Information security

Password Policy

v1.0
Reviewed Jun 2026 · next review Jun 2027

HALVED LIMITED

PASSWORD POLICY

Version: 1.0 Effective Date: 4th June 2026 Last Review: 4th June 2026 Next Review: 4th June 2027

Owner: Andrew James, CEO

1. PURPOSE

This policy defines password requirements for all Halved Limited systems to protect against unauthorised access and meet Cyber Essentials requirements.

2. SCOPE

This policy applies to all passwords used to access:

3. PASSWORD REQUIREMENTS

3.1 Minimum Password Standards

All passwords must meet the following minimum requirements:

3.2 Multi-Factor Authentication (MFA)

3.3 Password Management Requirement

All users must:

3.4 Admin Account Passwords

Administrative accounts require additional security:

Minimum length: 12 characters (must be different from standard account passwords)

MFA: Mandatory on all admin accounts

Uniqueness: Admin account passwords must be completely different from standard account passwords

4. PASSWORD CREATION GUIDANCE

4.1 Creating Strong Passwords

Good approaches:

Avoid:

4.2 Password Expiry

5. COMPROMISED PASSWORDS

If you suspect your password has been compromised:

6. NEW USER ONBOARDING

When a new team member joins:

7. COMPLIANCE

Failure to comply with this policy may result in:

8. TRAINING

All users receive password security training:

APPROVED BY:

Andrew James, CEO Halved Limited Date: 4th June 2026