---
title: "Strong Passwords: Payment Data Security Essential for SMBs"
description: Passwords are essential for computer and payment data security. But to be effective, they must be strong and updated regularly.
image: https://blog.pcisecuritystandards.org/hubfs/2017-Blog/smb-passwords.jpg
---

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/strong-passwords-payment-data-security-essential-for-smbs#)

# [Strong Passwords: Payment Data Security Essential for SMBs](https://blog.pcisecuritystandards.org/strong-passwords-payment-data-security-essential-for-smbs)

 Posted by [Laura K. Gray](https://blog.pcisecuritystandards.org/author/laura-k-gray) on 1 Nov, 2017 in [Small Business](https://blog.pcisecuritystandards.org/topic/small-business) and [Passwords](https://blog.pcisecuritystandards.org/topic/passwords) and [QIR](https://blog.pcisecuritystandards.org/topic/qir) and [Small Merchant Resources](https://blog.pcisecuritystandards.org/topic/small-merchant-resources) and [Cyber Security Awareness Month](https://blog.pcisecuritystandards.org/topic/cyber-security-awareness-month)

![smb-passwords.jpg](https://blog.pcisecuritystandards.org/hs-fs/hubfs/2017-Blog/smb-passwords.jpg?width=800&name=smb-passwords.jpg "smb-passwords.jpg")

<https://www.linkedin.com/shareArticle?mini=true&url=https://blog.pcisecuritystandards.org/strong-passwords-payment-data-security-essential-for-smbs>

<https://www.facebook.com/share.php?u=https://blog.pcisecuritystandards.org/strong-passwords-payment-data-security-essential-for-smbs>

<https://twitter.com/intent/tweet?original_referer=https://blog.pcisecuritystandards.org/strong-passwords-payment-data-security-essential-for-smbs&url=https://blog.pcisecuritystandards.org/strong-passwords-payment-data-security-essential-for-smbs&source=tweetbutton&text=Strong%20Passwords:%20Payment%20Data%20Security%20Essential%20for%20SMBs> 

[mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/strong-passwords-payment-data-security-essential-for-smbs](mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/strong-passwords-payment-data-security-essential-for-smbs)

Passwords are essential for computer and payment data security. But to be effective, they must be strong and updated regularly. Weak and vendor default passwords are a frequent source of SMB breaches.

What makes a strong password? Not “password” or “123456”. Criminals try these easily-guessed passwords because they’re used by half of all people. A strong password has seven or more characters and a combination of upper and lower case letters, numbers and symbols (like !@#$&*). A phrase can also be a strong password (and may be easier to remember), like “B1gMac&frieS” (See this [**infographic**](https://www.pcisecuritystandards.org/documents/PCI-Password-Letter.pdf) for quick tips).

Computer equipment and software out-of-the-box (including payment terminals) often come with default or preset passwords such as “password” or “admin”, which are commonly known by criminals. To minimize the risk of being breached, businesses should change these default passwords to strong ones, update them every three months and never share them – each employee should have its own login IDs and passwords.

Need help? Businesses can ask their vendors and service providers to identify default passwords and change them. Additionally, the PCI [**Qualified Integrators and Resellers list**](https://www.pcisecuritystandards.org/assessors_and_solutions/qualified_integrators_and_resellers) is a resource merchants can use to find companies and individuals that have been trained by PCI SSC on strong passwords and other payment data security essentials.

[![SMB Payment Protection Resources](https://no-cache.hubspot.com/cta/default/281302/051d7996-83b7-4951-b7a7-8a5cd046427f.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/051d7996-83b7-4951-b7a7-8a5cd046427f)

[![More on Passwords](https://no-cache.hubspot.com/cta/default/281302/a327175f-07b3-4cfc-b889-584c24d14ac6.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/a327175f-07b3-4cfc-b889-584c24d14ac6)

 

### LIKE WHAT YOU READ?

Subscribe to the PCI Perspectives blog to receive insights, information and practical resources to help your organization protect payment data.

[Subscribe Here](https://training.pcisecuritystandards.org/subscribe-to-pci-perspectives-blog)

![Laura K. Gray](https://blog.pcisecuritystandards.org/hubfs/Headshots/laura-gray.jpg)

[ Laura K. Gray ](https://blog.pcisecuritystandards.org/author/laura-k-gray)

[Twitter ](https://www.twitter.com/pcissc) [Email](mailto:blog@pcisecuritystandards.org) [Website](http://www.pcisecuritystandards.org)

 The PCI Security Standards Council (PCI SSC) is a global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments worldwide.

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/strong-passwords-payment-data-security-essential-for-smbs#)