Dabish Digital
Security

Password policies for small teams

Teams tend to reach for this after something has already gone wrong. Most advice about password policies assumes a team that does not exist at your size. Here is the version that does not.

Security is a maintenance habit rather than a purchase, which is why it drifts. Write the reasoning down alongside the decision, because the reasoning is what changes first.

What to keep

Length beats complexity rules. That sounds obvious written down. It is still the thing most often skipped. The teams that stay on top of it are the ones who put it on a calendar rather than a wish list.

What to drop

Process that exists to coordinate ten people is overhead when there are two of you. The cost of getting this wrong is rarely visible on the day it happens.

The practical version

Check credentials against known breach lists. That sounds obvious written down. It is still the thing most often skipped. Assume whoever inherits this will have half your context and none of your patience.

The short version

The cheapest security work is the boring kind done on a schedule. Three things worth confirming about password policies before you move on:

  • Someone can say what the current setup is without going to look
  • Length beats complexity rules — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

None of this needs a rewrite. Most of it is a morning's work once someone decides to do it.