Do you need a password policy for your business?


  • 06 May 2022
  • Advice, Security


Passwords are one of the first defences against unauthorised access within a business to protect data and any customer information. Many companies need to consider putting a password policy in place to minimise the risk of any unauthorised access that could potentially cause reputational damage.

An effective password policy is a strong set of rules that will be followed for creating passwords and prevent any sensitive data being accessed by unauthorised users.

Here are our top 5 best password policy best practices;

Complex passwords

Ensure all passwords are;

Unique, randomly generated passwords. The password should not create any word, it should be a complete random combination of upper & lower case characters, symbols and numbers

At least 8 characters long.

Be neutral - the password should not contain any factor of the user's personal information such as name, contact number or date of birth.

Mandatory password resets

Making sure passwords are reset every 30, 60 or 90 days will ensure security for your business.

Multi factor authentication -

This ensures authentication before users gain access by having to prove their identity with

  • Something only the user knows; password or an answer to a ‘secret question’
  • One time password (otp) that can be sent to the user
  • Biometrics

You can implement;

  • Two Factor authentication (2FA) using two of the methods above
  • Multi-factor authentication using a range of the methods above

Store passwords on an encrypted database

Using the same password for everything can cause serious security breaches so it's important to use a randomly generated password for everything. Understandably they won’t be easy to remember so to keep track you should store them in  a password manager . It’s highly recommended to use an encrypted password manager to ensure only authorised users gain access.

Limit Login time

Don’t allow users to be logged in indefinitely. Ensure passwords are required at the start of a new session and automatic timed logouts.

Password Audits

This will track your team's passwords and can ensure if passwords meet the security policy. This can highlight any weak points where passwords may need changing to ensure no security compromises.

Implement a password policy into your business now to ensure you all your data is protected!

 


Book a Demo.

To find out more and discuss how we can help test and train your staff contact us to book a demo.

Book a Demo