Security2024-05-02

The Password Security Audit Checklist Every Company Needs

80% of data breaches involve weak or stolen passwords. Here's a security architect's checklist for password policies that actually prevent breaches.

#password#security#audit#best-practices#enterprise

Let me tell you a story. Last year, a Fortune 500 company was breached. The attack vector? An employee's password was Company2023!. It was in every breach database. The attacker tried it in the first 10 minutes.

I've audited password policies for 30+ companies. Here's what I check — and what yours is probably getting wrong.

The Audit Checklist

1. Password Length Requirements

❌ "Minimum 8 characters" ✅ "Minimum 14 characters, recommend 20+"

Length beats complexity. A 14-character lowercase password has more entropy than an 8-character password with symbols.

2. No Composition Rules

❌ "Must contain uppercase, lowercase, number, symbol" ✅ "No composition rules — just minimum length"

NIST SP 800-63B explicitly says: don't require composition rules. They create predictable patterns (Capital letter first, number at end, symbol before number).

3. Breached Password Detection

❌ Not checking ✅ Checking against known breach databases

Use a Password Generator that checks against common password lists. If your password is in the top 100,000 most common passwords, reject it.

4. No Periodic Rotation

❌ "Change password every 90 days" ✅ "Change only if compromised"

Microsoft, Google, and NIST all recommend against forced rotation. It leads to Password1!, Password2!, Password3! — weaker, not stronger.

5. Multi-Factor Authentication

❌ Password only ✅ Password + MFA (TOTP or hardware key)

MFA blocks 99.9% of credential-based attacks. No exceptions. If your company doesn't have MFA, fix this TODAY.

6. Rate Limiting

❌ Unlimited login attempts ✅ Lock after 5 failed attempts, exponential backoff

Without rate limiting, an attacker can brute-force any password. With rate limiting, a 10-character password takes centuries.

7. Password Storage

❌ MD5, SHA-256 (without salt) ✅ bcrypt, Argon2id with per-user salt

Use a Hash Generator to understand the difference between hashing algorithms.

The Scorecard

Check Weight Common Failure
Length ≥ 14 High Require 8 chars
No composition Medium Force Aa1! pattern
Breach check High Not implemented
No rotation Medium 90-day policy
MFA required Critical Optional MFA
Rate limiting High No limit
bcrypt/Argon2 Critical MD5/SHA-256

The Bottom Line

Password security isn't about complexity. It's about length, breach detection, and MFA. Fix these three things and you'll block 95% of credential-based attacks.

Generate strong, unique passwords with our free Password Generator — configurable length, character sets, and strength validation.

🛠

Try It Yourself

Put what you've learned into practice with our free online tools.