Skip to main content

Blog

A printed Password Policy document on a wooden desk next to a keyboard and coffee mug

Why Your SME Needs a Proper Password Policy (Not Just "Use a Strong Password")

Why Your SME Needs a Proper Password Policy (Not Just "Use a Strong Password")

When I ask a small business owner whether they have a password policy, the usual answer is: "Yes, we tell everyone to use a strong password." That is not a policy. It is a suggestion, and suggestions are not enforceable, auditable, or recoverable when something goes wrong.

A written password policy takes about two hours to write and costs nothing. Here is what it needs to say, and why it matters more than the password itself.

What a password policy actually is

A password policy is a written document that sets out the rules your business expects everyone to follow when creating and managing passwords. It applies to staff, contractors, and anyone else with access to your systems. It covers:

  • Minimum length and complexity requirements
  • Which accounts need MFA (multi-factor authentication)
  • Rules on reuse and sharing
  • What to do when a password is compromised
  • The consequence of not following the policy

That last point matters. A policy is only useful if people know it exists and know it applies to them.

Why length beats complexity

For years, IT advice told people to use a mix of upper case, lower case, numbers, and symbols. The result was passwords like "Summer2024!" - technically complex, practically predictable, and changed every 90 days to "Autumn2024!" by staff who found the whole thing annoying.

Current NCSC guidance recommends length over complexity. A three-word passphrase like "carpet-thunder-bridge" has more entropy than "P@ssw0rd!" and is far easier to remember. Your policy should reflect this: minimum 12 characters, no mandatory special characters, no forced rotation unless there is a suspected breach.

If your business uses a password manager (which I recommend it should), the policy can simply say: every account gets a unique, manager-generated password, full stop. Length and complexity are handled automatically.

Which accounts need MFA

Your policy should list the accounts where MFA is mandatory, not optional. At minimum:

  • Microsoft 365 or Google Workspace accounts
  • Banking and payment platforms
  • Accounting software (Xero, Sage, QuickBooks)
  • Your website CMS or e-commerce platform
  • Any admin or IT management tools
  • CRM, HR, and payroll systems

The rule of thumb: if losing access to that account would hurt the business, MFA is mandatory.

Rules on sharing

Shared credentials are one of the most common security weaknesses I find. A shared login for a tool that "everyone uses" means:

  • You cannot tell who did what
  • You cannot remove one person's access without changing the password for everyone
  • If the password is compromised, you do not know how

The policy should say: no shared passwords except where the tool does not support individual accounts, and in that case the shared password must live in the shared vault of the business password manager, not on a sticky note or in a group chat.

What to do when a password is compromised

Staff need a clear, simple procedure for when they think an account has been compromised. This usually means:

  1. Change the password immediately via the password manager
  2. Enable MFA if it was not already active
  3. Report it to whoever manages your IT, the same day
  4. Check the account for unusual activity (sent emails, rules, forwarding addresses)

Without a written procedure, people either panic, ignore it, or quietly change the password and hope for the best. None of those outcomes serve the business.

Making the policy stick

A policy document is only as useful as the culture around it. For a small business, that means:

  • The owner or MD is visibly following the same rules
  • New starters read and sign it during onboarding
  • It is reviewed annually or after any security incident
  • There is a named person responsible for enforcing it

None of this requires a legal background. A one-page document with clear rules, reviewed once a year, is far better than a 40-page policy nobody reads.

Talk to ClearPath IT about a password policy   Cyber security services

ClearPath IT Services supports small businesses across Kent, Medway and South East London with practical cyber security that fits a real business.

ClearPath IT Services

Personal, reliable IT support for small businesses across Kent, Medway and South East London.

Clear IT. Sorted.

Get in Touch

Based in Kent, serving businesses across Medway, Dartford, Gravesend, Sidcup, Bexley and South East London.

Call: 0333 360 8308

Visit: 1a Saddington Street, Gravesend, DA12 1ED

Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

Contact me


© 2026 ClearPath IT Services Limited. All rights reserved. | Privacy Policy