Five mistakes teams make with password policies
The version of this that works is simpler than the version most people imagine. These are the ones we run into repeatedly when we audit password policies.
The realistic threat for most small businesses is automated and opportunistic, not targeted. If two people in the business would answer this differently, that gap is the actual problem.
The mistakes we see most
- Treating it as a launch task rather than an ongoing one
- Assuming someone else already owns it
- Length beats complexity rules
- Forced rotation makes passwords worse, not better
- Never checking whether the fix actually worked
Check credentials against known breach lists. Getting it slightly wrong is survivable. Ignoring it entirely is not. Most teams find the first pass takes an afternoon and the maintenance takes minutes a month.
Where to go from here
What this looks like day to day
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about password policies before you move on:
- Someone can say what the current setup is without going to look
- Forced rotation makes passwords worse, not better — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Pick the one that would hurt most if it failed, and start there.