Technology Resilience Score™
Passwords & Access
Most break-ins don't hack in. They log in.
The vast majority of break-ins start with a stolen or guessed password. Attackers rarely need to defeat your defences — they simply sign in as one of your staff and walk through the front door.
But the reverse is also true. A second verification step is the single most effective barrier you can put up, and it is quick to switch on. Most account takeovers are stopped dead by it.
The Passwords & Access domain of the Technology Resilience Score looks at how your organisation controls who can get into its systems — and whether access follows the person: the right access on day one, cleanly removed the day someone leaves.
If one of your team's passwords was stolen today, would it get an attacker in?
What is Passwords & Access?
Passwords & Access covers how your organisation verifies who is logging in and controls what they can reach — multi-factor authentication, password management, admin rights and the processes that grant and remove access as people join, move and leave. It is the heaviest-weighted domain in the Technology Resilience Score, accounting for 12% of the overall score.
What does Passwords & Access measure?
This domain assesses how well your organisation controls identity and access across its systems. Typical areas reviewed include:
- →multi-factor authentication coverage across email and cloud systems
- →adoption of a password manager across the team
- →restriction of admin rights to those who genuinely need them
- →joiner, mover and leaver processes for granting and changing access
- →regular reviews of who has access to what
- →elimination of shared accounts and shared passwords
- →how quickly and completely access is removed when someone leaves
- →monitoring and enforcement of login security across the organisation
This domain is not just about passwords. It is about making sure access follows the person — nothing more, nothing less.
Why this matters to business owners and operators
Fewer than half of UK businesses (47%) have two-factor authentication in place, according to the UK Government's Cyber Security Breaches Survey. Yet weak login security is the leading cause of business data breaches — and it is also one of the fastest problems to fix, which makes it one of the quickest ways to stand out with clients and insurers. Without strong access control, organisations face:
- →account takeover from a single stolen or guessed password
- →ex-staff retaining access to systems and data long after they leave
- →attackers inheriting admin rights the moment they get in
- →no way of knowing who did what when accounts are shared
- →lost opportunities — contracts, tenders and cyber insurance increasingly require MFA as standard
What weak Passwords & Access looks like
- ✗staff log in with a password only
- ✗passwords are shared between staff or stored in spreadsheets
- ✗ex-staff accounts are still active weeks or months after they leave
- ✗everyone has admin rights, whether they need them or not
- ✗MFA is available but optional — and not everyone uses it
- ✗nobody reviews who has access to what
- ✗shared accounts make activity impossible to trace to a person
- ✗leavers are removed from the payroll faster than from the systems
Each of these is an open door. The encouraging part is that most can be closed quickly — and closing them delivers one of the biggest single improvements available to your resilience.
What strong Passwords & Access looks like
A resilient organisation makes a stolen password useless on its own.
Multi-factor authentication is enforced for all staff across email and every key system — not just available, but required. A password manager gives everyone strong, unique passwords without having to remember them.
Admin rights are restricted to the people who genuinely need them, so one compromised account cannot take over everything.
Access follows the person. New starters have the right access on day one, access changes when roles change, and it is removed cleanly and completely the day someone leaves.
In a strong environment, access control is invisible to staff most of the time — and decisive when it matters.
How this affects your Technology Resilience Score
Passwords & Access is one of the 10 domains assessed as part of the Technology Resilience Score — and at 12% of the overall score, it is the heaviest-weighted of them all. That weighting reflects reality: most breaches start at the login screen, so no other domain moves your score further, faster. Improving this domain helps the organisation move towards a stronger overall score by creating:
Improving this domain helps by creating:
- ✓a barrier that stops most account-takeover attempts dead
- ✓confidence that only the right people can reach your systems and data
- ✓clean, auditable joiner, mover and leaver processes
- ✓a stronger position with insurers, clients and prospective contracts
- ✓one of the fastest available uplifts to your overall score
Improving this domain turns your login screen from your biggest vulnerability into your strongest checkpoint.
How LBT Resilience improves Passwords & Access
LBT Resilience starts with a Technology Resilience Assessment. We assess your organisation across all 10 domains, including Passwords & Access, and give you a clear score out of 5.
We then look at how access works in practice. This includes where MFA is enforced and where the gaps are, how passwords are managed, who holds admin rights and what happens when someone joins, changes role or leaves.
From there, we create a practical improvement plan. This typically starts with enforcing multi-factor authentication across email and every cloud system — the single most effective step — then rolls out password management, tightens admin rights and puts clean joiner and leaver processes in place.
Because support and security are included as part of LBT Resilience, access control is not treated as a one-off project. Accounts, permissions and leavers are managed as part of an ongoing, measurable improvement process.
Find out if a stolen password could stop your business
Most break-ins start at the login screen — and most are preventable with steps that are quick to switch on. The Technology Resilience Assessment gives you a score out of 5, a clear view of your access risk and a roadmap to strengthen it.
Get your Technology Resilience ScoreFrequently Asked Questions
What is multi-factor authentication (MFA)?
A second verification step — such as an app prompt or a code — required alongside a password when logging in. It stops the overwhelming majority of account-takeover attempts, even when a password has been stolen.
Why is Passwords & Access the heaviest-weighted TRS domain?
Because most breaches start with a stolen or guessed password. It carries 12% of the overall score — more than any other domain — so improving it delivers one of the biggest single uplifts to your resilience.
What is a joiner, mover and leaver process?
A defined process for granting the right access when someone joins, adjusting it when their role changes, and removing it cleanly the day they leave — so access always follows the person.
Do many UK businesses use two-factor authentication?
Fewer than half. The UK Government's Cyber Security Breaches Survey found only 47% of UK businesses have two-factor authentication in place — so getting it right is also a way to stand out with clients, insurers and prospective contracts.