Practical guide
Strong passwords and managing practice credentials
Passwords are the first line of defence for the condominium archive, yet they are also the link most often neglected. A manager handles credentials for the software, email, banking portals, tax services and integrations with public administration: a set that, if handled carelessly, becomes a way in. Weak passwords, reused across several services or shared via chat, expose owners' personal and financial data, which the manager processes as data controller under the GDPR. This guide explains how to build strong passwords, manage them tidily and overcome the riskiest habits without burdening daily work.
What makes a password truly strong
A password's strength depends above all on its length and unpredictability. A long, random sequence is far harder to guess or crack than a short word with a few numbers added. An effective and easy-to-remember strategy is the passphrase: several unrelated words forming a long but memorable sentence, hard to attack precisely because of its length.
Predictable elements should be avoided: proper names, birth dates, the practice's name, trivial keyboard sequences. Automated attacks try the most common combinations first. Adding a capital at the start and an exclamation mark at the end of a known word is not enough: strength comes from length and true randomness, not from small cosmetic variations.
The gravest mistake: reusing the same password
Reusing the same password across several services is the most widespread and most underestimated risk. When any site suffers a breach, the stolen credentials end up in lists that attackers automatically try on other services. If the software's password is the same one used for a forum or an online shop, the compromise of that minor site opens the door to the condominium archive.
The rule is simple: every service must have a different, unique password. Remembering dozens by heart is impossible, and this is exactly where a password manager comes in. The point is not the theoretical strength of a single password, but preventing a single theft elsewhere from compromising all the practice's accounts in a chain.
The password manager: a tool, not a luxury
A password manager is an application that generates, stores and fills in strong, different credentials for each service, protected by a single master password the manager has to remember. It removes the need to jot passwords on sheets, diaries or text files, and lets you use complex credentials without the effort of memorising them.
For a practice it is a particularly useful tool, because it allows the many credentials to be organised in a single protected place. The master password must be chosen with care, made long and unique, and paired with two-factor authentication where available, so that the manager itself is adequately defended and does not become a single point of failure.
The habits to abandon in the practice
Some common practices must be overcome. Sharing a password via chat or email exposes it permanently, because those messages remain stored. Sticking a note with the password on the monitor makes it visible to anyone passing by. Using a single account shared by several staff members erases traceability: you no longer know who did what.
Better to have personal accounts for each staff member, so every operation stays attributable to a person, and to share credentials only through the password manager when strictly necessary. When a staff member leaves the practice, their credentials must be revoked and the shared passwords they had access to must be changed, to close any residual access.
A checklist for practice credentials
A software like AmministraPro pairs strong credentials with two-factor authentication and role-based access, so good password practices fit into a coherent security system. Anyone who wants to understand how access is protected can review the capabilities on the features page and compare the plans on the pricing page.
Frequently asked questions
What makes a password secure?
Above all its length and unpredictability. A long, random sequence, or a passphrase made of several unrelated words, is far harder to crack than a short word with a few numbers. Names, dates and trivial keyboard sequences should be avoided, as automated attacks try them first. Small cosmetic variations do not increase real strength.
Why not reuse the same password across several services?
Because when any site suffers a breach, the stolen credentials end up in lists that attackers automatically try elsewhere. If the software's password is the same as a compromised minor service, that theft opens the door to the condominium archive. Every service must have a different, unique password to avoid chain compromises.
Is a password manager really secure?
A good password manager stores credentials in protected form, accessible only through a single master password. It is far safer than sheets, text files or human memory, because it lets you use strong, different credentials for each service without having to remember them. The master password should be long and unique and, where possible, paired with two-factor authentication.
Can I have staff use a single shared account?
It is not advisable. A shared account erases traceability: you can no longer know who performed a given operation. Better to have personal accounts for each staff member, so every action stays attributable to a person. Credentials should be shared only through a password manager and only when strictly necessary.
What should be done with passwords when a staff member leaves?
Their personal credentials must be revoked without delay and the shared passwords they had access to must be changed. Even a staff member who leaves on good terms retains knowledge of credentials that, if not updated, remain residual access to the condominium archive. Prompt revocation closes this door and should be built into the offboarding procedures.
Try AmministraPro
Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.
