• FREE RESOURCES
        • Accounts Payable
          Finally! The trick to securing greater T&E compliance
          Benefits
          Rooting out folks who don’t belong on your health plan: A 6-point dependent audit checklist
          IT
          3 costly misconceptions about biz email compromise
          Credit and Collections
          Collecting via email: 4 must-make moves in your subject line
          Accounts Payable
          5 Tough-to-spot signs that an invoice is fake
  • PREMIUM CONTENT
        • Staff management
          120 Proven Communications Tips for Today’s CFO
        • Payroll
          Handling Nonexempt Employee Pay: Stay Compliant and Avoid DOL Audits
          Accounts Payable
          T&E Best Practices: Complete Guide to Ensure Compliance
          Payroll
          Payroll Best Practices: 4 Ways to Save Time and Money
        • Staff management
          Email Best Practices: A 6-Question Quiz
          Staff management
          Innovative Communications Strategies: An Email Case Study
          Staff management
          A 5-part Framework for Successful Workplace Communications
        • SEE MORE
          PREMIUM RESOURCES
  • CORONAVIRUS RESOURCES
  • LOG IN
  • SIGN UP FOR FREE

Resourceful Finance Pro

  • FREE RESOURCES
        • Accounts Payable
          Finally! The trick to securing greater T&E compliance
          Benefits
          Rooting out folks who don’t belong on your health plan: A 6-point dependent audit checklist
          IT
          3 costly misconceptions about biz email compromise
          Credit and Collections
          Collecting via email: 4 must-make moves in your subject line
          Accounts Payable
          5 Tough-to-spot signs that an invoice is fake
  • PREMIUM CONTENT
        • Staff management
          120 Proven Communications Tips for Today’s CFO
        • Payroll
          Handling Nonexempt Employee Pay: Stay Compliant and Avoid DOL Audits
          Accounts Payable
          T&E Best Practices: Complete Guide to Ensure Compliance
          Payroll
          Payroll Best Practices: 4 Ways to Save Time and Money
        • Staff management
          Email Best Practices: A 6-Question Quiz
          Staff management
          Innovative Communications Strategies: An Email Case Study
          Staff management
          A 5-part Framework for Successful Workplace Communications
        • SEE MORE
          PREMIUM RESOURCES
  • CORONAVIRUS RESOURCES
  • Accounts Payable
  • Credit and Collections
  • Payroll
  • Accounting
  • Benefits
  • Finance Technology
  • Sales & Use Tax
  • More
    • Employment Law
    • Strategy
    • Policy and Culture
    • Fraud
    • Budgeting and Forecasting
    • Banking
    • Staff Management
    • Cost Control
  • Fraud
  • Policy and culture
2 minute read

Passphrases secure, but hard to remember: Should they be your password policy?

Brian Bingaman
by Brian Bingaman
February 3, 2023
  • SHARE ON

Cybercriminals who are out to steal your company’s money are getting smarter. Even a password that uses a capital letter, at least one number and a special character can be cracked by hackers because people tend to use the same 32 keyboard characters.

One school of thought on better password security is using simple, long passphrases that are 25 characters or more, such as “I like to go to the beach to get wet.”

But while that might make it more difficult for crooks, it increases the risk that people will reuse the same passphrase across different sites, setting up the possibility of a larger scale attack.

Also, many sites truncate a passphrase because the maximum character length they’ll accept is less than 25.

Passphrase alternatives to try

For a better approach to security, ask IT’s opinion on using passwords that:

  1. are four random common words that can be remembered in a humorous mental picture, such as “horse battery staple correct”
  2. use “leetspeak” letter substitutions in words: one instead of lowercase L, zero for the letter O, the dollar sign instead of S, three in place of E and the “at” symbol replacing A. So the passphrase in the previous example would look like “h0r$3 b@tt3ry $t@pl3 c0rr3ct,” or
  3. have a word intentionally misspelled to throw hackers off.

Managing login credentials with a password manager that creates and remembers unique, long, random passwords for each security domain can also be valuable. Examples include 1Password, LastPass and KeePass (which is free).

In addition, using multi-factor authentication wherever possible, especially when using cloud-based apps or sites, is sound cybersecurity strategy.

How Not to Wreck Your Reconciliations

Evaluating your authentication needs

Because anyone with a developer license can make a multi-factor authentication app, there are a lot of them out there.

If you haven’t yet chosen one for your organization, when you’re researching, get IT’s feedback on an app’s:

  • Platform compatibility: Do you need it to work on both Android and iOS, or both Windows and Mac?
  • Usability: How easy is it to add new accounts, find existing accounts and delete unneeded accounts?
  • Ease of account recovery: Does it offer multiple ways to recover an account (e.g., support line, device backup, etc.)?
  • App security: Do you want another layer of security, such as a PIN or biometric locks like face ID or a fingerprint scan?
Brian Bingaman
Brian Bingaman
Brian researches and writes about accounts payable and CFO management trends. He was a newspaper journalist in suburban Philadelphia for nearly 20 years.

Get the

Resourceful Finance Pro Logo

Newsletter

With Resourceful Finance Pro arriving in your inbox, you will never miss critical stories on accounting, benefits, payroll & employment law strategies.

  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • Hidden
  • This field is for validation purposes and should be left unchanged.
Resourceful Finance Pro Logo
  • ABOUT
  • CONTACT
  • WRITE FOR US
  • ADVERTISE WITH US
  • Accounting
  • Benefits
  • Payroll
  • Policy and Culture
  • Employment Law
  • Fraud
  • Finance Technology
  • Sales & Use Tax
  • Accounts Payable
  • Credit and Collections
  • Strategy
  • Budgeting and Forecasting
  • Banking
  • Staff Management
  • Cost Control

Resourceful Finance Pro, part of the SuccessFuel Network, provides the latest Finance and employment law news for Finance professionals in the trenches of small-to-medium-sized businesses. Rather than simply regurgitating the day's headlines, Resourceful Finance Pro delivers actionable insights, helping Finance execs understand what Finance trends mean to their business.

Privacy Policy | Terms of Service
Copyright © 2023 SuccessFuel

WELCOME BACK!

Enter your username and password below to log in

Forget Your Username or Password?

Reset Password

Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.

Log In

During your free trial, you can cancel at any time with a single click on your “Account” page.  It’s that easy.

preloader