
Why Your SME Needs a Proper Password Policy (Not Just "Use a Strong Password")
Why Your SME Needs a Proper Password Policy (Not Just "Use a Strong Password")
When I ask a small business owner whether they have a password policy, the usual answer is: "Yes, we tell everyone to use a strong password." That is not a policy. It is a suggestion, and suggestions are not enforceable, auditable, or recoverable when something goes wrong.
A written password policy takes about two hours to write and costs nothing. Here is what it needs to say, and why it matters more than the password itself.
What a password policy actually is
A password policy is a written document that sets out the rules your business expects everyone to follow when creating and managing passwords. It applies to staff, contractors, and anyone else with access to your systems. It covers:
- Minimum length and complexity requirements
- Which accounts need MFA (multi-factor authentication)
- Rules on reuse and sharing
- What to do when a password is compromised
- The consequence of not following the policy
That last point matters. A policy is only useful if people know it exists and know it applies to them.
Why length beats complexity
For years, IT advice told people to use a mix of upper case, lower case, numbers, and symbols. The result was passwords like "Summer2024!" - technically complex, practically predictable, and changed every 90 days to "Autumn2024!" by staff who found the whole thing annoying.
Current NCSC guidance recommends length over complexity. A three-word passphrase like "carpet-thunder-bridge" has more entropy than "P@ssw0rd!" and is far easier to remember. Your policy should reflect this: minimum 12 characters, no mandatory special characters, no forced rotation unless there is a suspected breach.
If your business uses a password manager (which I recommend it should), the policy can simply say: every account gets a unique, manager-generated password, full stop. Length and complexity are handled automatically.
Which accounts need MFA
Your policy should list the accounts where MFA is mandatory, not optional. At minimum:
- Microsoft 365 or Google Workspace accounts
- Banking and payment platforms
- Accounting software (Xero, Sage, QuickBooks)
- Your website CMS or e-commerce platform
- Any admin or IT management tools
- CRM, HR, and payroll systems
The rule of thumb: if losing access to that account would hurt the business, MFA is mandatory.
Rules on sharing
Shared credentials are one of the most common security weaknesses I find. A shared login for a tool that "everyone uses" means:
- You cannot tell who did what
- You cannot remove one person's access without changing the password for everyone
- If the password is compromised, you do not know how
The policy should say: no shared passwords except where the tool does not support individual accounts, and in that case the shared password must live in the shared vault of the business password manager, not on a sticky note or in a group chat.
What to do when a password is compromised
Staff need a clear, simple procedure for when they think an account has been compromised. This usually means:
- Change the password immediately via the password manager
- Enable MFA if it was not already active
- Report it to whoever manages your IT, the same day
- Check the account for unusual activity (sent emails, rules, forwarding addresses)
Without a written procedure, people either panic, ignore it, or quietly change the password and hope for the best. None of those outcomes serve the business.
Making the policy stick
A policy document is only as useful as the culture around it. For a small business, that means:
- The owner or MD is visibly following the same rules
- New starters read and sign it during onboarding
- It is reviewed annually or after any security incident
- There is a named person responsible for enforcing it
None of this requires a legal background. A one-page document with clear rules, reviewed once a year, is far better than a 40-page policy nobody reads.
Talk to ClearPath IT about a password policy Cyber security services
ClearPath IT Services supports small businesses across Kent, Medway and South East London with practical cyber security that fits a real business.