- Job title
- Courier coordinator
- Sector
- Real estate
- Organization type
- chain store
- Joined
- Dec 2025
- Message
- 86
Consultant said 'passwords should be changed every 3 months'.
IT says 'that's old, 180 days is recommended'.
Is it really necessary?
Consultant said 'passwords should be changed every 3 months'.
IT says 'that's old, 180 days is recommended'.
Is it really necessary?
Don't miss this: If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.
It's rare to find an explanation this clear. If permission and scope aren't in writing, don't start that test.
Most time waste accumulates in tasks waiting for approval. If you have questions, write them; I'll answer as best I can.
I don't think this advice fits everyone. Most incidents start with a leaked password, not a vulnerability.
Don't rely on a single measure; go layer by layer.
You're right. When making decisions, write down the worst-case scenario too, not just the best.
Correct me if I'm wrong.
Same here. Don't rely on a single measure; go layer by layer.
If you have questions, write them; I'll answer as best I can.
Doki · Penetration test · 2025
We experienced almost the exact same thing last year. If you get three different answers on a topic, the question was asked wrong.
An automated scan report is not the same as a penetration test. Good luck with that.
Let me share my experience. Everything goes well for the first three months; problems arise in the fourth.
If 2FA is on, a stolen password alone is useless. Hope this helps.
This approach has a cost, which isn't discussed. Mistakes made on the password policy side are usually reversible but expensive.
Of course, it varies if your situation is different.
Let me share my experience. Processes without records never improve, because you don't know what to fix.
This is my opinion, I'm not claiming it's absolute truth.
We got stuck at the same point for a while. Taking notes for two weeks yields better results than a six-month estimate.
Proven by experience.
We got stuck at the same point for a while. If you get three different answers on a topic, the question was asked wrong.
If you get three different answers on a topic, the question was asked wrong... btw correct me if Im wrong.
Here's how it went for us. If permission and scope aren't in writing, don't start that test.
Proven by experience.
Sorry, but this doesn't apply in every case. Taking measures without an inventory leaves doors you haven't seen open.
Just because everyone does it doesn't mean it's right.
Doki · SEO consulting · 2023
Let me summarize the topic, since several different answers were given. Everything goes well for the first three months; problems arise in the fourth.
If 2FA is on, a stolen password alone is useless. If I were you, I'd go this route.