4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Insights & News

Password Policy for Australian Small Business

A workable password policy for an Australian small business is shorter than most templates suggest. Require long passphrases rather than complex short ones, require a unique password for every account, require multi-factor authentication on anything that matters, provide a password manager so those rules are possible to follow, and change passwords when there is a reason rather than on a calendar. That is most of it. Policies fail when they demand behaviour people cannot sustain, because staff then work around them in ways that leave you worse off than having no policy at all.

Manager reviewing a business policy document at a desk.

Key facts

  • Length beats complexity. A long passphrase is harder to crack and easier to remember than a short password padded with symbols.
  • Forced periodic expiry is no longer recommended practice. It produces predictable variations and encourages people to write passwords down.
  • Uniqueness is the rule that does the most work, because credential reuse is how one unrelated breach becomes your breach.
  • Blocklisting known-breached passwords is more effective than complexity rules, since it stops the passwords attackers already have on file.
  • A policy is only enforceable if you supply the tools. Requiring unique passwords for forty systems without a password manager is a rule that cannot be met.
  • Multi-factor authentication belongs in the same policy. It covers the case a password policy cannot, which is a credential stolen outright.

Why has the advice on password expiry changed?

Because the evidence went against it. Forcing a change every ninety days was meant to limit how long a stolen credential stayed useful, but in practice it changed behaviour in the wrong direction. People do not invent a fresh strong password each quarter. They increment the one they have, so a password gets one predictable character worse each cycle, and the pattern is easy for an attacker holding an old credential to guess. Rotation also pushes people towards writing passwords down, because remembering a moving target across dozens of systems is not realistic.

Current guidance from major standards bodies favours long unique passwords held until there is a reason to change, with the reasons being a known or suspected breach, a shared credential when someone leaves, or any sign of compromise. This is a real improvement, but it depends on something the old advice did not: you need visibility of whether a credential has been breached. A password manager that reports breach exposure gives you that, and without it the no-expiry approach is a guess rather than a policy.

What should the policy require?

Keep it to rules you can state plainly and enforce. A minimum length in the range of twelve to sixteen characters, phrased to encourage passphrases rather than symbol substitution. A unique password for every account, with no reuse between work and personal systems. Multi-factor authentication mandatory on email, remote access, banking, administrative accounts and anything holding customer data. Credentials stored only in the approved password manager, never in browsers, spreadsheets, notes or chat. Passwords changed on evidence of compromise, on staff departure where a credential was shared, and never shared outside a vault.

Add a short section on administrative accounts, because that is where the risk concentrates. Administrators should have separate accounts for privileged work, those accounts should carry stronger multi-factor requirements, and they should not be used for daily email and browsing. It is a small paragraph that removes a large amount of exposure.

Resist the urge to include everything a template offers. A two-page policy people have read beats a twelve-page one nobody has, and every rule you add that cannot be enforced teaches staff that the policy is decorative.

Does an Australian SME need a written password policy at all?

It is not required by name in Australian law, but the obligations behind it are real. Under the Privacy Act, an organisation covered by the Australian Privacy Principles must take reasonable steps to protect personal information it holds, and credential handling is squarely part of that. If a breach exposes personal information and you are assessing it under the Notifiable Data Breaches scheme, how credentials were managed becomes part of the picture.

There are also commercial drivers that arrive whether or not you sought them. Cyber insurance applications now routinely ask about password policy, multi-factor authentication coverage and password manager use, and the answers affect both premium and whether a claim is paid. Larger customers increasingly send security questionnaires before signing, and tenders often ask outright. A short, accurate policy you can hand over is worth having before someone asks for it. If you are working towards the Essential Eight, restricting administrative privileges and multi-factor authentication both connect directly to this.

How do you make a policy that people follow?

Give them the tools first, then write the rules. A password manager deployed across the fleet, with the browser extension installed and the vault structure set up around how teams work, turns most of the policy into the default behaviour rather than a compliance exercise. Unique passwords stop being a rule and become what happens automatically when the vault generates them.

Then keep the policy visible and short, cover it at induction rather than only at the annual training, and check the reporting. A password manager that flags reused and breached credentials tells you whether the policy is being followed, which is the difference between a policy and a document. See password management for the platform side, multi-factor authentication for the layer that sits beside it, and security awareness training for keeping it front of mind.

Frequently asked questions

Should we still force staff to change passwords every 90 days?

No. Forced periodic expiry is no longer recommended by the major standards bodies, because it produces predictable incremental changes and drives people to write passwords down. Replace it with long unique passwords, breach monitoring so you know when a specific credential is exposed, and changes triggered by evidence rather than by the calendar. Keep rotation for the cases that warrant it: suspected compromise, and shared credentials when someone leaves.

How long should a business password be?

Aim for at least twelve to sixteen characters, and prefer a passphrase of several unrelated words over a short password with substituted symbols. Length adds far more resistance to cracking than complexity rules do. For credentials generated and stored by a password manager, go longer still, because nobody has to type them. The exception is anything you must type regularly from memory, such as the vault's own password or a device login, where a memorable passphrase is the right shape.

Does a password policy need to cover contractors?

Yes, and it is often the gap. Contractors, bookkeepers and external agencies frequently end up with shared credentials sent by email because adding them properly seemed like too much effort. The policy should require that external parties get guest access to a specific vault rather than a copy of a password, and that their access is reviewed and removed when the engagement ends. Include the review step, because external access is what tends to persist unnoticed.

Where do passkeys fit into a password policy?

They are worth acknowledging now and mandating later. Passkeys remove the password from the sign-in entirely and are resistant to phishing in a way passwords with codes are not, but coverage across business systems is still patchy, so a policy cannot yet require them everywhere. The sensible position is to allow and encourage passkeys where a system supports them, while the password and multi-factor rules continue to apply everywhere else.

If you need a password policy that staff will follow and that stands up to an insurance questionnaire, we can draft it around what your business runs and deploy the tooling that makes it enforceable. Request a callback and we will work through it.

Brett Muscio

About the author

Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on cybersecurity, including password policy, multi-factor authentication, the Essential Eight, and Microsoft 365 hardening, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.

Recent Posts

Scroll to Top

Thanks!

We've received your request.

We'll call you back the same business day

Book a meeting

Tell us a bit about your business

We'll call you back the same business day

What are you interested in?
What are you trying to solve?

Contact details