5 Password policy best practices to protect your business
by Fergus O'Sullivan | January 28, 2025
2-minute read

Does your organization have a password policy? This is the set of rules employees must abide by when creating new passwords and logging into their accounts. A robust password policy allows employees to be responsible for protecting themselves and your business.
Here are our 4 tips on creating a strong password policy:
Tip 1: Use random passwords with a minimum length
All passwords should be generated randomly rather than created by humans, who tend to choose easy-to-remember passwords that are vulnerable to brute-force attacks. Hackers use software to systematically guess passwords, so randomization is key.
Another important factor is password length. A good rule of thumb is a minimum of 16 characters — longer passwords make it significantly harder for hackers to crack them. If remembering complex passwords is a challenge, passphrases are a great alternative, offering both security and memorability.
Tip 2: Never reuse passwords
Another important thing that should be part of any password policy is that you should never reuse passwords. This means all your accounts should have their own unique passwords, and you should never recycle old passwords. For every new account you create, you need to generate a new, random password.
The reason for this is something called credential stuffing, where a hacker will take all the logins leaked during a large breach and try hundreds of sites to see if they will work there, too. It’s a serious risk, too, implicated in high-profile data leaks. In 2024, Dropbox, LinkedIn, and X (formerly known as Twitter) have all been affected, with 26 billion records being leaked.
Protect your business data with Proton Pass
Tip 3: Enable two-factor authentication (2FA)
If passwords protect your accounts, two-factor authentication can protect your passwords. 2FA is a temporary code, usually generated by an app on your phone. When you access an account, you must enter both the password and the code from the 2FA app. You can also use biometric logins, which are attributes such as your fingerprint or facial scan that can’t be easily replicated, to log in to many online accounts.
Using 2FA means that even if somebody unauthorized were to get access to your password, they would also need the phone or other device with your 2FA app on it to gain entry to your account. 2FA is the best way to defend against phishing attacks. It’s a powerful tool, but sadly underutilized.
Tip 4: Use a password manager to ensure compliance
Remembering long, random passwords is practically impossible — that’s their strength, after all — and manually keeping track of them on paper is not secure. To make sure your team actually implements your password policy, they’ll need a password manager, a piece of software that can generate strong passwords, autofill them, enable 2FA, and store your passwords for you.
Tip 5: Protect Your Business with Proton Pass
Proton Pass for Business is the perfect companion for any password policy you’re working on for your team, allowing your colleagues to safely share workplace login details using secure links. And you can manage your users from the admin panel, so you can grant or revoke access as needed or enforce 2FA. It also offers your organization security in other forms, like through our hide-my-email aliases, which enter a spoofed email address when creating a new online account, offering an extra layer of anonymity. With Pass Professional, users get access to Proton Sentinel, an advanced program that helps protect against account takeover attacks.



Join over 100,000 business users who trust Proton to secure their data
Claim offer
Pass Professional
1-year plan
Minimum 3 users
Pass Professional
1-month plan
Minimum 3 users
30-day money-back guarantee
As recommended by
Swiss vault for your business passwords
Securely and easily share, store, and manage passwords for work.
