Bitweb
Guide · Policy template

A password and MFA policy that matches how attackers actually get in

Most small-business password policies are copied from a 2010 corporate template: eight characters, a symbol, change every 90 days. Every one of those rules is now wrong. Here is what to require instead, with the policy text you can paste.

By a working IT technician supporting 400+ users · Updated September 2026 · 6 min read

Attackers rarely guess passwords any more. They buy them from previous breaches, phish them with a fake login page, or push MFA prompts until someone taps approve. A policy is only useful if it addresses those three, which is why NIST's current guidance dropped complexity rules and forced rotation and instead emphasises length, uniqueness, and multi-factor authentication.

What to require

Policy text you can use

Password & Multi-Factor Authentication Policy (excerpt)
  1. Passwords must be at least 14 characters. A passphrase of three or more unrelated words is recommended.
  2. Every account must have a unique password. Reusing a password across two or more services, including between personal and work accounts, is prohibited.
  3. Passwords do not expire on a fixed schedule. They must be changed immediately if there is any suspicion they have been exposed, or when the IT Lead directs.
  4. All work passwords must be stored in the approved password manager, [Password Manager Name], which must also be used to generate new passwords. Passwords must not be stored in browsers on shared devices, spreadsheets, notes apps, on paper, or in email.
  5. MFA is mandatory on email, the password manager, remote access, cloud administration consoles, banking and payment platforms, and any system holding customer or employee data.
  6. Users must never approve an MFA prompt they did not initiate. Unexpected prompts must be denied and reported to the IT Lead immediately.
  7. Administrator accounts must have a separate password from the user's day-to-day account and must always be protected by MFA.

Add a Purpose, Scope, Responsibilities and Enforcement section around it, have the owner sign it, and collect acknowledgements. That's the whole policy; anything longer will not be read.

How to enforce it without policing

Enforce technically where you can: tenant-wide MFA in Microsoft 365 or Google Workspace, minimum password length in the directory, and the password manager's own reports on weak or reused entries. The policy then exists to make those settings legitimate and to cover the systems you can't configure centrally.

Want the documents done for you?The Small Business Cybersecurity Policy Bundle is the written policy set, incident response plan and asset register described here, as editable Word and Excel files: CA$24 on its own, or CA$39 in the full kit, instant download. Get all 8 policies
The cyber-insurance questionnaire, question by question12 questions, what "yes" needs, which document proves itAn incident response plan a small business will actually useRoles, severity levels, first-hour checklist, three playbooksWhat an IT asset inventory needs to track (and what it can skip)The columns insurers and auditors look for