Dabish Digital
Security

Before you invest in password policies

Every audit we run turns up some version of this. Before you spend anything on password policies, it is worth confirming a few things are already true.

The realistic threat for most small businesses is automated and opportunistic, not targeted. The teams that stay on top of it are the ones who put it on a calendar rather than a wish list.

Prerequisites

  • You can describe the outcome you want in one sentence
  • Someone owns it after the work is done
  • Length beats complexity rules
  • You have a way to tell whether it worked

What to watch for

Forced rotation makes passwords worse, not better. In practice this is a scheduling problem more than a technical one. Check it against what you would want a competitor's site to get wrong.

Check credentials against known breach lists. This is the sort of thing that compounds, quietly, in both directions. Check it against what you would want a competitor's site to get wrong.

In practice

The cheapest security work is the boring kind done on a schedule. Three things worth confirming about password policies before you move on:

  • Someone can say what the current setup is without going to look
  • Length beats complexity rules — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

If any of that sounds like a description of your current setup, it is fixable.