Passwords Are Still the First Step in Data Security: Here’s How to Secure Yours
Whether they come to your organization as consumers or clients, students or patients, people expect you to keep their personally identifiable (and often highly sensitive) information safe. To meet this expectation, you might turn to cutting-edge encryption tools and pseudonymization methods. But countless organizations overlook the most obvious place to start when it comes to protecting data: passwords. To help you take this pivotal first step toward optimal data security and to protect your organization from mistakes and breaches from within, here a few robust password guidelines you can follow.
Create and implement a password policy
Simply, a password policy is a set of rules outlining how your employees should approach creating and using their passwords.
To make your password policy as strong as possible, it should include password expectations. Establish clear criteria for your employees’ passwords, and make sure they follow those rules. To help you create your criteria, some password best practices include:
- Embracing long passwords—research shows that password complexity isn’t nearly as important as length
- Avoiding the use of personal information like addresses, nicknames, and important dates (no birthdays allowed!)
- Avoiding dictionary words
- Using passphrases instead of passwords (e.g. “NYG!antsAreTheB3st” instead of “GiantsFan1”)
- Encouraging uniqueness, even a little weirdness (the days when “password” and “12345” were acceptable choices are long behind us)
- Avoiding writing down passwords
- Not changing passwords too frequently (a couple of times a year is usually fine, though you should change them immediately if you suspect a breach)
- Never sharing passwords, even if it’s with someone in your organization
- Never letting someone watch you enter your password
- Not using the same password for multiple applications or accounts




