What people use to authenticate.
WHAT MAKES PASSWORDS FAIL
Reuse across services Predictability Sharing Storage in unsafe places Never being changed after exposure
WHY REUSE IS THE LARGEST PROBLEM
One compromised service exposes every account sharing the password.
WHAT TO ESTABLISH
Different passwords for every service.
HOW
A password manager.
WHY A MANAGER
Remembering unique passwords is impossible, and the alternative is reuse or writing them down badly.
WHAT TO PROVIDE
A manager for the organisation, with shared vaults where needed.
WHAT TO ESTABLISH ABOUT LENGTH
That longer matters more than complexity rules.
WHY
Complexity requirements produce predictable patterns that people reuse.
WHAT TO AVOID
Forced frequent rotation without cause.
WHY
It produces incremental predictable changes and it is now widely discouraged.
WHAT TO REQUIRE INSTEAD
Change when there is reason: suspected exposure, shared credentials, departure.
WHAT TO ESTABLISH ABOUT SHARED ACCOUNTS
That they are avoided wherever possible.
WHY
Actions cannot be attributed, and removal requires changing the credential for everyone.
WHAT TO DO WHERE SHARING IS UNAVOIDABLE
Use a shared vault with individual access Record who has access Change the credential when anyone leaves
WHAT TO NEVER DO
Send credentials in messages Store them in documents or spreadsheets Leave default credentials unchanged
WHY DEFAULTS SPECIFICALLY
They are published, and unchanged defaults are the commonest route into equipment.
WHAT TO ESTABLISH
That every device and service has its default changed at installation.
WHAT TO CHECK
Whether credentials have appeared in known breaches.