---
title: Why Password Policies Aren’t Enough
description: Security is often a trade-off. The greater the protection, the more inconvenience to the user. The lesser the protection, the less inconvenience to a user.
image: https://europe.sifytechnologies.com/hubfs/Information%20Security%20Card%20Handmade%20from%20Paper%20Characters%20on%20Blue%20Background.%203D%20Render.%20Business%20Concept..jpeg
---

[![Sify Logo](https://europe.sifytechnologies.com/hs-fs/hubfs/logo.webp?width=107&height=52&name=logo.webp "Sify Logo")](https://europe.sifytechnologies.com/)

Open main menu Close main menu

- Services
- [Resources](https://europe.sifytechnologies.com/blog)

[Cloud](https://europe.sifytechnologies.com/blog/tag/cloud)

# Why Password Policies Aren’t Enough

[James Ridgway](https://europe.sifytechnologies.com/blog/author/james-ridgway)

[Share this blog post on Twitter](https://twitter.com/intent/tweet?text=I+found+this+interesting+blog+post&url=https://europe.sifytechnologies.com/blog/why-password-policies-arent-enough) [Share this blog post on Facebook](http://www.facebook.com/share.php?u=https://europe.sifytechnologies.com/blog/why-password-policies-arent-enough) [Share this blog post on LinkedIn](http://www.linkedin.com/shareArticle?mini=true&url=https://europe.sifytechnologies.com/blog/why-password-policies-arent-enough)

![](https://europe.sifytechnologies.com/hubfs/Information%20Security%20Card%20Handmade%20from%20Paper%20Characters%20on%20Blue%20Background.%203D%20Render.%20Business%20Concept..jpeg)

We’ve all been there. We’ve had to set a password in a system and we’ve been told it’s not strong enough. Or we finally set a strong password only to be told 30 days later that we need to change our password. Password policies are not enough to encourage good security behaviour.

A password policy enforces a set of rules for what a password should contain or how long it can be valid.  

A typical password policy might look like this:

- At least 1 lowercase character
- At least 1 uppercase character
- At least 1 numeric character
- At least 1 special character
- Minimum length of 8 characters
- Password expires after 30 days
- Your last 12 passwords must be unique

 

For years the [National Institute of Standards and Technology (NIST)](https://www.nist.gov/) have long advocated against password expiry and discouraged the use of over-complicated password rules.

 

## Why don’t password policies work?

Security is often a trade-off. The greater the protection, the more inconvenience caused to the user. The lesser the protection, the less inconvenience to a user.

![](https://thecurve.io/wp-content/uploads/2021/02/security-spectrum-tradeoff.png)

Let’s take a look at a few simple examples of security in the physical world:

1. If you lock your car with the key fob, you get a level of security, and the convenience is fairly good.
2. If you lock your car with the key fob and use a steering wheel lock, the security afforded is greater than in (1), but locking and unlocking your car is more inconvenient.
3. If you lock your car with the key fob, use a steering wheel lock, and a wheel clamp, the security afforded is greater than in (1) and (2). Similarly, the inconvenience of locking and unlocking your car is even greater than in (1) and (2).

I

In an ideal world, security should be just enough to discourage an attack, but minimal enough not to cause unnecessary inconvenience to legitimate users. 

The key problem with password policies is that they educate you on what you should do. How you achieve this is often left up to you to figure out. A typical password policy is designed to ensure a high level of complexity for passwords. This is an inconvenience for end users who have to try and remember long and complex strings of characters that they will probably have to change in a number of days anyway when the policy enforces that the password expires. 

How many times have you been required to put a special character into a password and you just reach for the exclamation mark (!) because it’s the easiest to remember. How many times have you had a password expire, only to change it to the same password with a different number at the end?

 

## Is there a better solution?

The best way to keep your team and systems secure is to provide them with:

- Education, awareness and training on security topics
- Tools to assist in staying secure

 

Using a tool such as [1Password](https://1password.com/)means that your team can generate a complex, secure and unique password for every account that they have. With apps for Android and iOS, and plugins for all the popular web browsers, inputting a password from 1Password can be much more convenient than having to remember the credentials you used for a given system.

 

## Conclusion

Password policies can still be a good security measure, but they should be considerate of the fact that an aggressive password policy may cause users to adopt bad practices (such as writing down a password or simply incrementing a number) to circumvent the inconveniences of the policy.

 

*This article originally appeared on The Curve's* [blog](https://thecurve.io/why-password-policies-arent-enough/). The Curve Consulting are on-demand technical experts and a trusted partner of Sify. To learn more about The Curve, please visit their [website](https://thecurve.io/).

#### James Ridgway

James is a Director of The Curve, an experienced Software Engineer and Leader of Engineering Teams. Since graduating with a First Class Honours Masters degree in Software Engineering from The University of Sheffield James has worked across numerous technology stacks from Android development and web development through to data science analytics and building distributed platforms of microservices. His approach to engineering is quality focused, with an emphasis on consistency, best practice and technical excellence. Experienced in technical leadership James has transformed poor-performing, high-attrition teams to delivering regularly and consistently. In transforming teams, James has re-built team cultures, instilled best practices, embedded continuous improvement processes and enabled individuals and teams to reach their potential.

### Leave a Comment

## Related Articles

[![](https://europe.sifytechnologies.com/hubfs/More!%20More!%20More!%20card%20isolated%20on%20white%20background.jpeg)](https://europe.sifytechnologies.com/blog/maximising-productivity-doing-more-with-less)

[Cloud](https://europe.sifytechnologies.com/blog/tag/cloud) [Managed Services](https://europe.sifytechnologies.com/blog/tag/managed-services)

### [Maximising Productivity: Doing More with Less](https://europe.sifytechnologies.com/blog/maximising-productivity-doing-more-with-less)

As all senior IT people will understand, running a successful business with diminishing resources and budget, or as it's better known being asked to “do more with less”,...

![Justin Polley](https://europe.sifytechnologies.com/hs-fs/hubfs/justin-150x150.jpg?width=45&name=justin-150x150.jpg) 

[Justin Polley](https://europe.sifytechnologies.com/blog/author/justin-polley) 

[Read More](https://europe.sifytechnologies.com/blog/maximising-productivity-doing-more-with-less)

[![](https://europe.sifytechnologies.com/hubfs/Image%20of%20human%20hands%20holding%20plant%20shaped%20like%20arrow.jpeg)](https://europe.sifytechnologies.com/blog/bridging-the-gap-between-applications-and-their-cloud-environments)

[Cloud](https://europe.sifytechnologies.com/blog/tag/cloud)

### [Bridging the Gap Between Applications and Their Cloud Environments](https://europe.sifytechnologies.com/blog/bridging-the-gap-between-applications-and-their-cloud-environments)

As the need for organisations to move faster and become more flexible to meet the demands of their customers, IT teams need to be agile to innovate, launch new products,...

[Tony Dolan](https://europe.sifytechnologies.com/blog/author/tony-dolan) 

[Read More](https://europe.sifytechnologies.com/blog/bridging-the-gap-between-applications-and-their-cloud-environments)

#### About Sify 

Sify is an IT and Digital Services company that was formed in 1995 and Nasdaq listed since 1999. We help over ten thousand clients and partners improve business operational efficiency and deliver excellence on the Indian subcontinent and globally. Headquartered in India, Sify is widely respected as a Fortune India 500 company accredited as an IT service provider, system integrator and all-in-one network solutions company.  

#### Explore us more

[About Us](https://europe.sifytechnologies.com/about)

#### Connect with us

E: [sify.europe@sifycorp.com ](mailto:sify.europe@sifycorp.com)  
T: +44 (0)20 3862 9734

[Follow us on LinkedIn](https://www.linkedin.com/company/67080748/) [Follow us on Twitter](https://twitter.com/SifyEurope) [Follow us on Facebook](https://www.youtube.com/channel/UCAXND-9LS6urvx1s5sqHtdA)

Copyright © 2023 Sify Technologies Limited. All Rights Reserved.