2 min read
Length beats complexity
The old advice — one capital, one number, one symbol — produced passwords that were hard for humans to remember and easy for computers to guess. The modern rule is simpler: make it long. A passphrase of three or four unrelated words, such as copper-lantern-harbour-42, is far harder to crack than P@ss1! and much easier to type. Aim for at least 14 characters.
The one word to avoid is anything guessable about your company — the trading name, your postcode, the year you incorporated. Those are the first things an attacker tries.
Never reuse it
The biggest real-world risk is not a weak password but a reused one. When another website is breached and its password list leaks, criminals try those same email-and-password pairs on banking and lending sites automatically. If your Credit Corp password is unique, that attack fails on the first try. If it is the same one you use for your email or a shopping site, one unrelated breach can expose your finance account.
Use a password manager
You cannot remember a unique 14-character passphrase for every site — nobody can. A password manager (built into modern browsers and phones, or a dedicated app) generates and stores them for you, so you only remember one master passphrase. It also spots when you have reused a password and warns you. This is the single highest-value habit for account security.
What to do if it may have leaked
If you suspect your password has been exposed — you reused it somewhere that was breached, or you typed it into a suspicious site — change it immediately from your account settings, then turn on two-factor authentication so a leaked password alone is no longer enough. If you cannot get in, follow account recovery.
Frequently asked questions
How long should my password be?
At least 14 characters. A passphrase of three or four unrelated words easily clears that and is simpler to remember than a short, complex string.
Is it safe to store my password in my browser?
Yes — a reputable browser or password manager encrypts stored passwords and is far safer than reusing one weak password everywhere or writing it down.
How often should I change my password?
Only when there is a reason: a suspected leak, a departing colleague who knew it, or a phishing scare. Routine forced changes tend to produce weaker, predictable passwords.
Related reading

Securing your Credit Corp business account: the full guide
The single place to lock down your Credit Corp business account — covering the password, two-factor…
Read →
Setting up an authenticator app for two-factor authentication
Two-factor authentication adds a second step to sign-in: after your password you enter a six-digit code from…
Read →
Setting up a passkey for your Credit Corp account
A passkey replaces your password with your device's own unlock — fingerprint, face or PIN. It is…
Read →
Recovering access if you're locked out
Being locked out is almost always recoverable. Work through it in order: reset your password, use a recovery…
Read →Funding for UK limited companies
Credit Corp lends to your company, not to you personally — short-term working capital with no personal guarantee. See what your business could access.