Staff Are the Attack Surface
Most institutional breaches don't start with sophisticated hacking. They start with a government employee using the same password they use for their personal email — or a password that takes three seconds to guess. Attackers know this. They target staff accounts specifically because it's the path of least resistance into a network that would otherwise be difficult to breach.
What Makes an Institutional Password Policy Work
A password policy only works if staff actually follow it. That means: minimum 14 characters for all institutional accounts, no reuse across systems, mandatory change when any breach is suspected, and a password manager provided and maintained by the institution — not a personal one. If staff have to remember strong unique passwords without a tool, they won't.
Privileged Accounts Need Special Treatment
Administrators, database users, and anyone with elevated access to institutional systems represent the highest-risk accounts. These should have longer passwords (20+ characters), be stored in a privileged access management system, never be used for day-to-day tasks, and require approval logging for each use. A compromised admin account is a full institution compromise.
Multi-Factor Authentication Is Non-Negotiable
Even strong passwords can be phished. Multi-factor authentication (MFA) — requiring a second verification step like a phone app code — stops most credential-based attacks cold. MFA should be mandatory for all institutional email, VPN access, administrative systems, and any external-facing service. There is no reasonable argument against it.
