In brief
- Use a unique password for every account
- Add protection with multifactor authentication
- Deny any sign-in prompt you did not initiate.
Picture this: You receive a notification one of your accounts has been accessed, no problem, but you quickly realize you didn’t access any of your accounts, so who did?
Your first instinct may be to panic, but no need to fear, the guidance of the IT directorate is here.
The reality is that cyber criminals will try to access accounts by using stolen or guessed passwords and repeated multifactor authentication (MFA) prompts in hopes that someone approves one by mistake. Good news is you have the power to stop the culprit in their tracks by changing your password, using an MFA and staying proactive.
Creating Unique Passwords
Your password should not include your personal information, a recycled password, common phrases or numerical or alphabetical sequences.
Unique passwords include:
- 8-15 characters
- A combination of uppercase and lowercase letters
- Numbers
- Special symbols
Fear your password isn’t strong enough or you’ll forget it? Use a password manager to generate and store them securely.
Be Proactive, Not Reactive
- Ensure your password recovery methods and trusted devices are updated.
- Allow notifications for new devices and unfamiliar locations.
Stay informed about data breaches and scams. If your information has been exposed, verify any notification through the organization’s official website before taking action.
Multifactor Authentication
Consider utilizing multifactor authentication (MFA) wherever possible. MFA adds an extra layer of protection by requiring you to use at least two different verification factors before accessing your account.
- Deny MFA prompts you did not initiate.
- Do not share your MFA codes or passwords with anyone.
Exchange IT personnel or senior leadership will never ask for this information.
A Byte of Humor:
Before we wrap up, here’s a byte of humor followed by the real-world habit that helps keep your accounts secure.
Why did the password bring a friend to the login?
Because it needed MFA support.
Reality: Passwords are stronger when paired with MFA. This can look like a phone-based code, fingerprint, face scan or a security question.
Check out the Exchange Post and @exchangeassoc social channels (Facebook, Instagram and X) every week for Cybersecurity Awareness Month tips and tricks.




Share your thoughts!