What to ask your agency about password policies
We end up explaining this on discovery calls often enough that it deserved writing down. If you are briefing an agency or a freelancer on password policies, these questions are worth asking early.
The realistic threat for most small businesses is automated and opportunistic, not targeted. Doing this properly once is usually cheaper than doing it approximately three times.
Questions worth asking
- Who will actually do this work, and have they done it before?
- How will we know afterwards whether it worked?
- What happens if it needs changing in a year?
- What are you assuming that we have not confirmed?
What a good answer sounds like
Length beats complexity rules. This is the sort of thing that compounds, quietly, in both directions. The failure mode is not doing it wrong, it is doing it once and assuming it stays done.
Check credentials against known breach lists. Small and consistent beats large and occasional here. It rarely shows up as a line item, which is exactly why it slips.
The short version
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about password policies before you move on:
- Someone can say what the current setup is without going to look
- Forced rotation makes passwords worse, not better — and you know whether that is true here
- There is a way to tell whether the last change to this helped
If you want a second opinion on how yours is set up, ask.