Password policies, explained without the jargon
Every audit we run turns up some version of this. Here is password policies without the vocabulary that usually surrounds it.
The cheapest security work is the boring kind done on a schedule. It is worth deciding this deliberately rather than inheriting whatever the last person set up.
The short version
Length beats complexity rules. Getting it slightly wrong is survivable. Ignoring it entirely is not. Anything you cannot measure here, you are deciding by taste, which is fine as long as everyone knows it.
Why people complicate it
Most of the confusion comes from tooling rather than from the idea itself. Where this goes wrong is almost never a lack of knowledge.
Forced rotation makes passwords worse, not better. None of that requires a large budget, only a decision and someone to own it. It is worth deciding this deliberately rather than inheriting whatever the last person set up.
What to do next
Check credentials against known breach lists. There is a version of this that is over-engineered, and it is worth avoiding. The practical test is whether someone new to the project could tell, in a minute, that it had been handled.
In practice
The realistic threat for most small businesses is automated and opportunistic, not targeted. Three things worth confirming about password policies before you move on:
- Someone can say what the current setup is without going to look
- Length beats complexity rules — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Pick the one that would hurt most if it failed, and start there.