Knowledge base

Password and MFA policy

Tips for a good password and MFA policy: long passphrases, MFA on every account, no reuse, and a password manager. Plus how B/Focused does it.

Need support? +31 45 303 0003 Advice or a quote? +31 45 303 0232

A good password and MFA policy is one of the simplest and most effective measures against cybercrime. On this page you’ll read how we do it ourselves and which tips you can apply within your own organisation.

What added value do we offer your business with a good password and MFA policy?

Better security

We only work with long hexadecimal passwords that normal people cannot remember, not even if we show them for a minute. We use special tooling for this, secured with multifactor authentication. In the background, it is scanned whether our passwords have been hacked. If that is the case, we are automatically alerted via a high-priority ticket.

Good guidance and policy

Only with good advice and knowledge transfer can we convince our employees to see the added value of a good password and MFA policy themselves. We can request reports of which employees have viewed which passwords and report any deviations. Employees can never download or export an entire password list.

Multifactor authentication

Passwords are dead… well, dying at least. They pose too great a risk, which is why multifactor authentication (MFA) is being implemented on more and more systems. We have made MFA mandatory on all platforms we use. Combined with a good password and good tooling, it becomes very difficult to hack our company.

Alignment with legislation

With our policy we comply with the GDPR and take into account the requirements from NIS2 / the Cyberbeveiligingswet (Cbw). This matters, because you as a client may also get questions about this.

ISO 27001

We are working towards ISO 27001 certification. This standard concerns information security and aligns with the requirements from NIS2 / the Cyberbeveiligingswet (Cbw).

Strategy in case of a cyber incident

We have a monitoring strategy and an emergency strategy that we can carry out in case of a cyber incident in our password tooling and procedures. Hopefully we will never need these, but if the need arises, we know what to do.

Which tips can you adopt from us for a better password and MFA policy within your organisation?

Implement a good password policy

  • Only change a password if you suspect misuse or a data breach, not periodically
  • Use a long passphrase instead of a short password, preferably 15 characters or more
  • Length matters more than complexity: a long passphrase is stronger than a short password full of capital letters and special characters
  • Never use the same password for multiple accounts
  • Turn on multifactor authentication (MFA) on every account that supports it
  • Don’t make up passwords using data that can be found on social media
  • Give your staff tips and tricks about data security and passwords
  • Don’t accept post-its with passwords on or around your employees’ workstations
  • Even better: use generated passwords and a password manager for businesses

Your dog, partner, children or favourite football club are not a good password!

If we had to hack your password

We would start by gathering information. Nowadays it’s easy to find out via social media what your children, partner and even your pets are called. Dates of birth are also relatively easy to find out.

Your username is also important. In most cases that’s your email address, so this too is relatively easy to find out.

Then there are a number of standard passwords that are often used, such as: password, 123456, letmein, the local football club, and so on. These lists are easy to download and enter into a password scanner. In addition, passwords from previous data breaches are tried on a large scale on other services.

Do you recognise any of the above points in your password? Then don’t doubt that, after some preliminary research, we would have access to your account within half an hour!

How quickly can a password be hacked?

That depends on various factors, such as the computing power of the attacker and the length and predictability of the password. Short passwords can be cracked quickly with modern hardware, even if they contain capital letters, numbers and special characters. Every extra character makes cracking exponentially harder. That’s why a long, unique passphrase combined with MFA offers the best protection.

Frequently asked questions

How often should I change my password?

You don't need to change a password periodically. This is only necessary if you suspect misuse or a data breach. Length and uniqueness are more important than regularly changing a password.

What is better, a complex password or a long passphrase?

A long passphrase is stronger than a short password full of capital letters and special characters. Length matters more than complexity when it comes to security. Preferably, use a passphrase of 15 characters or more.

How does B/Focused itself handle passwords?

B/Focused only works with long hexadecimal passwords that normal people cannot remember. Special tooling is used for this, secured with multifactor authentication. In the background, it is also scanned whether passwords have been hacked.

Does this policy comply with information security legislation?

This policy complies with the GDPR and takes into account the requirements from NIS2, the Cyberbeveiligingswet (Cbw). This matters because you, as a client, may also get questions about this. In addition, work is being done towards ISO 27001 certification, a standard that aligns with those same NIS2 requirements.

How quickly can my password be hacked?

That depends on factors such as the computing power of the attacker and the length and predictability of the password. Short passwords can be cracked quickly with modern hardware, even with capital letters, numbers and special characters. Every extra character makes cracking exponentially harder, so a long unique passphrase with MFA offers the best protection.

Getting acquainted · which step suits your organisation?

You will be speaking with Ralph Dykstra

Founder and owner of B/Focused

A conversation of about 30 minutes in which we get to know your organisation and look at the challenges, risks and opportunities in your IT environment.

Advice or a quote? Sales
+31 45 303 0232
Need support? Service desk
+31 45 303 0003