Globya Information Technologies · Since 2000 0850 432 55 13 info@globya.com.tr
SearchCtrl K Start a project

Data Protection and Security

Not complex passwords, but long passwords and a second step

Mandatory changes every three months and forced uppercase, digits and symbols are no longer the recommended approach. We explain a workable password policy and two-factor authentication in plain language.

A password policy is the set of rules defining how passwords for a company's accounts are chosen, stored and protected. 2FA (two-factor authentication) is a sign-in method that asks for a second proof after the password. Many companies' written or unwritten password rules still look like this: at least eight characters, an uppercase letter, a digit, a special character and a mandatory change every three months. The result is predictable: "Company2026!" becomes "Company2026?", and a sticky note goes up on the edge of the screen. In this article we explain the approach recommended today and where to start with 2FA.

Current guidance — length matters more than complexity

The digital identity guideline (SP 800-63B) of the US National Institute of Standards and Technology (NIST) changed several long-established habits around passwords. The guideline's general approach can be summarized like this:

  • Prioritize length. A long passphrase made of several words is both stronger and easier to remember than a short, complex password.
  • Don't impose mandatory character rules. An "at least one symbol" rule produces predictable patterns.
  • Drop periodic forced changes. A password should be changed only when there's a sign it has been compromised.
  • Block breached passwords. New passwords should be checked against lists of passwords exposed in previous data breaches.
  • Allow pasting. Don't make it harder to use a password manager.

The logic behind this change is simple: rules that burden people push them toward passwords that are weak but technically compliant.

A password manager — a separate password for every account

The most important item in a password policy is actually this: the same password is never used in two places. A password leaked from a forum also unlocks the corporate account opened with the same email address. The human brain can't hold dozens of different passwords, so a business password manager is the only realistic solution.

In a business password manager, shared accounts (social media, the domain panel, banking screens) are kept in shared vaults, and you can see who has access to which password. When an employee leaves, access is revoked from one place. Passwords don't circulate by email, WhatsApp or a shared Excel file.

What is 2FA, and which type should you prefer?

Two-factor authentication prevents access to an account even if the password is stolen, because the attacker also has to pass the second step. The types are not equal in terms of security:

MethodHow it worksAssessment
SMS codeA one-time code sent to the phoneBetter than nothing; vulnerable to SIM swapping and phishing
Authenticator appA time-based code generated by an app on the phoneA good balance for most companies
App approval (push)A "confirm if this is you" notification on the phoneConvenient; risk of careless approval of repeated requests
Security key / passkeyA physical key or a digital key bound to the deviceThe most phishing-resistant method

A passkey (a passwordless sign-in key) is the strongest option against phishing because it technically prevents credentials from being entered on a fake site, and it's supported by more and more services.

Where to start? Order of priority

Setting up 2FA on everything at once is hard. Rank by the size of the risk:

  1. Email accounts. Password reset links go to email; whoever takes over the email can take over other accounts too. Business email should be your priority.
  2. The domain and DNS panel. If compromised, your site and email can be redirected elsewhere.
  3. Admin panels. Website admin, e-commerce panel and dealer portal administrator accounts.
  4. Cloud storage and accounting/ERP access.
  5. Social media and advertising accounts.

The software you use must also store passwords correctly

A password policy also has an invisible side: how your website and software store user passwords. Passwords should never be kept in the database as plain text or in a reversible form; they should be stored using slow hashing methods designed for this purpose (such as bcrypt or Argon2). Repeated failed login attempts should also be limited, and "forgot my password" links should be short-lived and single-use. From the perspective of the data security obligation under KVKK (Türkiye's Personal Data Protection Law), these technical details are as important as your written policy.

A short password policy draft

  • Passwords are at least 12 characters; passphrases are recommended
  • Passwords that appear on breached password lists are not accepted
  • A separate password for every account; a business password manager is used
  • No mandatory periodic changes; immediate change when a breach is suspected
  • 2FA is mandatory for email, domain, admin panels and finance screens
  • Administrator accounts are not used for day-to-day work
  • All access is revoked on the day an employee leaves, and shared passwords are changed
  • Passwords are not shared by email or messaging apps

How we do it at Globya

On the websites, portals and software we build, we store passwords with current hashing methods, limit failed login attempts and turn on two-factor authentication for administrator accounts by default. We also help companies set up a short, workable password and 2FA routine for their own accounts. In line with our KVKK compliance approach, these requirements are never left out of our projects and there is no extra charge.

Frequently asked questions

Doesn't dropping mandatory password changes reduce security?

Dropping them on its own might; but when combined with long passwords, breached password checks and 2FA, overall security goes up. Mandatory changes push people toward small, predictable tweaks.

Our employees don't want to install an app on their phones. What can we do?

A physical security key is a good alternative. SMS codes can be used during the transition, but we don't recommend them as a permanent solution for critical accounts.

How does an employee who loses their phone get into their account?

When 2FA is set up, one-time recovery codes are generated and stored in a safe place. There should also be a defined process through which an administrator can reset the account.

Can you review the state of our existing accounts?

Yes. Reach us at +90 850 432 55 13 or through the contact page, and we'll prepare a priority list starting with your critical accounts.

Anything on your mind about this article?

The Globya assistant is online 24/7; it answers right away and passes your question to the team if needed.

Ask the assistant

The next project could be yours

Let us run your digital work from a single point.

Let us hear your needs in a short phone call and prepare a free preliminary analysis report for your website.