Signs it is time to revisit password policies
Teams tend to reach for this after something has already gone wrong. A few signals that password policies is due some attention.
Security is a maintenance habit rather than a purchase, which is why it drifts. Doing this properly once is usually cheaper than doing it approximately three times.
The signals
- Nobody can say when it was last reviewed
- The answer depends on who you ask
- Length beats complexity rules
- Forced rotation makes passwords worse, not better
The practical version
Check credentials against known breach lists. It is worth being explicit about, because assumptions differ quietly. The failure mode is not doing it wrong, it is doing it once and assuming it stays done.
How to tell if yours is fine
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about password policies before you move on:
- Someone can say what the current setup is without going to look
- Check credentials against known breach lists — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Most of the value here comes from doing the first two things, not all of them.