How to Write a Password Policy for a Small Business (the Sensible Way)
Most password policies are copied from the internet and quietly ignored because they are miserable to follow. This article shows how to write a short, NCSC-aligned policy your team will actually use: longer passphrases instead of fiddly complexity, no forced monthly changes without a reason, multi-factor authentication on everything, and a password manager so nobody has to remember the lot.
Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.
Why most password policies fail
Most small-business password policies are copied off the internet, printed once, and quietly ignored. They demand a capital letter, a number, a symbol and a change every thirty days — and the entirely predictable result is a wall of sticky notes and a company full of variations on Summer2025!.
The good news is that modern advice, led by the UK’s National Cyber Security Centre (NCSC), is both more secure and far kinder to your staff. A sensible policy is easier to follow, not harder. This article shows you what to put in it and, just as importantly, what to leave out.
Length beats complexity
The old rules — a symbol here, a number there — produce passwords that are hard for humans to remember and surprisingly easy for computers to guess, because everyone reaches for the same tricks. P@ssw0rd1 is short and predictable, and a cracking tool chews through it in moments.
The NCSC’s advice is to think in passphrases: three or four random words strung together, such as copper-anchor-violin-drizzle. It is long, it means nothing to anyone else, and yet a person can actually remember it. Length is what defeats the automated guessing tools, so a long, ordinary phrase beats a short, tortured one every time.
Your policy should say, in plain words: make passwords long — aim for a passphrase of at least three random words — rather than short and fiddly.
Every password unique — no reuse
The most damaging password habit is reuse. When one website suffers a breach and your email-and-password combination leaks, criminals try that same pair on everything else — your email, your banking, your Microsoft 365. This is called credential stuffing, and it is automated and relentless.
So the rule is simple and non-negotiable: every account gets its own unique password, and passwords are never shared between people or written down where others can find them. Which immediately raises the obvious objection — nobody can remember dozens of unique passphrases. That is exactly what the next section solves.
Give people a password manager
A password manager is the single change that turns a good policy from wishful thinking into something people actually do. It generates a long, unique password for every account and stores them all securely behind one master password. Your staff remember one strong passphrase; the software remembers everything else and fills it in for them.
For a UK small business we like Proton Pass — it is straightforward for non-technical staff, it works across phones and computers, and it comes from Proton, a privacy-focused company based in Switzerland with strong data-protection credentials. Whichever tool you choose, the policy should name one approved password manager so that everyone stores work passwords in the same, sanctioned place rather than in browsers, notebooks or their heads. If you want to compare options first, our rundown of the best password managers for small business walks through the choices.
A short policy people actually follow protects you far better than a long one that lives in a drawer.
Stop forcing routine password changes
Here is the part that surprises people most: you should not force staff to change their passwords on a schedule. The NCSC now advises against routine expiry, and the reasoning is sound. When you make people change a password every month, they do the least-effort thing — Summer2025! becomes Autumn2025! — which is entirely predictable and no safer at all. Forced changes create weak patterns and help no one.
Instead, change a password when there is an actual reason to: a suspected or confirmed compromise, a device lost or stolen, or a member of staff leaving. A strong, unique passphrase that is backed by multi-factor authentication does not need swapping out on a timer. Say this explicitly in your policy — it saves your team a recurring irritation and makes them more likely to take the rest of it seriously.
Turn on multi-factor authentication everywhere
Even a strong password can be stolen through a convincing phishing email. Multi-factor authentication (MFA) is the safety net: a second step, usually a prompt or code on your phone, so that a stolen password on its own is not enough to get in. It is the most effective single control most small businesses can turn on.
Cyber Essentials already requires MFA on all cloud services, so this is not optional if certification matters to you — and it should be standard regardless. Your policy should state plainly: MFA is switched on wherever it is offered, and always for email, banking, and any administrator account. Our plain-English guide to multi-factor authentication is worth sharing with the team.
Name someone to own it
A policy with no owner slowly rots. Someone — a director, an office manager, or your IT provider — needs to be responsible for keeping it alive: making sure new starters are set up in the password manager and with MFA, that leavers’ access is removed promptly, and that the policy is glanced over once a year to check it still reflects how you work. It need not be onerous. It just needs a name against it.
Your one-page policy
Strip away the jargon and a genuinely good small-business password policy fits on a single page:
- Use long passphrases — at least three random words — rather than short, complex-looking passwords.
- Every password is unique. Never reuse a password across accounts.
- Never share or reuse passwords, and never store them in notebooks, spreadsheets or browsers.
- Store all work passwords in our approved password manager, behind one strong master passphrase.
- Turn on multi-factor authentication everywhere it is available, always for email, banking and admin accounts.
- We do not force routine password changes — passwords are changed only when there is a reason, such as a suspected compromise or someone leaving.
- Report anything suspicious — a phishing attempt, a lost device, a password you think may be exposed — straight away.
- [Name] is responsible for keeping this policy and our accounts in order.
That is it. A policy this short has a fighting chance of being read and followed, which is worth far more than a ten-page document nobody opens.
Where this fits in the bigger picture
Passwords are one plank of good security, and they sit alongside sensible backups, patched devices, and staff who can spot a scam. If you would like a hand rolling out a password manager and MFA across your team, or a wider look at your cyber-security, get in touch — we are happy to have a straight, jargon-free conversation about what your business actually needs.
Frequently asked questions
How long should a password be?
Length matters far more than a mix of odd characters. The NCSC recommends thinking in terms of memorable passphrases — three or four random words strung together, such as a phrase you would never guess for someone else. That is both far harder for a computer to crack and far easier for a person to remember than something like P@ssw0rd1, which is short and predictable despite ticking the 'complexity' boxes.
Should we force staff to change passwords every month?
No — and this surprises people. The NCSC advises against routine forced password changes, because they push staff towards weak, predictable patterns like adding a number on the end each time. You should only force a change when there is a reason to, such as a suspected compromise or someone leaving. A strong, unique password protected by MFA does not need replacing on a timer.
Do we really need a password manager?
If you expect staff to use a long, unique password for every account — and you should — then yes, because no one can remember dozens of them. A password manager generates and stores strong passwords behind one master password, so people only remember one. It is the single change that makes a good password policy actually workable rather than aspirational.
Is multi-factor authentication part of a password policy?
It should be. A password can be stolen or guessed; multi-factor authentication means a stolen password alone is not enough to get in. Cyber Essentials already requires MFA on all cloud services, so any modern password policy should state plainly that MFA is switched on wherever it is available, especially for email, banking and admin accounts.
What should a small-business password policy actually cover?
Keep it to one page: use long passphrases, make every password unique, never reuse or share them, store them in the approved password manager, turn on MFA everywhere it is offered, and report anything suspicious. Name who is responsible for keeping it going. A short policy people follow beats a long one they ignore.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.