Choosing a password policy people will follow

By The happier IT service desk

The password policies that fail are the ones written for auditors instead of people. Force a change every thirty days and staff will append a number; ban dictionary words and the word gains an exclamation mark. The policy passes review, and the accounts stay easy to guess.

What actually reduces account takeovers is shorter to write down: long passphrases instead of complex passwords, a password manager so nobody has to remember them, and multi-factor authentication on everything that faces the internet. Length beats complexity because length is what the attacking software actually fights.

The three-line policy we recommend: passphrases of at least four words, stored in the company password manager; multi-factor authentication on email, remote access and finance systems, no exceptions; and no scheduled resets. Passwords change when there is a reason.

If your current policy is longer than that and still generates lockout tickets every Monday, it is optimised for the wrong reader.

Talk to us

Managed IT services