Password policy: the principles that actually work

Published on May 18, 20267 min read
A small-business owner writes a simple password rule on a notepad, an easy-to-remember passphrase, a password manager open on her laptop

One Monday morning, Sophie B. finds the notebook sitting by the printer: the password for the accounting software is written in it, unchanged for years, known to a good part of the team — including a colleague who left last autumn. Nothing has ever "gone wrong." But the thought that a client file could be opened this easily makes her uneasy. The real question isn't how to invent a more twisted password: it's how to put in place a password policy that survives the firm's real, everyday life.

What a password policy is actually for

A password policy, in plain terms, is the set of simple rules the whole team follows to create, store and protect its passwords. Not a ten-page regulation: a handful of principles everyone understands and actually applies.

The problem it solves is very concrete. In a small organisation, the same habits show up everywhere: a short password that's "easy to remember," the same one reused across several services, written on a sticky note or shared by email. Each of these habits opens a door.

The most common attack, in fact, is nothing sophisticated. When a password leaks in the breach of some random website, attackers automatically try it again, by the thousands, on other services — email, online banking, business tools. This is called "credential stuffing": reusing elsewhere a password that was stolen once. If you use the same password everywhere, a single leak is enough to bring the rest down.

A shared password written in a notebook actually stacks two weaknesses. First, you no longer know who knows it: as people join and leave, the list grows and no one keeps track of it. Second, you can't cleanly take it away from one person: when someone leaves, either you keep the password as it is — and the former employee still has access — or you change it for everyone, which nobody wants to do. The usual outcome: nothing gets done.

For a fiduciary firm, the stakes go beyond convenience. You hold the accounting, payroll and tax data of dozens of clients — information effectively covered by professional secrecy. Switzerland's new Federal Act on Data Protection (nFADP) expects every business to take "appropriate" security measures for the data it processes. Serious password management is part of that. No one is asking you for a certificate: you're asked to be able to show that you're taking care of it.

The key takeaways

Length matters more than symbols. For years, we demanded passwords stuffed with capitals, digits and special characters, changed every three months. The result: unpronounceable passwords no one can remember — so they end up in a notebook. The reference guidance (the US NIST, now echoed by Switzerland's federal cybersecurity office, the NCSC) has changed its mind: a long, easy-to-remember password beats a short, complicated one. Hence the idea of the passphrase — a string of several words, for example four unrelated words, which gives you a password that's long, easy to recall and very hard to guess.

You no longer remember your passwords: you file them away. With dozens of services, memorising a unique, long password for each is impossible. That's the job of the password manager — a digital vault that creates, stores and fills in your passwords for you, protected by a single master password. You have just one thing to remember; the software handles the rest.

A password alone is no longer enough. Even long and unique, it can be intercepted. Two-factor authentication (often shortened to MFA) adds a second proof at the moment you log in — usually a temporary code on your phone, or a confirmation in an app. Even if someone knows your password, they're missing that second factor. It's the most effective, and often the simplest, complement to a good password policy.

The steps to put in place this week

1. Adopt passphrases for sensitive accounts

Start with the accounts that matter: email, the accounting software, administrator access. For each, replace the old password with a passphrase: four randomly chosen words, easy for you to picture, unrelated to your name or your company. You get a far stronger access, without the symbol headache. And you stop, right now, reusing the same password from one service to another. Good news along the way: a long, unique passphrase doesn't need changing every three months. You only change it if you suspect it has leaked — that's today's recommendation, and it takes a pointless chore off your plate.

2. Install a password manager

Choose a reputable password manager and set it up for yourself first, on both computer and phone. Let it generate and remember unique passwords for every service. Once you're comfortable, extend it to the team: it's the cleanest way to end passwords on sticky notes and shared by email. How you organise the vaults, shared access and departures is something you plan for — and that's exactly what a structured rollout sets up.

3. Turn on two-factor authentication where it counts

Turn on two-factor authentication (MFA) at least on email and on the tools that hold client data. In most professional services — including the office suite you probably use — the option already exists: you just switch it on and enrol the team's phones. Plan for a fallback too (a recovery code kept somewhere safe) so you're not locked out if a phone is lost.

Where do you really stand?

These three steps already cut the risk significantly. But a password policy that lasts asks for a little more: deciding which accounts are critical, sharing an access cleanly rather than whispering it, and above all cutting off the access of someone who leaves the company — the very point that made Sophie B. uneasy in front of her notebook.

Cyber Passport certifies nothing and does not declare you "compliant." It helps you carry out a structured self-assessment: where you really stand on passwords, access and the rest, and where to start. It's an honest starting point that you can then share with a client or an auditor who asks the question.

To move from three steps to a full policy — a rules template, rolling out the manager across the team, shared vaults and a departure procedure — the dedicated blueprint walks you through it, step by step.

Topics

  • passwords
  • password manager
  • MFA
  • SME
  • Switzerland

Read next