Weak or reused passwords are behind a staggering percentage of business data breaches. Yet most small businesses have no formal password policy — and those that do often have policies employees work around because they’re impractical. Here’s how to build one that actually works.
The Problem With “Change Your Password Every 90 Days”
This was standard advice for decades, and it backfired. When forced to change passwords constantly, people pick weaker ones (Password1, Password2, Password3) or write them on sticky notes. NIST — the US government body that sets security standards — now recommends not requiring frequent password changes unless there’s evidence of a compromise. Instead, focus on password strength and uniqueness.
What Your Password Policy Should Require
- Minimum length of 12 characters — Length matters more than complexity. A 16-character passphrase is harder to crack than an 8-character “complex” password.
- Unique password for every account — No reusing passwords across work systems, and especially not between work and personal accounts.
- No sharing passwords between employees — Every person gets their own login. Shared accounts make it impossible to audit who did what.
- Immediate change if a breach is suspected — This is the one case where you do require an immediate change.
- Multi-factor authentication on all critical accounts — MFA is the backstop when a password is compromised.
The Tool That Makes All of This Practical: A Password Manager
The reason employees reuse passwords is simple: no one can remember 40 unique, strong passwords. A password manager solves this completely. It generates and stores a unique strong password for every account, autofills logins, and only requires employees to remember one master password. For teams, a business password manager (like 1Password Teams or Bitwarden Business) also lets you share passwords securely and revoke access when someone leaves.
Enforcing the Policy
A written policy no one follows is worthless. Technical enforcement is more reliable than asking people to comply:
- Use your business email platform (Microsoft 365, Google Workspace) to enforce minimum password length and MFA requirements at the admin level
- Deploy a password manager and make enrollment part of new employee onboarding
- Remove access immediately when employees leave — don’t wait for the offboarding paperwork to catch up
We help Naples area small businesses implement practical security policies and the tools to enforce them. If you’re not sure where to start, call (239) 513-1960 — we’ll walk you through what matters most for your specific situation.
Need Help With Your Computer?
Naples Computers serves Collier & Lee County — same-day repair, remote support, and small business IT.
Get Help Today