Password policies for small teams
Teams tend to reach for this after something has already gone wrong. Most advice about password policies assumes a team that does not exist at your size. Here is the version that does not.
Security is a maintenance habit rather than a purchase, which is why it drifts. Write the reasoning down alongside the decision, because the reasoning is what changes first.
What to keep
Length beats complexity rules. That sounds obvious written down. It is still the thing most often skipped. The teams that stay on top of it are the ones who put it on a calendar rather than a wish list.
What to drop
Process that exists to coordinate ten people is overhead when there are two of you. The cost of getting this wrong is rarely visible on the day it happens.
The practical version
Check credentials against known breach lists. That sounds obvious written down. It is still the thing most often skipped. Assume whoever inherits this will have half your context and none of your patience.
The short version
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about password policies before you move on:
- Someone can say what the current setup is without going to look
- Length beats complexity rules — and you know whether that is true here
- There is a way to tell whether the last change to this helped
None of this needs a rewrite. Most of it is a morning's work once someone decides to do it.