---
title: Best Practice Password Security
description: Passwords have an important role to play in any organisation’s cyber security – whether to protect user access to applications, data or email.
image: https://blog.grantmcgregor.co.uk/hubfs/password-2781614_640.jpg
---

<https://grantmcgregor.co.uk/>

<https://grantmcgregor.co.uk/>[![Grant McGregor](https://blog.grantmcgregor.co.uk/hubfs/GRMC_blue_logo.svg "Grant McGregor")](https://www.grantmcgregor.co.uk/)

- [Home](https://grantmcgregor.co.uk/)
- About Us

    - [Our Story](https://grantmcgregor.co.uk/about-us/our-story)
    - [Meet the Team](https://grantmcgregor.co.uk/about-us/meet-the-team)
    - [Certifications](https://grantmcgregor.co.uk/about-us/certifications)
    - [Careers](https://grantmcgregor.co.uk/about-us/careers)
- IT Support Services

    - [IT Support Services](https://grantmcgregor.co.uk/it-support-services)
    - [People Centric Support](https://grantmcgregor.co.uk/it-support-services/people-centric-support)
    - [Enhanced Security Service](https://grantmcgregor.co.uk/it-support-services/enhanced-security-service)
- Professional IT Services

    - [Professional IT Services](https://grantmcgregor.co.uk/professional-it-services)
    - [Microsoft 365](https://grantmcgregor.co.uk/professional-it-services/microsoft-365-business-premium)
    - [Microsoft Copilot](https://grantmcgregor.co.uk/professional-it-services/microsoft-365-copilot)
    - [AI Adoption Services](https://grantmcgregor.co.uk/ai-adoption-services)
    - [Microsoft Azure](https://grantmcgregor.co.uk/professional-it-services/microsoft-azure)
    - [MDR](https://blog.grantmcgregor.co.uk/mdr-vs-soc-cyber-security-defence)
    - [Microsoft Teams Phone](https://grantmcgregor.co.uk/professional-it-services/microsoft-teams-phone)
    - [KnowBe4](https://grantmcgregor.co.uk/professional-it-services/knowbe4)
    - [DMARC](https://grantmcgregor.co.uk/professional-it-services/dmarc)
    - [Enclave Networks](https://grantmcgregor.co.uk/professional-it-services/enclave-networks)
- [Cyber Security](https://grantmcgregor.co.uk/cyber-security)
- Knowledge Hub

    - [Case Studies](https://grantmcgregor.co.uk/knowledge-hub/case-studies)
    - [Testimonials](https://grantmcgregor.co.uk/knowledge-hub/success-stories)
    - [Blog](https://grantmcgregor.co.uk/knowledge-hub/blog)
    - [Podcast](https://grantmcgregor.co.uk/knowledge-hub/podcast)
- [Client Area](https://grantmcgregor.co.uk/client-area)
- [Contact us](https://grantmcgregor.co.uk/contact-us)

- [Home](https://grantmcgregor.co.uk/)
- About Us

    - [Our Story](https://grantmcgregor.co.uk/about-us/our-story)
    - [Meet the Team](https://grantmcgregor.co.uk/about-us/meet-the-team)
    - [Certifications](https://grantmcgregor.co.uk/about-us/certifications)
    - [Careers](https://grantmcgregor.co.uk/about-us/careers)
- IT Support Services

    - [IT Support Services](https://grantmcgregor.co.uk/it-support-services)
    - [People Centric Support](https://grantmcgregor.co.uk/it-support-services/people-centric-support)
    - [Enhanced Security Service](https://grantmcgregor.co.uk/it-support-services/enhanced-security-service)
- Professional IT Services

    - [Professional IT Services](https://grantmcgregor.co.uk/professional-it-services)
    - [Microsoft 365](https://grantmcgregor.co.uk/professional-it-services/microsoft-365-business-premium)
    - [Microsoft Copilot](https://grantmcgregor.co.uk/professional-it-services/microsoft-365-copilot)
    - [AI Adoption Services](https://grantmcgregor.co.uk/ai-adoption-services)
    - [Microsoft Azure](https://grantmcgregor.co.uk/professional-it-services/microsoft-azure)
    - [MDR](https://blog.grantmcgregor.co.uk/mdr-vs-soc-cyber-security-defence)
    - [Microsoft Teams Phone](https://grantmcgregor.co.uk/professional-it-services/microsoft-teams-phone)
    - [KnowBe4](https://grantmcgregor.co.uk/professional-it-services/knowbe4)
    - [DMARC](https://grantmcgregor.co.uk/professional-it-services/dmarc)
    - [Enclave Networks](https://grantmcgregor.co.uk/professional-it-services/enclave-networks)
- [Cyber Security](https://grantmcgregor.co.uk/cyber-security)
- Knowledge Hub

    - [Case Studies](https://grantmcgregor.co.uk/knowledge-hub/case-studies)
    - [Testimonials](https://grantmcgregor.co.uk/knowledge-hub/success-stories)
    - [Blog](https://grantmcgregor.co.uk/knowledge-hub/blog)
    - [Podcast](https://grantmcgregor.co.uk/knowledge-hub/podcast)
- [Client Area](https://grantmcgregor.co.uk/client-area)
- [Contact us](https://grantmcgregor.co.uk/contact-us)

[Contact Us](https://grantmcgregor.co.uk/contact-us)

[Back to main](https://grantmcgregor.co.uk/knowledge-hub/blog)

Digital Transformation, Cyber Security

# Best Practice Password Security

Grant McGregor Team

 5 March 2018 • 5 min read

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.grantmcgregor.co.uk%2F2018%2Fbest-practice-password-security> <https://x.com/intent/tweet?url=https%3A%2F%2Fblog.grantmcgregor.co.uk%2F2018%2Fbest-practice-password-security&text=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EBest+Practice+Password+Security%3C%2Fspan%3E&via=yourusername> <https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.grantmcgregor.co.uk%2F2018%2Fbest-practice-password-security&title=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EBest+Practice+Password+Security%3C%2Fspan%3E>

![](https://blog.grantmcgregor.co.uk/hubfs/password-2781614_640.jpg)

# Passwords have an important role to play in any organisation’s cyber security – whether to protect user access to applications, data or email.

**So what should organisations be doing to ensure that the passwords and password policies being used are up to scratch? **

For many an organisation today, the data it holds counts among its most valuable assets. Yet this data must be available on a real-time basis for many applications and staff members to use. Add to this the increasing sophistication of phishing scams sent to senior executives from apparently internal email addresses and we can clearly see the need for good password security.

So, what are the current best practices around password security?

What are the processes and rules that your organisation needs to put in place to ensure that data, applications, user accounts and email accounts are not compromised by poor password practices?

### Choosing a Password

Helping users to understand what makes a good password has to be the starting point of any password strategy. Before you start implementing other policies you need to ensure the passwords are worth protecting in the first place.

The UK Government has launched new password advice on its cyber aware website. It warns against using passwords that are based on:

• Current partner’s name  
• Child’s name  
• Other family members’ names  
• Pet’s name  
• Place of birth  
• Favourite holiday  
• Something related to your favourite sports team

It suggests: “A good way to create a strong and memorable password is to use three random words. Numbers and symbols can still be used if needed, for example 3redhousemonkeys27!”.

This reflects the advice that was also published last year by the US Department of Commerce’s[National Institute of Standards & Technology (NIST)](https://pages.nist.gov/800-63-3/) . It suggested that organisations enforce longer password (suggesting up to 64 characters was desirable!).

### New Password Rules

Here, a password generation tool is going to aid most users – it’s the one of best ways to create incredibly strong passwords. However, it has to be admitted that 64-character passwords aren’t practical for most user logins, unless used in conjunction perhaps with [a password vault.](https://www.getsafeonline.org/protecting-yourself/passwords/) And some of NIST’s other advice is equally surprising, albeit a little more practical.

Its recommendations included:

• Removing all password complexity rules  
• Avoiding frequent mandatory password resets  
• Forbidding commonly used passwords  
• Limiting the number of password attempts  
• Swapping knowledge-based authentication for two-factor authentication

While “removing all password complexity rules” and “avoiding frequent mandatory resets” might seem contrary to existing advice, NIST argue that anything that makes it difficult for users to remember their passwords is counterproductive: leading to bad practice such as writing passwords down or oversimplifying them.

### User Education

Like so much in cybersecurity, good password practices must incorporate policies around user behaviour and user education. Don’t assume your users know what is good practice or not. Provide them with appropriate cyber security awareness training in which password management is covered as part of a broad range of topics. To some it seems like common sense but this is often not as ‘common’ as everyone imagines!

Last month, [we reported about the Hawaii emergency control room staff member](https://www.grantmcgregor.co.uk/2018/could-social-media-be-your-security-weak-spot/) caught on camera posing with a password on a post-it note stuck to the front of his computer monitor – thereby highlighting a few salutary lessons for us all.

The first rule of password security is that they shouldn’t be written down on paper - and certainly not stuck to the desk, computer or anywhere public.

And be very careful what you share on social media!

It is important that organisations put rules in place and ensure that all users understand and follow this advice.

### Two Factor Authentication

Multi-factor authentication is another important element of best practice. Last year [we highlighted the shift towards bio-metric identifiers](https://www.grantmcgregor.co.uk/2017/is-the-password-still-relevant-to-control-identity-and-access-to-your-it-systems-and-data/) and suggested this transition should be a question of “and” not “or”.

Ideally, you should require at least two out of three different identifiers: something you know, something you are, and something you have.

The password is, of course, the most common iteration of “something you know”. The “something you are” refers to a bio-metric element whilst “something you have” is usually a device (here NIST prefers SMS over email, because of the inherent vulnerabilities of email).

### Encryption and Hashing

And what of your organisational responsibilities when it comes to securing passwords?

GDPR is placing greater pressure on organisations to be able to demonstrate [how they protect the personal data](https://www.grantmcgregor.co.uk/2018/fed-up-of-hearing-about-gdpr/) they hold on staff, customers and other individuals. And not just from technological measures to protect data but appropriate organisational measures too!

Strong password policies have an important role to play in this. Perhaps the best way an organisation can demonstrate this is to give users access to an approved password generation tool and password manager or vault and to implement encryption and hashing of user passwords.

If you can demonstrate that you have taken steps to securely encrypt user passwords, not only can you prove to the regulator that you are taking your data security responsibilities seriously but, if a password database breach should happen in your organization, it should have a much more limited impact.

 

For more information about password best practice [please contact the Grant McGregor team](https://www.grantmcgregor.co.uk/contact-us/) or call us on 0131 603 7910.

We can also help with some of the other security topics touch on in this article, such as:

[GDPR Preparation & Organisational Measures](https://www.grantmcgregor.co.uk/gdpr-online-readiness-assessment-get-yourself-prepared-for-the-general-data-protection-regulation/)

[Cyber Essentials / Plus Certification](https://www.grantmcgregor.co.uk/it-software-and-solutions/cyber-essentials/)

[Cyber Security Awareness Training](https://www.grantmcgregor.co.uk/it-software-and-solutions/gm-cyber-aware/)

[Two Factor/Multi Factor Authentication](https://www.grantmcgregor.co.uk/double-up-on-your-it-security-with-our-fully-managed-2fa-2-factor-authentication-service/)

[Help with IT Security Services ](https://www.grantmcgregor.co.uk/it-software-and-solutions/)

Grant McGregor Team

 5 March 2018 • 5 min read

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.grantmcgregor.co.uk%2F2018%2Fbest-practice-password-security> <https://x.com/intent/tweet?url=https%3A%2F%2Fblog.grantmcgregor.co.uk%2F2018%2Fbest-practice-password-security&text=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EBest+Practice+Password+Security%3C%2Fspan%3E&via=yourusername> <https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.grantmcgregor.co.uk%2F2018%2Fbest-practice-password-security&title=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EBest+Practice+Password+Security%3C%2Fspan%3E>

## Recent Posts

![](https://blog.grantmcgregor.co.uk/hubfs/Shadow%20AI%20-%20Is%20Your%20Business%20Ready%20for%20AI%20Adoption.png)

### Shadow AI: Is Your Business Ready for AI Adoption?

 Understand shadow AI's impact on your business. Discover how to assess risks, improve processes, and adopt AI securely w...

[Read More](https://blog.grantmcgregor.co.uk/shadow-ai-is-your-business-ready-for-ai-adoption)

![Our Net Zero Target for 2040 - What Can We Change](https://blog.grantmcgregor.co.uk/hubfs/Our%20Net%20Zero%20Target%20for%202040%20-%20What%20Can%20We%20Change.png)

### Our Net Zero Target for 2040: What Can We Change?

 From company vehicles and travel to suppliers and technology, see how Grant McGregor is working towards its net zero tar...

[Read More](https://blog.grantmcgregor.co.uk/our-net-zero-target-for-2040-what-can-we-change)

![](https://blog.grantmcgregor.co.uk/hubfs/What%20Is%20Penetration%20Testing%3F%20A%20Guide%20for%20Businesses.png)

### What Is Penetration Testing? A Guide for Businesses

 Learn what penetration testing is, how it works, what the report should include and when your business should consider a...

[Read More](https://blog.grantmcgregor.co.uk/what-is-penetration-testing-a-guide-for-businesses)

![Grant McGregor named 2026 Top Managed Service Provider](https://blog.grantmcgregor.co.uk/hubfs/Social/MSP%20501%202026%20Winner.png)

### Grant McGregor Recognised as a Leading Global MSP in the 2026 MSP 501

 Grant McGregor has been named a Top Global Managed Service Provider in the 2026 MSP 501, ranking #1 Scotland-based MSP a...

[Read More](https://blog.grantmcgregor.co.uk/grant-mcgregor-recognised-as-a-leading-global-msp-in-the-2026-msp-501)

Union

## Empower your business with secure, expert-led solutions.

Talk to us about people-focused technology that drives results.

[Start a conversation](https://grantmcgregor.co.uk/contact-us)

![](https://blog.grantmcgregor.co.uk/hubfs/Woman%20in%20White%20longsleeve%20polo.png)

![Divider Footer](https://blog.grantmcgregor.co.uk/hubfs/footer.svg)

![GrantMcGeregor Logo White](https://blog.grantmcgregor.co.uk/hubfs/McGregor%20Theme%20Assets/GRMC_white_logo-cropped.svg "GrantMcGeregor Logo White")

Premium IT Services Tailored for Leading Brands

[Follow us on LinkedIn](https://www.linkedin.com/company/grant-mcgregor-ltd/) [Follow us on Facebook](https://www.youtube.com/itgrantmcgregor) [Follow us on Facebook](https://www.facebook.com/grantmcgregorltd/) [Follow us on Twitter](https://x.com/GrantMcGregorIT)

Quick Links

- [Home](https://grantmcgregor.co.uk)
- [About us](https://grantmcgregor.co.uk/about-us/our-story)
- [Knowledge Hub](https://grantmcgregor.co.uk/knowledge-hub/blog)
- [Contact us](https://grantmcgregor.co.uk/contact-us)

Services

- [People Centric Support](https://grantmcgregor.co.uk/it-support-services/people-centric-support)
- [Enhanced Security Service](https://grantmcgregor.co.uk/it-support-services/enhanced-security-service)
- [Professional IT Services](https://grantmcgregor.co.uk/professional-it-services)
- [Cyber Security](https://grantmcgregor.co.uk/cyber-security)

Edinburgh – Chesterfield

![Phone icon](https://blog.grantmcgregor.co.uk/hubfs/raw_assets/public/GrandMcGregor_climb/images/tel.png "Phone icon")

[0131 603 7910](tel:+441316037910)

![Email icon](https://blog.grantmcgregor.co.uk/hubfs/raw_assets/public/GrandMcGregor_climb/images/mail.png "Email icon")

[info@grantmcgregor.co.uk](mailto:info@grantmcgregor.co.uk)

![Location icon](https://blog.grantmcgregor.co.uk/hubfs/raw_assets/public/GrandMcGregor_climb/images/loc.png "Location icon")

**Main Office:**   
The Merchants' Hall,  
22 Hanover St,  
Edinburgh EH2 2EP

 © 2026

Grant McGregor. All rights reserved.

[Privacy and Cookie Policy](https://blog.grantmcgregor.co.uk/hubfs/UsefulDownloads/Policies/GRMC-SEC-Privacy-and-Cookie-Policy.pdf)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Grant McGregor Team",
    "url" : "https://blog.grantmcgregor.co.uk/author/grmc-team"
  },
  "dateModified" : "2022-04-06T06:50:27.374Z",
  "datePublished" : "2018-03-05T07:30:53.000Z",
  "headline" : "Best Practice Password Security",
  "image" : [ "https://blog.grantmcgregor.co.uk/hubfs/password-2781614_640.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.grantmcgregor.co.uk/2018/best-practice-password-security",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.grantmcgregor.co.uk/hubfs/GRMC_blue_logo.svg"
    },
    "name" : "Grant McGregor"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://grantmcgregor.co.uk/",
  "@type" : "LocalBusiness",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "GB",
    "addressLocality" : "Edinburgh",
    "postalCode" : "EH2 2EP",
    "streetAddress" : "22 Hanover Street"
  },
  "geo" : {
    "@type" : "GeoCoordinates",
    "latitude" : 55.9526313,
    "longitude" : -3.1970679
  },
  "image" : "https://grantmcgregor.co.uk/hubfs/GRMC_blue_logo.svg",
  "name" : "Grant McGregor",
  "openingHoursSpecification" : {
    "@type" : "OpeningHoursSpecification",
    "closes" : "18:00",
    "dayOfWeek" : [ "Monday", "Tuesday", "Wednesday", "Thursday", "Friday" ],
    "opens" : "08:00"
  },
  "sameAs" : [ "https://www.facebook.com/grantmcgregorltd/", "https://x.com/GrantMcGregorIT", "https://www.youtube.com/itgrantmcgregor", "https://www.linkedin.com/company/grant-mcgregor-ltd/" ],
  "telephone" : "+441316037910",
  "url" : "https://grantmcgregor.co.uk/"
}
```