Close-up view of a mouse cursor over digital security text on display.

What Small AEC Firms Get Wrong About Passwords

Shared logins, passwords on sticky notes, and no MFA are common at small AEC firms. This explains why it matters and what to do about it without making everyone’s life harder.

Close-up image of an electronic safe with a key in Baghdad, Iraq.

First, credit where it is due

You have passwords on everything. You are getting the work out the door. That counts for something, and we are not here to scold anyone.

Here is the honest part. The way most firms handle passwords is built for convenience, not safety. That made sense when nobody was looking. But small firms are getting looked at now. Attackers go after small firms on purpose, because they expect the doors to be unlocked. You are a small fish, but the pond is full.

So the goal is not guilt. The goal is a setup that protects your work without slowing your team down.

You do not need to make everyone’s life harder. You need to make the firm harder to break into.

Mistake 1: Shared logins

This is the big one. One account that the whole office uses. It feels efficient. It is a real risk.

For example: five people share one login. When someone leaves the firm, that password is still in their head. Did anyone change it? Usually not. And when something bad happens on that account, you cannot tell who did what. There is no trail.

You should give every person their own login for every system. Individual accounts mean you can see who did what, and you can shut off one person without locking out the whole team. This is what we call accountability, and shared logins throw it away.

Mistake 2: Passwords on sticky notes (and in spreadsheets)

The sticky note is a cliché because it is everywhere. So is the shared spreadsheet of passwords, or the one in someone’s email.

The problem is obvious once you say it out loud. Anyone who walks by the desk, or opens that file, has the keys. A cleaning crew, a visitor, a hacked email account. The passwords are sitting in plain sight.

The fix is a password manager — a secure app that stores all your passwords behind one strong master password. It remembers the long, ugly passwords so your people do not have to. They learn one password. The manager handles the rest. No more sticky notes, no more spreadsheet.

Mistake 3: Reusing the same password everywhere

People reuse passwords because remembering twenty of them is impossible. That is fair. It is also how one breach becomes ten.

Here is how it goes. A website you used years ago gets hacked. Your email and password leak. Attackers take that pair and try it on everything: your Microsoft 365, your bank, your Autodesk account. If you reused the password, they are in. This is what we call credential stuffing, and it works because people reuse.

A password manager fixes this too. It makes a different long password for every site, so one leak stays one leak.

Mistake 4: No second step to log in

This is the most important fix, and the one too many firms skip. A password alone is one lock. Multifactor authentication (MFA, a second step like a code from your phone or a tap in an app) adds a second lock.

Why it matters: even if someone steals your password, they still cannot get in without that second step. It stops most account break-ins cold. Federal cybersecurity guidance from NIST and CISA pushes MFA hard for exactly this reason.

You should turn on MFA everywhere it is offered. Your email first. Then Microsoft 365 or Google, your Autodesk account, your bank, your remote access. The strongest kind is a physical security key (a small device you tap or plug in), which even blocks fake login pages. A code in an app is a big step up from nothing.

Detailed close-up of a combination lock with numbers in focus, highlighting security and privacy.

What the password rules actually say now

Here is good news that surprises people. The old, annoying password rules have changed, and the new ones are easier to live with. NIST, the federal agency that sets these standards, updated its guidance in 2025. Three things matter for your firm.

Length beats complexity. The old “must have a capital, a number, and a symbol” rules are out. They just pushed people to “Password1!” and a sticky note. NIST now says a long passphrase is stronger. Think four random words, like “correct-stapler-river-cloud.” Easy to remember, hard to crack. Aim for length, not symbols.

Stop forcing resets every 90 days. NIST now says do not force routine password changes. Forced resets just make people pick weaker, predictable passwords. You only need to change a password when there is a real sign it was exposed.

Screen for known-bad passwords. Passwords should be checked against lists of common and already-leaked ones. A good password manager and a properly set up Microsoft 365 can do this for you. The takeaway is freeing: better security here actually means less hassle, not more.

A simple plan for your firm

You do not have to do all of this in a day. Here is the order that gives you the most safety for the least pain.

First, turn on MFA on email and Microsoft 365 or Google. That single step blocks most attacks. Second, get a password manager for the whole team, so everyone can use long, unique passwords without memorizing them. Third, give every person their own login and retire the shared accounts. Fourth, kill the sticky notes and the password spreadsheet.

Being proactive here is far better than reactive. A lot of attacks start with one stolen or reused password. The basics above are what keep that one bad password from becoming a one-week shutdown.

Frequently asked questions

Turn on multifactor authentication (MFA), starting with email and Microsoft 365 or Google. Even if a password gets stolen, MFA stops most break-ins because the attacker still needs your second step.

Yes. NIST’s 2025 guidance says length matters more than symbols. A long passphrase like four random words is both stronger and easier to remember than something like “P@ssw0rd1.” Aim for length.

No. NIST now recommends against routine forced resets. They push people toward weaker, predictable passwords. Change a password when there is a real sign it was exposed, not on a calendar.

Yes, and it is safer than the alternatives. A reputable password manager stores everything behind one strong master password and makes a unique password for every site. That beats sticky notes, reused passwords, and shared spreadsheets by a mile.

We will lock it down without slowing you down

Good password security is not about making your team suffer through impossible rules. It is about setting things up once so the firm is hard to break into and easy to work in. MFA turned on, a password manager rolled out, shared logins retired, and the basics checked.

We help small architecture and engineering firms around Knoxville do exactly that, so your people can focus on the work, not on remembering twenty passwords. If your firm still runs on shared logins and sticky notes, give us a call. We will get the basics in place without making anyone’s day harder.

Key takeaways

  • The common mistakes are shared logins, sticky-note passwords, reused passwords, and no second login step — they feel normal and they are exactly what attackers count on.
  • The rules got easier, not harder. NIST’s 2025 guidance favors long passphrases over complex ones, says stop forcing 90-day resets, and pushes MFA. Better security here means less hassle.
  • Do the basics in order: turn on MFA, roll out a password manager, give everyone their own login, and retire sticky notes. That keeps one stolen password from becoming a week-long shutdown.

Still running on shared logins and sticky notes?

We turn on MFA, roll out a password manager, and lock down your logins without making anyone’s day harder. No obligation, no sales pitch.


Sources: NIST SP 800-63B Digital Identity Guidelines; CISA: Secure Your Business; NIST password guidelines explained (Netwrix)

Similar Posts

4 Comments

Leave a Reply

Your email address will not be published. Required fields are marked *