Over 24 billion stolen credentials are estimated to be circulating on criminal marketplaces at any given time — the byproduct of years of breaches at other companies, most of which have nothing to do with you. If any employee has ever reused a password across a work account and a breached personal account, that credential pair is likely already for sale. For remote and hybrid teams, where there's no office network to fall back on, credentials are effectively the entire perimeter.

Why credential theft matters more for remote teams

In an office, a stolen password alone often isn't enough — there may be network-level protections, physical access controls, or IT staff nearby to notice something odd. Remote work removes most of that. If a password (or a session token stolen via malware) works, an attacker can log in from anywhere, at any hour, and look exactly like a legitimate remote employee.

Setting up MFA properly

Not all MFA is equal

SMS-based codes are better than nothing but are vulnerable to SIM-swapping and interception. Authenticator apps (push notification or TOTP code) are significantly stronger. Hardware security keys are the strongest option and increasingly practical for admin and finance roles specifically.

Enforce it everywhere, not just email

MFA on email alone leaves VPN, cloud admin consoles, accounting software, and CRM systems exposed. Attackers specifically target whichever system doesn't have MFA enabled — that becomes the weak point the rest of your security stack doesn't help with.

Watch for MFA fatigue attacks

A newer tactic floods a user's phone with repeated push notification prompts until, out of annoyance or confusion, they approve one. Number-matching MFA (where the user must enter a code shown on the login screen, not just tap 'approve') largely defeats this and is worth enabling wherever your provider supports it.

Password managers: the other half of the equation

MFA protects you when a password is stolen. A password manager reduces the odds it gets stolen or reused in the first place.

Unique passwords per account, generated automatically. The core problem a password manager solves is password reuse — the reason one breached website can compromise your work accounts too. A password manager makes using a unique, long, random password for every account as easy as using a weak one.

Business-tier, not personal-tier. Business password manager plans add centralized deployment, shared vaults for team credentials (so nobody is texting passwords), deprovisioning when someone leaves, and visibility for IT into weak or reused passwords across the organization.

Built-in phishing resistance. Most password managers only autofill credentials on the exact legitimate domain they were saved for. This quietly blocks a large share of phishing attempts, since a lookalike domain won't trigger the autofill and gives the user a moment to notice something's wrong.

A realistic rollout plan

Start with your highest-risk systems: email, VPN or remote access, and financial software. Enable MFA there first, ideally with number-matching or hardware keys for anyone with admin or payment authority. Roll out a business password manager alongside it, with a short training session — adoption is the real barrier, not the technology.

Need help rolling this out across a remote team? Find your plan or book a free 15-minute call.