what you type to log into an account (as well as all sorts of information you tap out on your keyboard). Others outright take control of your system altogether, which in turn gives the attacker access to your accounts that are stored on said system — much like if the device had been physically stolen.

We’ve published numerous articles on how to protect yourself from malware for this very reason. On the part of the consumer, it’s a lot to take in and remember. And it’s exhausting. It’s unfortunate that we live in a world where the burden always seems to fall on the shoulders of those who just want to go about their business in peace. At V2 Systems, we strive to take as much of that burden away from you as possible. Our advice is meant to both inform and protect you, but we can offer much more than advice. Call us and allow us to stand watch for you, so that you can focus on what’s most important: your actual business.

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

More From V2 Systems

What Government Contractors Get Wrong About Secure Cloud Environments

Secure cloud environments require more than moving files into Microsoft 365, SharePoint, or another cloud platform. For government contractors, controlled access, proper configuration, CUI scoping, enclaves, and shared system responsibilities all matter. This blog explains what GovCons often get wrong about cloud security and how to stay aligned with current CMMC expectations.

Hybrid Work in 2026: The Endpoint Problem That Never Went Away

Hybrid work is now a normal part of business, but the endpoint problem never went away. Laptops, mobile devices, remote access tools, and unmanaged personal devices can create cybersecurity risk when they are not properly secured. This blog explains how small businesses and government contractors can strengthen endpoint security in 2026.

CMMC Update: What Government Contractors Need to Know as of August 2026

The Department of War announced the immediate suspension of CMMC Phase II requirements on July 13, 2026, pausing upcoming third-party assessment mandates. However, Phase I self-assessments, NIST SP 800-171 Rev. 2, DFARS 252.204-7012, and core cybersecurity obligations remain active. This blog explains what government contractors need to know as of August 2026 and how to stay prepared during the review period.

Summer Cyber Risks: Why Attacks Spike When Teams Are Short-Staffed

Summer vacations, lighter staffing, remote work, and busy schedules can create cybersecurity gaps for small businesses and government contractors. This blog explains why attackers take advantage of short-staffed teams and what organizations can do to reduce risk during the summer months.

Why Security Awareness Training Fails and How to Fix It

Security awareness training often fails because it is too generic, too infrequent, or too disconnected from how employees actually work. This blog explains why annual training alone is not enough and how small businesses and government contractors can build a more practical, ongoing approach to cybersecurity awareness.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic