Dabish Digital
Security

When password policies is worth the effort

Most teams know this matters. Fewer have decided who owns it. Password policies is not free, and pretending otherwise leads to bad decisions.

Security is a maintenance habit rather than a purchase, which is why it drifts. Budget a little time for it every quarter and it never becomes a project of its own.

When it is worth it

Length beats complexity rules. It is worth being explicit about, because assumptions differ quietly. Check it against what you would want a competitor's site to get wrong.

When it is not

If nothing downstream depends on it and nobody is complaining, it can wait. There is a version of this that is over-engineered, and it is worth avoiding.

How to decide

Check credentials against known breach lists. The teams that handle this well are rarely the ones with the biggest budgets. Doing this properly once is usually cheaper than doing it approximately three times.

In practice

The cheapest security work is the boring kind done on a schedule. Three things worth confirming about password policies before you move on:

  • Someone can say what the current setup is without going to look
  • Forced rotation makes passwords worse, not better — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

If you are not sure where your systems currently stand on this, it takes us about an hour to find out.