Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Password Best Practices – I know, AGAIN!

By Sean Lawless on July 9, 2015
Email this postTweet this postLike this postShare this post on LinkedIn

With the uptick in high profile security breaches like the Office of Personnel Management, Target, JPMorgan and others, it is easy to become desensitized to the constant risk our cyber lives pose both personally and professionally. Information Technology departments have been rallying the battle cry about the necessity of using strong, complex passwords for decades now, to the point where discussing password best practices has become cliché. However, weak password practices continue to be one of the largest threats to both individual’s and business’ cybersecurity.

According to Verizon’s 2015 Data Breach Investigation Report, credential hacking is still the most common threat action. When you consider the number of devices, websites and systems you have a password to it is not hard to appreciate the need for good password practices. Outlined below are the Dos and Don’ts to creating and maintaining strong, complex passwords, all commonly considered best practices by security experts.

Do:

  • Create passwords that are a minimum of 10 characters long, preferably longer
  • Use mixed case, alpha numeric AND special characters (#, !, @)
  • Create a unique password for every device, website and/or system that requires authentication
  • Choose multi-factor authentication whenever possible
  • Change your passwords often, preferably every 60-90 days
  • Use a password checker like Microsoft’s 

Don’t:

  • Use dictionary words or sequential numbers (i.e. password or 123456)
  • Use proper names in your password
  • Choose to allow a website, system or web browser to ‘remember you, save your password, etc.’
  • Reuse your passwords
  • Write your passwords down anywhere

Example:

To create complex, unique, strong passwords that are easy to remember use a pass phrase and inject an identifier that is website or system specific.

mutatis mutandis becomes mU+@+15mU+@nd15

This is certainly a complex password. Now add the unique identifier.   If this password was to be used for an email account you might use mU+@+15emailmU+@nd15. If for a shopping website you might use mU+@+15sitenamemU+@nd15 and so on.

Photo of Sean Lawless Sean Lawless

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries…

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries, develop and implement practical information security programs based on industry standard frameworks. Sean holds a Bachelor of Science degree from the University of Connecticut and is a member of several cybersecurity professional organizations.

Read more about Sean LawlessEmail
Show more Show less
  • Posted in:
    Other
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo