How to Write a Password Policy Your Team Will Actually Follow
Weak and reused passwords are one of the easiest ways into a business. A short, clear password policy, with a password manager and two-step login, fixes most of this problem. This guide shows you what to include.
What should a password security policy for a small business include?
A good password security policy asks for long, unique passphrases for every account, a business password manager for storing and sharing them, and two-step login on email, banking, hosting and admin tools. It bans password sharing on WhatsApp or sheets, removes access when staff leave, and changes passwords only when there is a reason, such as a suspected leak.
Key takeaways
- Length beats complexity: use passphrases of three or more random words.
- Every account needs a different password; a password manager makes this easy.
- Two-step login on email, banking, hosting and admin tools is a must.
- Never share passwords on WhatsApp, email or spreadsheets.
- Change passwords when there is a leak or a staff exit, not on a fixed timer.
- Keep the policy to one page so people read it.
Why does a small business need a password security policy?
A small business needs a password security policy because stolen and reused passwords are a top cause of hacked email, websites and bank accounts. A written policy makes good habits the normal way of working for everyone.
- Staff reuse personal passwords for work tools
- Passwords are saved in WhatsApp chats, notebooks or shared Excel sheets
- Former staff and agencies still know key passwords
- One person holds all logins, which is risky if they leave or are unavailable
- Website and hosting logins have no two-step login
A clear policy fixes these problems at low cost. It is one of the first items in our cybersecurity checklist for business.
What makes a strong password today?
A strong password is long, unique and hard to guess. Modern guidance, including from NIST in the USA, favours length and uniqueness over forced symbols and frequent changes.
| Old habit | Better practice | Why |
|---|---|---|
| 8 characters with symbols, like P@ssw0rd! | Passphrase of 3โ4 random words, 14+ characters | Long passphrases are harder to crack and easier to remember |
| Change every 30 or 90 days | Change when there is a reason | Forced changes lead to weak patterns like Name@2024, Name@2025 |
| Same password with small changes | A different password for every account | One leak should not open every door |
| Write passwords in a notebook or sheet | Store them in a password manager | Encrypted, searchable and shareable with control |
| Security questions like mother's name | Random answers saved in the manager | Real answers are often found on social media |
Password security policy template: what to include
A practical password security policy covers password rules, a password manager, two-step login, sharing, staff joining and leaving, and what to do if a password leaks. Keep it to about one page.
1. Password rules
- Use at least 14 characters for work accounts; passphrases are welcome
- Use a different password for every work account
- Never use work passwords for personal accounts
- Do not use names, dates, phone numbers or the company name
2. Storage and sharing
- All work passwords are stored in the company password manager
- Shared logins are shared only through the password manager
- Never send passwords by WhatsApp, SMS, email or in documents
- Do not save work passwords in browsers on shared or personal devices
3. Two-step login
- Two-step login is required on email, banking, hosting, domain, website admin, CRM and social media accounts
- Use an authenticator app or security key where possible
- Keep backup codes in the password manager
4. Joining, leaving and incidents
- New staff get their own accounts, never a shared admin login
- When someone leaves, remove access and change any shared passwords they knew the same day
- Report any suspected leak or phishing click immediately
- Change passwords at once if a service reports a breach
Do we need a password manager, and which type?
Yes. A business password manager is the easiest way to make every password unique and to share access safely. Choose one with team sharing, two-step login, admin controls and easy removal of users.
Business password manager
- Creates and fills strong, unique passwords
- Share logins without showing the password
- Remove a leaver's access in one place
- Audit reports show weak or reused passwords
Browser or sheet storage
- Hard to control who sees what
- No record of who used which login
- Sheets get forwarded, printed and copied
- Personal browser profiles mix home and work
What to look for
- Shared folders or vaults per team
- Two-step login for the manager itself
- Admin recovery if a staff member forgets their master password
- Apps for Windows, Mac, Android and iPhone
- Clear security information from the vendor
How to roll out two-step login for your team
Roll out two-step login one system at a time, starting with email, then banking, hosting, domain and website admin. Give staff a short guide and a deadline, and help them set up an authenticator app.
- 1
List your key accounts
Email, bank, payment gateway, domain registrar, hosting, website admin, CRM, accounting, social media.
- 2
Pick the method
Use an authenticator app or security keys. Use SMS only if nothing else is offered, as SIM swap scams exist.
- 3
Start with admins and finance
These accounts give the most access, so secure them first.
- 4
Turn it on company-wide
In Google Workspace or Microsoft 365, enforce two-step login for all users after a short grace period.
- 5
Save backup codes
Store recovery codes in the password manager, not on the phone itself.
- 6
Plan for lost phones
Write a short process for resetting two-step login when a phone is lost or changed.
How often should passwords be changed?
Change passwords when there is a reason: a data breach, a phishing click, a staff member leaving, or signs of misuse. Forced changes every month usually make passwords weaker, not stronger.
| Event | Action |
|---|---|
| Service reports a data breach | Change that password and any place it was reused |
| Staff member or agency leaves | Remove their account; change shared passwords they knew |
| Phishing link clicked and login entered | Change password from a clean device, check two-step login and sessions |
| Password manager shows reused or weak password | Replace it with a new unique one |
| Website or hosting hacked | Change all related passwords and keys; see our website hacked guide |
Passwords for websites, hosting and admin panels
Website, hosting and admin panel logins need extra care because they control your online presence and customer data. Each person should have their own login with only the access they need, plus two-step login.
- Separate logins for each developer, agency and staff member in WordPress, Shopify or Laravel admin
- Unique strong passwords for hosting panel, FTP/SFTP, database and SSH
- Use SSH keys instead of passwords for servers
- API keys stored in a secrets manager or environment file, not in code
- Remove agency access when a project ends
See our WordPress security and Shopify security pages for platform-specific steps, and our phishing protection training to stop staff giving passwords to fake login pages.
Our help with password policy and access setup
We help you write a one-page policy, choose and set up a password manager, turn on two-step login across your tools, and clean up old accounts. Most small teams can be set up within one to two weeks.
- Number of staff and accounts
- Tools in use: Google Workspace, Microsoft 365, Zoho, CRM, hosting
- Website platforms and admin users
- Training sessions for staff
- Ongoing access reviews
You get a clear quote after a free call. Our parent team, Shivah Web Tech, has 11+ years of experience. This work is often part of our cybersecurity consulting service. Contact us to start.
Related Pages
Phishing Training
Teach your team to spot fake emails, calls and WhatsApp scams.
Resources
Free cybersecurity checklist for business owners: website safety, hacked site first aid, passwords, phishing, staff exits and backups. Use it today.
Security Consulting
Practical security plans, policies and advice for owners.
SPF, DKIM, DMARC Guide
Stop fake emails from your domain and improve inbox delivery.
Frequently Asked Questions
What is a good password length for business accounts?
Aim for at least 14 characters for work accounts, and longer for admin, email and banking logins. A passphrase made of three or four random words is long, strong and easier to remember. Length and uniqueness matter more than adding many symbols.
Is it safe to save passwords in Chrome or other browsers?
Browser password managers are better than reusing passwords, but they are harder to control for a business. They mix personal and work accounts and do not offer team sharing or easy removal of access. A business password manager is the better choice for company logins.
Should we force staff to change passwords every 90 days?
Most modern guidance says no. Forced changes on a timer lead to weak patterns like adding a number at the end. Instead, require long unique passwords, two-step login, and change passwords when there is a breach, a phishing click or a staff exit.
Is SMS OTP good enough for two-step login?
SMS OTP is better than no two-step login, but it can be attacked through SIM swap fraud and fake login pages. Authenticator apps, passkeys or physical security keys are stronger. Use them for email, hosting, banking and admin accounts where possible.
How do we safely share one login among a team?
Use the sharing feature of a business password manager. Team members can log in without seeing the password, and you can remove access in one click. Better still, give each person their own account in the tool so you know who did what.
What should we do with passwords when an employee leaves?
On their last day, disable their accounts, remove them from the password manager, and change any shared passwords they knew, such as hosting, social media or Wi-Fi. Also check for forwarding rules and transfer ownership of files and documents they managed.
Who should own the master admin passwords in a small business?
The business owner or a trusted director should own the master accounts for email, domain, hosting and banking, not an outside agency or a single employee. Store these in the password manager with emergency access for a second trusted person, so the business is never locked out if someone leaves or is unavailable.
Do we need a written password policy if we already use two-step login?
Yes. Two-step login is a strong control, but a written policy also covers password sharing, staff exits, agency access, breach response and storage rules. A one-page policy makes sure everyone, including new joiners, follows the same habits, and it helps during audits and client security questionnaires.
Are passkeys better than passwords?
For accounts that support them, passkeys are generally safer than passwords because they cannot be typed into a fake website and are not reused across sites. They are supported by major services from Google, Microsoft and Apple. Keep a recovery method set up in case a device is lost.
Talk to our team today
Call or WhatsApp +91 85808 92163. We reply fast, Monday to Friday.