Proton
BUSINESS SECURITY

5 Password policy best practices to protect your business

by Fergus O'Sullivan | January 28, 2025
2-minute read

Does your organization have a password policy? This is the set of rules employees must abide by when creating new passwords and logging into their accounts. A robust password policy allows employees to be responsible for protecting themselves and your business.

Here are our 4 tips on creating a strong password policy:


Tip 1: Use random passwords with a minimum length

All passwords should be generated randomly rather than created by humans, who tend to choose easy-to-remember passwords that are vulnerable to brute-force attacks. Hackers use software to systematically guess passwords, so randomization is key.


Another important factor is password length. A good rule of thumb is a minimum of 16 characters — longer passwords make it significantly harder for hackers to crack them. If remembering complex passwords is a challenge, passphrases are a great alternative, offering both security and memorability.


Tip 2: Never reuse passwords

Another important thing that should be part of any password policy is that you should never reuse passwords. This means all your accounts should have their own unique passwords, and you should never recycle old passwords. For every new account you create, you need to generate a new, random password.


The reason for this is something called credential stuffing, where a hacker will take all the logins leaked during a large breach and try hundreds of sites to see if they will work there, too. It’s a serious risk, too, implicated in high-profile data leaks. In 2024, Dropbox, LinkedIn, and X (formerly known as Twitter) have all been affected, with 26 billion records being leaked.

Protect your business data with Proton Pass

Tip 3: Enable two-factor authentication (2FA)

If passwords protect your accounts, two-factor authentication can protect your passwords. 2FA is a temporary code, usually generated by an app on your phone. When you access an account, you must enter both the password and the code from the 2FA app. You can also use biometric logins, which are attributes such as your fingerprint or facial scan that can’t be easily replicated, to log in to many online accounts.


Using 2FA means that even if somebody unauthorized were to get access to your password, they would also need the phone or other device with your 2FA app on it to gain entry to your account. 2FA is the best way to defend against phishing attacks. It’s a powerful tool, but sadly underutilized.


Tip 4: Use a password manager to ensure compliance

Remembering long, random passwords is practically impossible — that’s their strength, after all — and manually keeping track of them on paper is not secure. To make sure your team actually implements your password policy, they’ll need a password manager, a piece of software that can generate strong passwords, autofill them, enable 2FA, and store your passwords for you.

Tip 5: Protect Your Business with Proton Pass

Proton Pass for Business is the perfect companion for any password policy you’re working on for your team, allowing your colleagues to safely share workplace login details using secure links. And you can manage your users from the admin panel, so you can grant or revoke access as needed or enforce 2FA. It also offers your organization security in other forms, like through our hide-my-email aliases, which enter a spoofed email address when creating a new online account, offering an extra layer of anonymity. With Pass Professional, users get access to Proton Sentinel, an advanced program that helps protect against account takeover attacks.


Proton Pass

Join over 100,000 business users who trust Proton to secure their data

  • Pass Essentials
    • Proton Pass

    Minimum 3 users

    Account protection for small teams, includes:

    • Unlimited logins, notes, and credit cards

    • Browser, mobile, and desktop apps

    • Secure vault, item and link sharing

    • Built-in 2FA authenticator

    • Dark Web Monitoring

    • Password health check

    • Passkey support on all devices

    • Unlimited hide-my-email aliases


  • Recommended

    Pass Professional
    • Proton Pass

    Minimum 3 users

    Everything in Pass Essentials, plus:

    • SSO and SCIM

    • Detailed activity logs

    • Enterprise policies

    • Advanced account protection

    • File attachment

    • SIEM integration

    • Command line interface (CLI)


  • Workspace Standard
    • Proton Pass
    • Proton VPN
    • Proton Mail
    • Proton Calendar
    • Proton Drive

    All Proton products for business, including:

    • Password manager to secure credentials

    • 1 TB storage per user

    • 15 custom email domains

    • Secure personal and shared calendar

    • Cloud storage and sharing for large files

    • Advanced account protection

    • Manage user permissions and access

    • VPN connection for 10 devices per user


30-day money-back guarantee

AS RECOMMENDED BY

ZDNET

Best free password manager for privacy. Proton Pass is a well-designed and highly secure password manager with a handful of unique features.

Linus Tech Tips

Proton has a password manager that got really good, and really quickly. It has support for making burner emails, or aliases, two-factor support, passkey support, and recently, gained the ability to lock your account with a different password than your account password.

Digital Trends

Overall, I'd recommend Proton Pass as the best password manager, especially if you're looking for a free or low-cost paid plan that's the most intuitive and offers the easiest sharing.

Proton Pass

Swiss vault for your business passwords

Securely and easily share, store, and manage passwords for work.