We used to do monthly laps password rotations, but switched to "on-demand" after realizing most breaches weren’t from stale passwords.
Now, we only rotate if there’s a suspicion of compromise or after an employee leaves.
Controversial? Maybe. But it’s worked for us so far.
Now, we only rotate if there’s a suspicion of compromise or after an employee leaves.
Controversial? Maybe. But it’s worked for us so far.
