---
title: Four Rules for a Robust Password Policy - SIRKit
description: Enhance security with 4 key rules for a strong password policy, including tips on password generation. Explore length, complexity, and reuse guidelines.
image: https://www.sirkit.ca/hubfs/cyber-security-3400657_1920-e1632857892128.jpg
---

[Skip to main content](https://www.sirkit.ca/blog/four-rules-for-a-robust-password-policy#main-content)

[![sirkit-logo-reverse-with-tm](https://www.sirkit.ca/hubfs/sirkit-logo-reverse-with-tm.svg) ![sirkit-logo-reverse-with-tm](https://www.sirkit.ca/hubfs/sirkit-logo-reverse-with-tm.svg)](https://www.sirkit.ca)

- Show submenu for Services Services 
  
    - [Managed IT](https://www.sirkit.ca/managed-it-services)
    - [Co-Managed IT](https://www.sirkit.ca/co-managed-it-services)
    - [Integrated IT Solutions](https://www.sirkit.ca/integrated-it-solutions)
- [Cybersecurity](https://www.sirkit.ca/cybersecurity)
- [Show submenu for About Us About Us](https://www.sirkit.ca/about) 
    - [Executive Team](https://www.sirkit.ca/about?#exec)
    - [Careers](https://www.sirkit.ca/careers)
    - [Contact Us](https://www.sirkit.ca/contact)
- [Blog](https://www.sirkit.ca/blog)

Open main navigation

Close main navigation

- Show submenu for Services Services 
  
    - Services
    - [Managed IT](https://www.sirkit.ca/managed-it-services)
    - [Co-Managed IT](https://www.sirkit.ca/co-managed-it-services)
    - [Integrated IT Solutions](https://www.sirkit.ca/integrated-it-solutions)
- [Cybersecurity](https://www.sirkit.ca/cybersecurity)
- Show submenu for About Us About Us 
  
    - About Us
    - [About Us](https://www.sirkit.ca/about)
    - [Executive Team](https://www.sirkit.ca/about?#exec)
    - [Careers](https://www.sirkit.ca/careers)
    - [Contact Us](https://www.sirkit.ca/contact)
- [Blog](https://www.sirkit.ca/blog)
- [Connect with our Team](https://www.sirkit.ca/contact)

[Connect with our Team](https://www.sirkit.ca/contact)

[Skip to main content](https://www.sirkit.ca/blog/four-rules-for-a-robust-password-policy#main-content)

This is an announcement bar or top menu bar. Additional content can go here.

[![sirkit logo](https://www.sirkit.ca/hubfs/Sirkit_Primary-Logo-RGB.svg) ![sirkit logo](https://www.sirkit.ca/hubfs/Sirkit_Primary-Logo-RGB.svg)](https://www.sirkit.ca)

- Show submenu for Services Services 
  
    - [Managed IT](https://www.sirkit.ca/managed-it-services)
    - [Co-Managed IT](https://www.sirkit.ca/co-managed-it-services)
    - [Integrated IT Solutions](https://www.sirkit.ca/integrated-it-solutions)
- [Cybersecurity](https://www.sirkit.ca/cybersecurity)
- [Show submenu for About Us About Us](https://www.sirkit.ca/about) 
    - [Executive Team](https://www.sirkit.ca/about?#exec)
    - [Careers](https://www.sirkit.ca/careers)
    - [Contact Us](https://www.sirkit.ca/contact)
- [Blog](https://www.sirkit.ca/blog)

Open main navigation

Close main navigation

- Show submenu for Services Services 
  
    - Services
    - [Managed IT](https://www.sirkit.ca/managed-it-services)
    - [Co-Managed IT](https://www.sirkit.ca/co-managed-it-services)
    - [Integrated IT Solutions](https://www.sirkit.ca/integrated-it-solutions)
- [Cybersecurity](https://www.sirkit.ca/cybersecurity)
- Show submenu for About Us About Us 
  
    - About Us
    - [About Us](https://www.sirkit.ca/about)
    - [Executive Team](https://www.sirkit.ca/about?#exec)
    - [Careers](https://www.sirkit.ca/careers)
    - [Contact Us](https://www.sirkit.ca/contact)
- [Blog](https://www.sirkit.ca/blog)
- [Get Started](https://www.sirkit.ca/contact)

[Get Started](https://www.sirkit.ca/contact)

Categories

- [Cyber-Security Advisories](https://www.sirkit.ca/blog/tag/cyber-security-advisories)
- [Technical Pro-tips and How-to](https://www.sirkit.ca/blog/tag/technical-pro-tips-and-how-to)
- [Knowledge Base (KB)](https://www.sirkit.ca/blog/tag/knowledge-base-kb)
- [SIRKit News](https://www.sirkit.ca/blog/tag/sirkit-news)
- [Product Reviews](https://www.sirkit.ca/blog/tag/product-reviews)
- [SIRKit360® News](https://www.sirkit.ca/blog/tag/sirkit360-news)

# Four Rules for a Robust Password Policy

[Kris Wilkinson](https://www.sirkit.ca/blog/author/kris-wilkinson)

Sep 14, 2021

A password policy is a simple way to enhance your company’s security. When implemented correctly, a password policy makes it much more difficult for 3rd parties to compromise accounts. A password policy, therefore, lowers the chance that your company might experience a breach. Most modern systems that facilitate authentication can be configured to enforce a password policy.

Ideally, each user’s password should be as strong as possible. What leads to a strong password? For one, length and complexity, but there’s more to it. Did you know a 10-character password with lowercase letters can be cracked in 58 seconds? Read on to learn more about what makes up a strong password and other factors to consider for your organization’s password policy.

**1. Minimum Length **

Minimum length is the most essential part of the policy. A strong password policy should enforce a minimum length. While computers are powerful, longer passwords ultimately take longer to guess or crack.

Here’s how long it takes to break passwords:

![Time_it_takes_to_crack_a_password-1](https://www.sirkit.ca/hs-fs/hubfs/Time_it_takes_to_crack_a_password-1.jpg?width=599&height=599&name=Time_it_takes_to_crack_a_password-1.jpg) ![](https://static.hsstatic.net/BlogImporterAssetsUI/ex/missing-image.png)

Passwords should be at least 12 characters long – and preferably include two or more types of symbols.

**2. Complexity requirements**

Complexity can also complement length. Passwords should contain both uppercase and lowercase letters, as well as numbers and some special characters ($#@%!). The more complex a password is, the less likely it is to be breached.

**3. Password Age**

There are two types of password ages: maximum and minimum.

A maximum password age policy requires passwords to be changed every certain number of days – usually 180. Changing passwords twice a year lowers the chance of a data breach.

A minimum password age requires a password to be used for a certain amount of time before being changed. This is useful to prevent users from changing passwords infinitely until they can successfully retrieve their old passwords.

Using a maximum and minimum password age will help you draft a more secure password policy.

**4. Password Reuse or History**

Passwords should never be reused:

- On a single system (e.g., using a previous password) or
- On multiple systems (e.g., using the same password at the same time for multiple systems)

When an online service is compromised, 3rd parties often attempt to use the credentials they captured to log in to other services. MANY major online services have suffered breaches in the last decade. Don’t assume that you weren’t impacted.

Verify if your credentials were compromised by visiting [Have I Been Pwned](https://haveibeenpwned.com/). This website offers a free service to search through past breaches. If you discover that you were included in a breach, ensure to change your password on any services that shared the same password immediately.

From a policy perspective, restricting password history will prevent users from reusing old passwords. Therefore, disallowing the use of old passwords- and forcing a change every 180 days- will help increase security for your organization.

**Additional Security Measures**

Passphrasing

Remembering passwords can be difficult, especially when they are at least 12-characters long, have complexity, and cannot be reused. Passphrasing offers a simple solution by allowing you to use random words in a phrase for your password.

*For example:*  Bottle-Carp3t-Stick-22!!

The general idea is to pick 3-4 words that don’t make sense together and add some complexity. Instead of remembering a password of random chaos, use a phrase that is simple to remember.

Check out [Use a Passphrase](https://www.useapassphrase.com/) for more information and a passphrase generator.

Multi-Factor Authentication

Multi-Factor Authentication should complement every strong password policy.

MFA is a login feature that helps verify identity. It also protects against identity-based attacks: a 3rd party attempting to gain access to an account, which often occurs due to poor password management. Multi-Factor Authentication introduces a secondary verification step that blocks 99.9% of attempted attacks. Even if a malicious party knows a user’s credentials, MFA will stop them from accessing the account.

When MFA is active, a random code or prompt (push notification) is sent to a user’s mobile device to confirm their identity. [Microsoft released an article](https://www.microsoft.com/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/) on the success rate of Multi-Factor Authentication. For more information on MFA, check out our article [here](https://www.sirkit.ca/blog/what-is-multi-factor-authentication-and-why-is-it-so-important).

Password Manager

There is a tool to assist with the storage and generation of strong passwords, and that is a password manager. A password manager will securely store passwords from various logins. Some password managers will even allow you to generate a strong password for use. With the memory feature of a password manager, there’s no need to remember the password you set.

Using a password manager can help with the enforcement of your password policy. If users no longer worry about remembering their passwords, it becomes easier to create abstract, long, or complex passwords.  Therefore, a Password Manager will enhance security for your organization.

We use and recommend [LastPass](https://www.lastpass.com/) as a password security solution.

**Conclusion**

Password policies are both simple and effective. Password policies can increase your company’s security by forcing users to use more strong passwords. An effective password policy should include:

- Minimum length
- Complexity requirements
- Password Age
- Password Reuse and History

Some additional tools to help security for your organization are:

- Multi-Factor Authentication
- Password Managers

Thanks for reading. If you have any questions about how to implement a strong password policy in your organization, or you’re looking for help with your cybersecurity needs, [reach out to us](https://www.sirkit.ca/contact/).

 

**Tags:** 

[Technical Pro-tips and How-to](https://www.sirkit.ca/blog/tag/technical-pro-tips-and-how-to)

### Related Posts

##### [![Is Your Cloud Secure? Common Security Gaps & How to Fix Them](https://www.sirkit.ca/hs-fs/hubfs/Sirkit%20Cloud%20Security%20Blog%20-%20Aug%204.png?width=520&height=294&name=Sirkit%20Cloud%20Security%20Blog%20-%20Aug%204.png) Technical Pro-tips and How-to • Aug 4, 2025 Is Your Cloud Secure? Common Security Gaps & How to Fix Them 3 min read](https://www.sirkit.ca/blog/is-your-cloud-secure-common-security-gaps-how-to-fix-them)

##### [![What's New in Microsoft Teams: June 2025 Update](https://www.sirkit.ca/hs-fs/hubfs/SIRKit-54-2.jpg?width=520&height=294&name=SIRKit-54-2.jpg) Technical Pro-tips and How-to • Jun 30, 2025 What's New in Microsoft Teams: June 2025 Update 2 min read](https://www.sirkit.ca/blog/microsoft-teams-update-june-2025)

##### [![How to compare MSP Offers: Price vs. Value – Making the Right Choice for Your Business](https://www.sirkit.ca/hs-fs/hubfs/Imported_Blog_Media/MSP-Comparison.jpg?width=520&height=294&name=MSP-Comparison.jpg) Technical Pro-tips and How-to • May 14, 2025 How to compare MSP Offers: Price vs. Value – Making the Right Choice for Your Business 12 min read](https://www.sirkit.ca/blog/comparing-msp-offers-price-vs-value)

### Stay connected.

Join our newsletter to stay informed with the latest technology insights, market and business updates, and Sirkit news and events.

###### Categories

- [Cyber-Security Advisories](https://www.sirkit.ca/blog/tag/cyber-security-advisories)
- [Technical Pro-tips and How-to](https://www.sirkit.ca/blog/tag/technical-pro-tips-and-how-to)
- [Knowledge Base (KB)](https://www.sirkit.ca/blog/tag/knowledge-base-kb)
- [SIRKit News](https://www.sirkit.ca/blog/tag/sirkit-news)
- [Product Reviews](https://www.sirkit.ca/blog/tag/product-reviews)

###### Recent Posts

- [6 AI-Related Cybersecurity Risks Businesses Can’t Ignore](https://www.sirkit.ca/blog/ai-related-cyber-risks)
- [What Is Agentic AI in Cybersecurity?](https://www.sirkit.ca/blog/what-is-agentic-ai-in-cybersecurity)
- [AI Cyber Attacks: What Business Leaders Need to Understand Right Now](https://www.sirkit.ca/blog/ai-cyber-attacks-business-leaders)
- [Vulnerability Assessment vs Penetration Testing](https://www.sirkit.ca/blog/vulnerability-assessment-vs-penetration-testing)
- [Why MFA Alone Is No Longer Enough: How to Prevent Token Theft and AiTM Attacks](https://www.sirkit.ca/blog/prevent-token-theft)

[![Sirkit_Primary-Logo-White-RGB](https://www.sirkit.ca/hubfs/Sirkit_Primary-Logo-White-RGB.svg)](https://www.sirkit.ca)

[1-780-758-5200](tel:17807585200) (Support)

[1-587-404-9002](https://www.sirkit.ca/blog/15874049002) (Sales)

 Unit 217, 236 91 Street SW  
 Edmonton AB, T6X 1W8

- [Managed IT Services](https://www.sirkit.ca/managed-it-services)
- [Cybersecurity](https://www.sirkit.ca/cybersecurity)
- [About Us](https://www.sirkit.ca/about)
- [Contact Us](https://www.sirkit.ca/contact)

©2026 Sirkit. All rights reserved. [Privacy Policy](https://www.sirkit.ca/privacy-policy)  |  [Terms of Use](https://www.sirkit.ca/terms-of-use)  
Sirkit® is a registered trademark.

- <https://www.linkedin.com/company/sirkit/>
- <https://www.instagram.com/sirkit.ca/>
- <https://www.facebook.com/sirkitcanada/>

×

![Managed IT Services Cost eBook Download](https://www.sirkit.ca/hubfs/Sirkit%20Managed%20IT%20PDF%20popup.png)

×

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Kris Wilkinson",
    "url" : "https://www.sirkit.ca/blog/author/kris-wilkinson"
  },
  "dateModified" : "2026-06-04T16:06:55.961Z",
  "datePublished" : "2021-09-14T18:09:05.000Z",
  "headline" : "Four Rules for a Robust Password Policy - SIRKit",
  "image" : [ "https://www.sirkit.ca/hubfs/cyber-security-3400657_1920-e1632857892128.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.sirkit.ca/blog/four-rules-for-a-robust-password-policy",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.sirkit.ca/hubfs/Logos/SirkitBadge%20(2).png"
    },
    "name" : "Sirkit"
  }
}
```