The Password Security Audit Checklist Every Company Needs
80% of data breaches involve weak or stolen passwords. Here's a security architect's checklist for password policies that actually prevent breaches.
Let me tell you a story. Last year, a Fortune 500 company was breached. The attack vector? An employee's password was Company2023!. It was in every breach database. The attacker tried it in the first 10 minutes.
I've audited password policies for 30+ companies. Here's what I check — and what yours is probably getting wrong.
The Audit Checklist
1. Password Length Requirements
❌ "Minimum 8 characters" ✅ "Minimum 14 characters, recommend 20+"
Length beats complexity. A 14-character lowercase password has more entropy than an 8-character password with symbols.
2. No Composition Rules
❌ "Must contain uppercase, lowercase, number, symbol" ✅ "No composition rules — just minimum length"
NIST SP 800-63B explicitly says: don't require composition rules. They create predictable patterns (Capital letter first, number at end, symbol before number).
3. Breached Password Detection
❌ Not checking ✅ Checking against known breach databases
Use a Password Generator that checks against common password lists. If your password is in the top 100,000 most common passwords, reject it.
4. No Periodic Rotation
❌ "Change password every 90 days" ✅ "Change only if compromised"
Microsoft, Google, and NIST all recommend against forced rotation. It leads to Password1!, Password2!, Password3! — weaker, not stronger.
5. Multi-Factor Authentication
❌ Password only ✅ Password + MFA (TOTP or hardware key)
MFA blocks 99.9% of credential-based attacks. No exceptions. If your company doesn't have MFA, fix this TODAY.
6. Rate Limiting
❌ Unlimited login attempts ✅ Lock after 5 failed attempts, exponential backoff
Without rate limiting, an attacker can brute-force any password. With rate limiting, a 10-character password takes centuries.
7. Password Storage
❌ MD5, SHA-256 (without salt) ✅ bcrypt, Argon2id with per-user salt
Use a Hash Generator to understand the difference between hashing algorithms.
The Scorecard
| Check | Weight | Common Failure |
|---|---|---|
| Length ≥ 14 | High | Require 8 chars |
| No composition | Medium | Force Aa1! pattern |
| Breach check | High | Not implemented |
| No rotation | Medium | 90-day policy |
| MFA required | Critical | Optional MFA |
| Rate limiting | High | No limit |
| bcrypt/Argon2 | Critical | MD5/SHA-256 |
The Bottom Line
Password security isn't about complexity. It's about length, breach detection, and MFA. Fix these three things and you'll block 95% of credential-based attacks.
Generate strong, unique passwords with our free Password Generator — configurable length, character sets, and strength validation.
Try It Yourself
Put what you've learned into practice with our free online tools.
Related Articles
Smart Contract Security: My 50-Point Audit Checklist
I've found $2M in vulnerabilities across 20 smart contract audits. Here's my checklist...
DeFi Protocol Security: What I Found Auditing 20 Smart Contracts
I audited 20 DeFi protocols. 17 had critical vulnerabilities. Here's what I found...
README-Driven Development: Why I Write Docs Before Code
If you can't explain it in a README, you can't code it. Here's my process...