ICT Security: Password Policy

09 May 2023

Last week was World Password Day, so it’s a great time to reflect on having a strong password policy.

Even if we ensure our clients’ systems are secure and up-to-date, internal staff often remain the weakest link. That’s why every company and organization should have its own password policy!

ICT Security: Password Policy

There are several signs that someone may have accessed your password and account. Alerts about hacked accounts from Google, Apple, and Microsoft are often serious—read those emails carefully to know what actions to take.

 

Recognize If You’ve Been Hacked

If you recognize any of the following, you may be a victim of cybercrime. It’s best to leave the device on, disconnect from the internet, and contact your organization’s security officer. They’ll know the next steps.

 

You May Be a Victim of Cybercrime

  • Files won’t open
  • Unknown (malicious) software is installed
  • Your identity has been stolen
  • Messages are sent from your name
  • Your computer frequently crashes or is very slow
  • You receive strange notifications
  • Your password no longer works
  • Files are missing
  • You’re asked to provide verification codes or receive them without initiating login
  • Your account settings have changed
  • You’ve lost access to your computer

 

Data Breach

You may have an account that was part of a data breach and your information was exposed.

To check if your email or phone number was involved, or if your password was compromised, visit Have I Been Pwned and Scattered Secrets.

 

Can You Prevent Cybercrime?

You can ensure digital systems are secure and up-to-date, but people remain the weakest link! Internally, implement a strong password policy and raise awareness about phishing.

 

Password Policy

Your password policy should include at least:

  1. Use a password generator
  2. Enable multi-factor authentication
  3. Never reuse passwords
Share page: