forumNew topic

We made it mandatory to change passwords every 3 months, employees are complaining

SSena Ş***4 days ago·30 messages·3.5K views#password#policy
SSena Ş***Veteran
Job title
Courier coordinator
Sector
Real estate
Organization type
chain store
Joined
Dec 2025
Message
86
#1

Consultant said 'passwords should be changed every 3 months'.

IT says 'that's old, 180 days is recommended'.

Is it really necessary?

RRecep A***Member
Job title
QA Tester
Sector
Retail
Organization type
a company within a holding
Joined
Jul 2025
Message
241
Most Helpful#2

NIST: regular changes are ineffective. Strong password + 2FA is better.

HHüsniye Ç***MemberCommunity member
Joined
Oct 2024
Message
17
#3

we did it every 3 months operations manager complained so we pushhed it to 180

AAhmet H***Member
Job title
System Support
Organization type
sole proprietorship
Joined
May 2024
Message
88
#4

Don't miss this: If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

MMehmet A***Expert
Job title
Software developer
Sector
Education
Organization type
300-person organization
Joined
Jul 2022
Message
2
#5

It's rare to find an explanation this clear. If permission and scope aren't in writing, don't start that test.

Most time waste accumulates in tasks waiting for approval. If you have questions, write them; I'll answer as best I can.

AAli G***Member
Job title
Logistics planning
Sector
Electrical-electronics
Organization type
family business
Joined
Jul 2023
Message
1
#6

I don't think this advice fits everyone. Most incidents start with a leaked password, not a vulnerability.

Don't rely on a single measure; go layer by layer.

HHilal B***ExpertCommunity member
Joined
Feb 2026
Message
66
#7

You're right. When making decisions, write down the worst-case scenario too, not just the best.

Correct me if I'm wrong.

DDamla A***MemberCommunity member
Joined
Jul 2025
Message
179
#8

Same here. Don't rely on a single measure; go layer by layer.

If you have questions, write them; I'll answer as best I can.

SSena A***Member
Job title
Secretary
Sector
Leather
Organization type
cooperative
Joined
Apr 2022
Message
3

Doki · Penetration test · 2025

#9

Correct.

FFerhat Ö***MemberCommunity member
Joined
Sep 2022
Message
290
#10

We experienced almost the exact same thing last year. If you get three different answers on a topic, the question was asked wrong.

An automated scan report is not the same as a penetration test. Good luck with that.

PPınar B***Member
Job title
Technical service technician
Sector
Packaging
Organization type
a company within a holding
Joined
Jul 2025
Message
263
#11

Let me share my experience. Everything goes well for the first three months; problems arise in the fourth.

If 2FA is on, a stolen password alone is useless. Hope this helps.

MMustafa A***MemberCommunity member
Joined
Nov 2024
Message
14
#12

Thanks for posting.

EElif P***New member
Job title
Quality control inspector
Sector
Energy
Organization type
a company within a holding
Joined
Jul 2026
Message
130
#13

This approach has a cost, which isn't discussed. Mistakes made on the password policy side are usually reversible but expensive.

Of course, it varies if your situation is different.

AAli Y***MemberCommunity member
Joined
Mar 2025
Message
157
#14

i agree.

PPerihan M***MemberCommunity member
Joined
Apr 2024
Message
83
#15

Let me share my experience. Processes without records never improve, because you don't know what to fix.

This is my opinion, I'm not claiming it's absolute truth.

EErcan D***Member
Job title
Administrative manager
Sector
Software
Organization type
two-branch business
Joined
Jul 2022
Message
419
#16

We got stuck at the same point for a while. Taking notes for two weeks yields better results than a six-month estimate.

Proven by experience.

DDilara Y***Veteran
Job title
Human Resources Manager
Sector
Real estate
Organization type
8-person team
Joined
Oct 2024
Message
98
#17

We got stuck at the same point for a while. If you get three different answers on a topic, the question was asked wrong.

If you get three different answers on a topic, the question was asked wrong... btw correct me if Im wrong.

UUğur Ö***Member
Job title
Warehouse Manager
Sector
Education
Organization type
family business
Joined
Jan 2023
Message
1
#18

Here's how it went for us. If permission and scope aren't in writing, don't start that test.

Proven by experience.

EEmre G***ExpertCommunity member
Joined
Jul 2024
Message
409
#19

Sorry, but this doesn't apply in every case. Taking measures without an inventory leaves doors you haven't seen open.

Just because everyone does it doesn't mean it's right.

PPolat G***Member
Job title
Graphic Designer
Sector
Law
Organization type
workshop
Joined
Nov 2023
Message
29

Doki · SEO consulting · 2023

#20

Let me summarize the topic, since several different answers were given. Everything goes well for the first three months; problems arise in the fourth.

If 2FA is on, a stolen password alone is useless. If I were you, I'd go this route.

Reply