A written password policy is one of the cheapest, highest-impact security controls you can adopt. Here's a template you can copy, tweak, and hand to your team.
1. The rules
- Use a unique password for every account — no reuse.
- Minimum 14 characters; passphrases ("correct-horse-battery" style) are easiest to remember and hardest to crack.
- Enable multi-factor authentication (MFA) on email, banking, and any admin account — required, not optional.
- Never share passwords over email, chat, or text.
2. Shared accounts
Avoid shared logins. If unavoidable (e.g., a social account), store credentials in a business password manager with shared-folder access and revocable permissions — never in a spreadsheet.
3. When someone leaves
Disable their access on day one and rotate any shared credentials they touched.
4. Breach response
If a password is suspected compromised: reset it, enable MFA, and check account activity. A password manager's breach alerting helps catch this early.
5. Enforcement
Review access quarterly. Pair this policy with our 10-employee security checklist.
Frequently Asked Questions
How long should my password policy require?
Modern guidance recommends: (1) Minimum 12-16 characters, (2) Passphrases with multiple words, (3) No mandatory periodic changes unless there's evidence of compromise, (4) Unique passwords for each account, (5) MFA required. Frequent forced password changes often lead to weaker, predictable passwords. Focus on password strength and uniqueness instead.
Can I let employees use their personal password managers?
For personal accounts, yes. For business accounts, use a business-grade password manager that allows admin oversight and secure sharing. Personal password managers don't provide the centralized management, audit trails, and compliance features needed for business security. Require business password managers for all work-related accounts.