Skip to content

Two-step verification vs. two-factor authentication

What is two-factor authentication (2FA)?

Two-factor authentication (2FA) is a security procedure that adds an extra layer of security to your logins. Rather than relying on a single piece of authentication data—such as a password —2FA requires two separate factors to confirm that you are who you claim to be. It’s a process that can significantly reduce the risk of unauthorized access, even if bad actors are able to get their hands on your username and password. The factors fall into 3 broad categories:

  1. Knowledge: Something only you know, such as a password, PIN, or an answer to a secret question.

  2. Possession: Something only you have, like your smartphone, a secure USB drive, etc.

  3. Inherence (biometric): Something you are—typically a fingerprint, facial recognition, or an iris scan.

Here’s how 2FA works in practice: say you’re trying to access an online dashboard that contains sensitive data. First, you enter your username and password (in 2FA, referred to as the knowledge factor). Then, you receive a push notification on your smart device (in 2FA, referred to as the possession factor), which you must tap to confirm your identity. Without both factors, access is denied.

Note that 2FA is a subset of a broader category known as multi-factor authentication (MFA). If you want to have a better understanding of MFA in general, check out our dedicated post on What is multi-factor authentication.

 

Advantages of 2FA

Improved security

By requiring two different factor types, 2FA drastically reduces the odds of a successful breach. Even if a hacker manages to guess or steal your password, they would still need your physical device or biometric data.

 

Coming closer to compliance

In many industries, such as finance, healthcare, or e-commerce, data protection standards and regulations either recommend or mandate 2FA.

 

Limitations of 2FA

Device reliance

In most instances, the second factor is tied to a mobile device. If a user loses or can’t access their phone or tablet, they might have to face major delays and stay locked out.

 

Potential cost or complexity

Rolling out 2FA for large companies might require purchasing physical keys or training employees to use authenticators, which could temporarily add complexity to their daily process.

 

Examples of 2FA

Password and a hardware security key

You type in your password, then insert a dedicated device like a YubiKey to finalize the login. Because the key is a physical object, attackers can’t replicate or hack it remotely.

 

Fingerprint and a passcode

The authentication process can be set up in such a way that when you unlock a smartphone app, you can scan your fingerprint (biometric factor) and also enter a short passcode (knowledge factor).

 

Facial recognition and a device push

Some 2FA systems are set up to scan your face and then send a push notification to your phone for final approval. This approach covers inherence (your face) and possession (your phone).

 

Password and an authenticator app

After entering a password (knowledge factor), you open an authenticator app (like Google Authenticator or an enterprise app). The code changes every 30 seconds, making it hard for potential attackers to guess.

In some instances, businesses might be inclined to explore even more advanced options, such as passwordless authentication. If you’re interested in moving beyond password-based authentication altogether, check out our piece on What is passwordless authentication.

 

What is two-step verification (2SV)?

Two-step verification (2SV)—much like 2FA—also requires two consecutive steps to verify your identity, yet it doesn’t necessarily demand two different factor “categories.” With 2SV, you might be asked to enter your password first, and then answer a personal question—in this instance, both factors would fall under the knowledge category. In other cases, you might be asked to enter your username and password, and then asked to enter a code that is sent to your email. While it’s an additional layer beyond a single password, the factors remain purely knowledge-based.

 

Advantages of 2SV

Ease of implementation

Because 2SV often uses common tools like SMS or email verification, it’s relatively straightforward for businesses to roll it out. Users are also accustomed to receiving codes via these channels.

 

Better than a single password

Even if you reuse your password across multiple sites (which is a risky habit), you’ll still need a second step to access your account. This layered approach is more secure than password-only logins.

 

Limitations of 2SV

Same-factor vulnerability

If both steps rely on knowledge factors (like a password plus a security question), hackers who know enough personal details could potentially break through both. The same can apply to SMS-based verification, which can be susceptible to SIM-swapping attacks.

 

Reliance on external channels

If the code is sent via email, and your email is compromised, that second step isn’t much of a barrier. Similarly, SMS codes can sometimes be intercepted or delayed.

 

Examples of 2SV

After entering your primary credentials, the system emails you a one-time link to confirm it’s really you. If your email account is well-protected, this is an extra hurdle for attackers.

 

Password and a security question

You log in with your usual password, then answer something like, “What was the name of your first pet?” Keep in mind these security questions can be a weak link if the answers are easy to guess or found via social media.

 

Password and an SMS code

You enter your password, then receive a numerical code on your phone. Once entered, the system grants access. While helpful, text-based codes are vulnerable to phone porting or SIM-swap attacks.

 

What is the difference between 2FA and 2SV?

At first glance, 2FA and 2SV can look and feel very similar. In fact, many people use the terms interchangeably. However, there’s a subtle but critical difference between the two:

  • 2FA mandates two distinct factor categories (e.g., something you know and something you have). For instance, a password (knowledge) and a security key (possession).

  • 2SV only requires two steps, and they could both be from the same category, such as a password followed by a security question or code.

From a practical standpoint, 2FA is usually deemed to be more secure than 2SV because it’s tougher to compromise two different types of factors. For example, bad actors can’t steal your fingerprint as easily as they can crack a simple password. However, 2SV is still significantly more secure than just relying on a single factor.

It’s also worth noting that the concept of 2SV vs. 2FA often comes up when discussing advanced authentication flows for businesses. Large organizations might experiment with mixing and matching steps—for instance, a password, plus a biometric scan, plus a push notification, which is effectively a form of multi-factor authentication (MFA). If you’re ready to explore the entire landscape, you might also want to see how passkeys fit into this conversation by checking out our article What is a passkey.

 

Why is it essential to use more than one security method to protect your account?

Cyber threats have evolved to the point where a single password—even a strong, complex one—can be bypassed through phishing scams, data breaches, or sophisticated hacking tools. And that’s exactly why adding additional security layers has become an indispensable practice for businesses that take security seriously. Even if one layer is breached or bypassed, others remain intact, ensuring robust protection.

Human error compounds these issues, as people tend to reuse passwords, are quick to click on dubious links, and are quite often easily duped by clever social engineering techniques. Having multiple authentication checkpoints means that a single oversight won’t necessarily compromise the entire system. Along with mitigating these risks, layered security builds consumer trust, showcasing your commitment to safeguarding personal information—a key differentiator in an era where privacy is a paramount concern.

Finally, many industry regulations and legal frameworks also require or strongly recommend the use of extra security measures. For remote teams spread across various locations and devices, these additional layers act as a safety net, catching suspicious login attempts before they can turn into full-blown breaches.

 

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How to password-protect a Word document

How to password-protect a Word document on Windows

Since Word is part of the Microsoft Office suite and works seamlessly with Windows, adding password protection to a Word document is just as simple as password-protecting an Excel sheet, a PDF or ZIP file, or even an entire folder. Here’s how you can do it:

  1. Open the Word document you want to password-protect.

  2. Click on “File” in the top-left corner.

  3. Select “Info,” then click on “Protect Document.”

  4. A drop-down will appear—choose “Encrypt with Password.”

  5. A new window will pop up. Type in your password, click “OK,” then re-enter the password to confirm.

How to password-protect a Word document on Mac

To password-protect a Word document on a Mac, you need the Microsoft Office suite installed on your Mac device. Once you have it, you can add password protection to your Word document by following these steps:

  1. Open the Word document you want to protect with a password.

  2. Click “Tools” in the menu bar and select “Passwords.”

  3. A “Password Protect” window will pop up. In the “Security” section, under “Set a password to open this document,” just type in the password you want to use for your document.

  4. When prompted, re-enter the password to confirm it, then click OK.

How to remove/change a password in a Word document

If you need to remove or change the password on a Word document, there’s a super easy way to do it. Just open the document and enter the password to unlock it. Then, go through the same steps you’d take to add a password to the document, the only difference being that, when it asks for the current password, you simply delete all characters and click “OK.”

Changing the password follows the same process. You’ll still go through the steps for adding a password, but when prompted, just enter a new one and confirm it. Then, click “OK” to save the change.

Alternatives to password-protecting a Word document

Adding password protection is a solid first step in securing your Word document, but it might not be enough. When you set a password, the document is protected with 128-bit AES encryption, which is pretty reliable. But there are stronger options available, like 256-bit AES or xChaCha20 encryption, which can help keep even the most determined hackers out.

And don’t forget—how you store and share your Word documents matters too. So, if you want to take things a step further, consider storing your files in an encrypted space that only you can access. Tools like NordPass and NordLocker can help with that, allowing you to securely store your documents in an encrypted vault and share them safely with people you trust.

What if I forget my password to a Word document?

We’ve got some bad news—if you ever forget or lose the password to one of your Word documents, unfortunately, you won’t be able to recover it. Password protection in Microsoft Word is designed to prevent any overrides, making sure your documents stay safe and sound. That means your only option is to type in the correct password.

But there’s a way to avoid this problem altogether—using a tool like NordPass.

NordPass securely stores all your passwords, passkeys, credit card details, and other sensitive info in a cloud vault protected by XChaCha20 encryption. It also syncs across all your devices, so you can access your passwords whenever you need them. And if you find coming up with strong passwords a challenge, NordPass can generate them for you on the spot and save them automatically in your vault. Plus, it can help you identify any weak, reused, or compromised passwords to keep your online accounts and data safe.

Sounds good? Then make sure to give NordPass a try!

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How often should you change your password?

Why you should change your passwords regularly

Passwords are like the unsung heroes of your online life—until they’re not. If you’re still rocking the same password from 3 years ago, it’s probably time for a change. Why? Because data breaches are happening all the time, and leaked passwords often end up on the dark web. If your long-loved password is on one of those lists, someone could be snooping through your accounts before you’ve even had your morning coffee.

And then there’s the whole password-guessing game. Hackers have tools that can crack weak passwords faster than you can say “123456.” Speaking of “123456,” the more your password looks like it, the easier it is to break. Regular updates make it harder for hackers to guess passwords, keeping your accounts locked tight.

Let’s not forget password reuse—a habit many are guilty of. Using the same password across multiple accounts is like giving every lock in your life the same key. If one account is breached, the others might as well. And so, using a unique password for each of your accounts helps protect the others if one is compromised.

And sometimes, things just happen—phishing scams, suspicious downloads, and maybe even that sketchy Wi-Fi you connected to at the café last week. Regularly updating your passwords helps you stay ahead of any sneaky situations you might not even know about.

How often should passwords be changed?

Figuring out how often to change your passwords can feel a bit like guessing how often to replace your toothbrush—not too often, but definitely not never. Here’s a quick breakdown by account type to help you decide.

Workplace accounts

For work-related accounts, follow your company’s IT guidelines or security policies. Many organizations rely on recommendations from the National Institute of Standards and Technology (NIST), which suggests focusing on strong, unique passwords and changing them only if there’s a specific reason, like a breach or suspected compromise. However, some workplaces may still require regular updates every 60–90 days, so check with your employer.

Personal accounts

For your personal accounts, how often passwords should be changed depends on how sensitive the information is and how often you use the account. Online shopping? Maybe once a year unless there’s a breach. Social media? The same rule applies. But for accounts with access to private photos, communications, or personal data, like cloud storage or subscriptions, consider changing passwords every 6–12 months.

High-risk accounts

High-risk accounts—like your bank, healthcare portals, or email—deserve extra attention. It’s a good idea to change these passwords every 3–6 months. And don’t wait for a breach—make it part of your routine. If your email password gets compromised, it could be a direct line to resetting your passwords on dozens of other accounts, including the high-risk ones.

Inactive accounts

For accounts you rarely use (or forgot they even existed), it’s better to delete them entirely if possible. An unused account with an old, weak password can be a jackpot for hackers. If account deletion isn’t an option, at least update the password to something very strong and unique. This will minimize the chances of an old account being a weak link in your security chain.

By adjusting your password habits based on the type of account, you can strike a balance between staying secure and not feeling like you’re constantly changing passwords for no reason.

 

Signs that it’s time to update your password immediately

Sometimes, waiting for your next scheduled password update isn’t an option. If any of the situations below sound familiar, it’s time to take action and update your password right away.

You receive a data breach notification

If you get an email or see news that a service you use has been hacked, change your password for that account immediately. Bonus tip: If you’ve reused that password elsewhere (we’ve all done it), update those accounts too.

You notice unusual activity on your account

Strange logins from unfamiliar locations? Messages you didn’t authorize? These are major red flags that someone might already have access to your account. Change your password right away to regain control and lock them out.

Your password has been shared

Whether you’ve shared your password with a friend, family member, or colleague, you’ve made it not only yours. And the more people who know your password, the less secure it becomes. If you’ve shared it even once with someone you trust, make sure to update it sooner rather than later.

You’ve used the same password for too long

Even the best passwords can wear out their welcome. If you can’t remember the last time you’ve changed your password, it’s probably been in use for too long. So, don’t wait for any signs of trouble—go ahead and change it now.

You fell for a phishing attempt

If you’ve clicked a suspicious link or entered your password on a fake website, assume it’s compromised and change it immediately. This is especially important for your email and other high-risk accounts.

Your device was lost or stolen

If your phone, laptop, or tablet is missing—and it’s not protected by strong passwords or encryption—update the passwords for any accounts logged in on that device. This ensures the attacker can’t access your accounts, even if they manage to unlock your device.

Common myths about frequent password changes

Password advice is everywhere, but not all of it is helpful—or true. Let’s debunk some of the most common myths about how often you should change your passwords.

You need to change your password every 30 days

Unless your password has been compromised (or you’re dealing with a super-sensitive work account), there’s no need to change it monthly. Frequent changes can actually backfire, leading people to use simpler passwords they can remember easily (and hackers can guess just as easily). Focus on having strong, unique passwords instead of following a rigid schedule.

A slight tweak counts as changing your password

Swapping “Password123” for “Password124” doesn’t fool anyone—especially not hackers. Small changes like this are just as predictable as the original password. When it’s time to update, go for something entirely new and unrelated.

Password managers make frequent changes unnecessary

Password managers do a great job of keeping your credentials safe and unique, but that doesn’t mean you can forget about updates. If one of your accounts is involved in a breach, you still need to change that password ASAP—your password manager just makes it easier to do so

Tips for managing and regularly updating passwords with ease

Keeping track of passwords and updating them doesn’t have to feel like a chore. With the right strategies, you can simplify the process and boost your security. Here are some tips to help you stay on top of it all:

Use a password manager

A password manager is a game-changer for keeping your accounts secure. It stores all your passwords securely, generates strong and unique ones for every account, and even fills them in for you. By combining zero-knowledge architecture and encryption technology, password managers like NordPass allow you to securely access your credentials and reduce the chances of a malicious party taking over your vault.

NordPass uses the XChaCha20 algorithm to encrypt your data directly on your device so that when it reaches cloud servers, it cannot be opened without your Master Password. In addition to your secure vault, you’ll also have access to features that help strengthen your data security, such as Password Health, which checks for weak or reused passwords, and Data Breach Scanner, which alerts you if you’re affected by a password data leak.

Set reminders for regular changes

Life gets busy, and sometimes it’s easy to forget about updating your passwords. Set reminders every 6–12 months for personal accounts or more frequently for high-risk ones. You can use calendar apps or even your password manager to nudge you when it’s time for a refresh.

Create strong passwords

When updating passwords, aim for a mix of upper- and lowercase letters, numbers, and special characters. Avoid predictable patterns like “password” or “1234.” A password manager can generate complex ones for you, but if you want to stick to doing things manually, try using passphrases—random combinations of unrelated words (e.g., “BlueTurtleDrums$23”).

Avoid password reuse

As we’ve mentioned before, using the same password across multiple accounts is a big no-no. If one account is breached, hackers can use that password to access others. So, always create unique passwords for every account, and let your password manager handle the juggling act.

Try passkeys

Passkeys rely on a pair of cryptographic keys: a private key saved on the user’s device and a public key stored on the website’s server. When the two keys are successfully matched, often triggered by biometric authentication, access is granted. They’re easier to use and nearly impossible for hackers to steal. If an account offers passkeys as an option, consider switching—it’s a big step toward better security.

 

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Regulatory Compliance and NordPass

What is regulatory compliance?

Regulatory compliance refers to various processes and procedures of adhering to the laws, regulations, and standards set by various governing bodies. The regulations can come from numerous sources such as local, state, federal, or even international agencies, industry groups, and professional associations. The intention behind various regulatory compliance is to protect consumers and other stakeholders.

Importance of regulatory compliance

The aim of regulatory compliance is to make sure that businesses and organizations operate in a secure, responsible, and ethical manner. Regulatory compliance can also provide businesses and organizations with a competitive advantage by helping to create a culture of transparency and credibility with customers, employees, and other involved parties. Furthermore, adhering to regulatory compliance can improve internal processes, risk management procedures, and mitigate potential legal issues, which in turn lays a great foundation for a sustainable organization.

However, it’s critical to remember that most regulatory compliance is mandatory. Failing to comply with any of the mandatory regulations can result in hefty fines. For instance, LinkedIn Ireland has been fined more than $300 million by the Irish Data Protection Commission (DPC) for violation of the General Data Protection Regulation (GDPR). Met —the company formerly known as Facebook—was also recently fined over $250 million by the Irish DPC as well for a security breach that exposed the sensitive data of over 28 million users worldwide.

Besides financial losses, non-compliance can cause major damage to the organization’s reputation as clients may lose trust in the organization. This can even lead to serious legal issues.

Below are some of the most common regulatory compliance standards.

National Institute of Standards and Technology (NIST)

The National Institute of Standards and Technology (NIST) is a US federal agency that develops technology, metrics, and standards to drive innovation and ensure operational security within a business environment. NIST compliance is mandatory for all US-based federal information systems except those related to national security. However, the standard can be adopted by any organization.

To be NIST-compliant, a company needs to implement access controls to limit the risk of unauthorized access, develop a comprehensive incident response plan, and devise audit procedures and schedules.

General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) is a data protection law that applies to businesses and organizations operating within the European Union (EU) and the European Economic Area (EEA). It sets out rules for how organizations can collect, use, and store personal data, and provides individuals the right to access and control their personal data.

To adhere to the GDPR, organizations and businesses need to implement measures such as obtaining consent from individuals before collecting their data, providing clear and concise information about their data collection practices, and implementing appropriate security measures to protect personal data.

Health Insurance Portability and Accountability Act (HIPAA)

The Health Insurance Portability and Accountability Act (HIPAA) is a US law that sets out standards for the protection of personal health information. The law applies to healthcare providers and all other entities that handle personal health information in the US.

To meet the requirements set out by the HIPAA, organizations need to implement secure systems for storing and transmitting personal health information, providing training to employees on HIPAA requirements, and implementing access controls to prevent unauthorized access to personal health information.

Payment Card Industry Data Security Standard (PCI DSS)

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards that apply internationally to organizations that handle credit card transactions. The regulatory standard sets out requirements for protecting cardholder data and preventing unauthorized access to such data.

The PCI DSS regulations require businesses and organizations that process payment card information to implement secure systems for storing and transmitting cardholder data, conduct regular security assessments, and implement further security controls to prevent unauthorized access to cardholder data.

ISO/IEC 27001

The ISO/IEC 27001 is an international standard that outlines best practices for an information security management system (ISMS). The standard has been developed to help organizations protect their information assets and manage risks related to information security. The ISO/IEC 27001 is not a mandatory requirement.

To meet the ISO/IEC 27001 compliance, organizations need to conduct regular risk assessments, implement controls to protect against unauthorized access, and regularly review and update their information security management systems.

California Consumer Privacy Act (CCPA)

The California Consumer Privacy Act (CCPA) is a privacy law that in many ways mimics its European counterpart — the GDPR. However, the CCPA applies to businesses operating in California and it provides California residents with the right to access and control their personal data, and imposes certain requirements on businesses that collect and handle personal data.

For an organization to be CCPA compliant, it needs to implement security measures to protect customer data. Furthermore, companies are also required to provide clear and concise information about data collection practices, allowing California residents to request access to and deletion of their personal data.

Gramm-Leach-Bliley Act (GLBA)

The Gramm-Leach-Bliley Act (GLBA) is a US law that applies to financial institutions within the US. Like many of the regulatory compliance standards we already discussed, GLBA requires financial institutions to implement safeguards that would protect personal information as well as to disclose their data collection and sharing practices to customers.

To comply with the GLBA regulatory standards, financial institutions may need to implement secure systems for storing and transmitting personal financial information, providing customers with information about their data collection and sharing practices, and implementing access controls to prevent unauthorized access to personal financial information.

Center for Internet Security (CIS)

The Center for Internet Security (CIS) is a nonprofit organization that provides cybersecurity guidance and best practices to help organizations protect their systems and data. The CIS comprises 18 Critical Security Controls for identifying and protecting against the most common cyber threats.

To be CIS compliant, companies and organizations need to establish a comprehensive cybersecurity perimeter to ensure protection of their data and information management systems.

For a detailed guide on how NordPass can ease compliance with CIS controls, make use of our comprehensive CIS compliance guide.

Opinion 498

The Formal Opinion 498 outlined by the American Bar Association (ABA) provides guidance for US-based lawyers and law firms with regard to virtual practice. While the ABA Model Rules of Professional Conduct permit virtual practice, the Formal Opinion 498 provides an additional set of guidelines for virtual practice.

To follow the guidelines set out by the Opinion 498, organizations or individuals are urged to establish secure information management systems and protect them with complex passwords to ensure secure storage and access to client data.

Agence nationale de la sécurité des systèmes d’information (ANSSI)

ANSSI compliance combines a set of security standards set by the French National Cybersecurity Agency. The ANSSI has been developed as a regulatory standard in France to protect sensitive information and systems from cyber threats such as hacking, malware, and data breaches. Companies that store and handle sensitive information may be required to comply with the ANSSI standards in order to ensure the security of that information.

Compliance with the ANSSI standards may involve regular audits, penetration testing, and other security measures to identify and address vulnerabilities in a company’s systems.

Network and Information Security Directive 2 (NIS2)

The Network and Information Security Directive 2 (NIS2) is an updated cybersecurity directive issued by the European Union to make the critical sectors like energy, healthcare, finance, and digital infrastructure more resilient. The updated directive extends the scope of cybersecurity obligations for organizations through enhanced risk management measures, incident reporting procedures, and supply chain security. More specifically, under the NIS2, organizations are expected to implement security measures, conduct periodic cybersecurity training sessions, and introduce a stricter timeframe for reporting security incidents.

Digital Operational Resilience Act (DORA)

The Digital Operational Resilience Act (DORA) is an EU regulation developed to help raise the cyber resilience of financial institutions, such as banks, insurance companies, and investment firms. DORA provides a framework for managing IT risks by requiring organizations to adopt tight security controls, regularly assess their cybersecurity posture, and ensure that third-party vendors are in compliance with resilience standards. The regulation also dictates detailed incident reporting and response mechanisms to improve the financial sector’s resilience to cyber threats.

How can NordPass help with regulatory compliance?

Meeting regulations and staying compliant can be a complex and time-consuming process, as businesses and organizations must stay up-to-date with the latest regulatory requirements and implement appropriate policies, procedures, and tools.

However, with the right tools at your disposal compliance can be less of a hassle than you might think. One such tool is NordPass — a secure and easy-to-use password manager designed for business use and it can help your organization comply with the security guidelines and requirements outlined in the regulatory compliance standards listed above. But how exactly can it help?

Strong passwords and secure password storage

Most regulatory compliance standards require organizations to implement some sort of security measures to limit the possibility of unauthorized access.

For instance, PCI DSS, GLBA, GDPR, and CIS Controls all have outlined guidelines for ensuring the security of personal data processing and storage.

This is where NordPass comes in as a tool that can help. Designed by the principles of zero-knowledge architecture and equipped with an advanced XChaCha20 encryption algorithm, NordPass offers a secure way to store and access business passwords and other sensitive information in line with regulatory requirements.

Password Policy — a NordPass feature — can also play a critical role in compliance. Using Password Policy, companies can set certain specifications for password complexity for the entire organization, which can significantly fortify the overall security of the organization.

To easily follow Password Policy rules and specifications, users can use our very own Password Generator — a tool that can generate a password adhering to all the specifications outlined in the Password Policy in just a few clicks.

On top of that, NordPass can ensure that all of your organization’s passwords are stored securely and in line with the regulatory requirements.

Secure access management

Some compliance standards require organizations to implement secure access management solutions. For example, this is the case with ANSSI compliance as well as with HIPAA and NIST.

Here NordPass and its Admin Panel can play a major role because it is designed to provide organizations a way to effectively and easily manage access privileges across the entire organization.

Via the Admin Panel, solution Owners and Admins can grant or revoke access to systems as well as monitor member activity within the organization. The Admin Panel is also the place where you can set the Password Policy for the organization, ensuring that passwords throughout the company adhere to certain specifications.

Additionally, NordPass comes equipped with a feature called Activity Log, which allows organization Admins to review user action such as system access and item sharing. For advanced monitoring and security analysis, NordPass integrates directly with Splunk. Organizations that use other Security Information and Event Management (SIEM) solutions can still transfer or audit logs by exporting them in JSON format. 

Sharing Hub is another integral feature that provides organization Owners with a detailed overview of all shared items and folders within the organization. Leveraging the Sharing Hub, Owners get details on who shared what and with whom, ensuring transparency and oversight of data.  

Breach Monitoring

Regulatory compliance standards also tend to outline best practices for responding to a security incident such as a data breach. This is explicitly outlined in the GDPR’s Article 33, which states that data breach including personal data breach should be reported within 72 hours to the supervisory authority. Failing to do so may result in a fine of 10 million or 2% of annual revenue.

NordPass is equipped with a Data Breach Scanner — a tool that can scan the entire company’s domain list for potential breaches. Because the Data Breach Scanner issues a notification to all members of the organization, the company potentially affected by a breach can act quickly and efficiently to contain it.

The NordPass Password Health tool can help you detect potentially, weak, old, or reused passwords throughout the organization and significantly reduce the risk of unauthorized access. On top of that, NordPass offers the Exposed Passwords feature, which scans your organization’s saved passwords against a database of known compromised credentials found on the dark web. If any of the passwords have been leaked in a breach, the Exposed Passwords feature will notify you of that, allowing you to promptly update them to maintain proper account security. 

Bottom line

These days, regulatory compliance is an inseparable part of running a business. Fail to comply and be ready to face hefty fines and serious reputational damage. However, compliance is never easy. But with the right tools at your disposal, the whole process can be a lot smoother.

NordPass can be a tool to assist organizations in meeting various requirements in an easier and more efficient way. By staying compliant, organizations can not only avoid costly fines and legal issues, but also gain a competitive advantage by building a culture of transparency and credibility with their customer base or investors.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How long should a password be?

Can you remember the last time you didn’t need to access at least one of your passwords? It’s probably been a while. After all, the average person handles around 168 passwords. With this scale, you might find yourself wondering if you can really prioritize your security or take some leeway to remember how to access your accounts in the first place.

It doesn’t help that the numbers vary across the board—some think you can get away with 6 characters, others go for numbers in the 20s. Let’s settle it once and for all and answer a few pressing questions. At the end of the day, how long should a password be on average, and how should its structure look to keep you safe online?

Let’s not beat around the bush—the length of your passwords is one of the key cybersecurity checkpoints you can tick off. The exact number of characters is something of a point of contention.

Our recommendation is to use a random mix of 8 characters (including upper- and lowercase letters, numbers, and special symbols) as the bare minimum for your password; however, the longer you go, the better.

Alternatively, you can choose to use a passphrase—a sequence of words or other text that you can use to authenticate your identity. For example, you can use a line from your favorite movie or book. However, make sure no one knows what that specific phrase is. A unique passphrase is as effective as a highly complex password because the spaces between words count as special characters.

The case for longer passwords

But why does it matter so much how long a password is? To answer this question, we first need to understand one of the biggest threats to password safety—brute-force attacks. Cybercriminals use special software to try millions (even billions, if the computer is powerful enough) of character combinations to find passwords that work. They usually start with every word in a dictionary, so passwords that contain only one or two words are not resilient.

With fewer characters, you can’t create as many secure, randomized combinations to protect your accounts. If you go any shorter than 8 characters, the chances of your passwords getting brute-forced increase. The more personal and work accounts you have, the more variety you need—and a longer password accounts for it.

In NordPass’ 2024 list of the Top 200 Most Common Passwords, the first 10 entries consisted of passwords ranging from 5 to 9 characters. Most were sequences of numbers and lowercase letters based on the keyboard layout—think 123456 or qwerty. Such combinations are easy bait for cybercriminals, who require less than a second to break through and claim the account for themselves.

Top 10 worst passwords

The problem is not just how short the passwords are but also how frequently they’re reused. If a person comes up with a 6-character password containing only letters and numbers, the hacker can run a program to easily find the matching combination. Then, they can use the password with the related email address and easily obtain all accounts belonging to their victim. Longer passwords with more variety require more guesses to predict, increasing the time required to breach them.

To address the problem of weak passwords, various password policies and guidelines are set in place to help both businesses and individuals manage their personal data better. The National Institute of Standards and Technology (NIST) updated its password security guidelines in 2024, clarifying how the expectations for credential security have shifted. According to the new guidelines, passwords should be up to 64 characters long—a long passphrase can be used in favor of a password—and should only be changed if there’s clear evidence that they’ve been compromised. Passwords should also be generated and stored using a password manager for better security.

 

Balancing length and complexity

What keeps you safe online and what makes it easy for you to be online in the first place requires a delicate balance. As mentioned earlier, password length plays a key role in its predictability. The fewer characters you use, the less time it takes to crack it. Likewise, the more variety you add, the more time and resources are needed to figure it out.

Passphrases are a great help here. They ensure your credentials are long and complex without the clutter of random characters. If you pick a quote, you’ll probably use at least 4 or 5 words. This automatically racks up the password length, granting it a higher resilience against cyber threats.

You might wonder how resilient passphrases are against brute-force attacks targeting dictionary words. The length of the passphrase is actually an advantage here despite it using words from a known corpus—it increases the guessing difficulty level, and fishing out every word, space, and punctuation mark in that order is resource-intensive, making it more difficult for cybercriminals to detect an exact match.

Now, let’s sprinkle in some complexity. Of the options “password123” and “PAl4p5e*tDgF!3”—the 111th entry in the aforementioned Top 200 list and a completely random keysmash—the former would take under a second to crack, while the latter would need hundreds of years.

The randomized example does not follow an easily detectable pattern and contains every character we’ve mentioned so far—upper- and lowercase letters, numbers, and special symbols. If you took a similar combination and kept adding random characters in random spots, the complexity level would increase. In short, length adds complexity, and complexity is exactly what you want for your credentials.

Tips for creating secure, long passwords

Passphrases are a solid idea for strong credentials. However, some websites and apps don’t recognize spaces as special characters, which makes it harder to use more memorable passwords. How do you come up with really good ones, and how do you make sure you don’t forget them?

One thing you can try is a spin on a passphrase—take the words in a phrase, omit some letters, replace them with special characters, and voila! You’ve got a strong password concept on your hands. For example, let’s take the classic phrase “The quick brown fox jumps over the lazy dog” and turn it into “1.Qui.bro.fo.jum.ove.1.laz.dO.” We’ve replaced “the” with 1, left the first 2 or 3 letters of the other words, capitalized the first and last letters, and finished with a full stop for good measure. The result? A password that would take centuries to breach.

That said, avoid simply taking a word and replacing its letters with numbers, like “0v3r” for “over”—hackers are familiar with such “tricks” and have added them to their brute-force checklist. Instead of following a predictable pattern, get creative—switch random letters with numbers that wouldn’t otherwise match (like a 5 for L instead of the anticipated S) and build a cipher only you know. We’ve got more inspiring ideas you can use to level up your inner password generator in our dedicated article.

If you’re unsure whether your new credential meets the ideal strong password criteria, you can test it using our secure password checker. Don’t worry—we don’t store the passwords you type into this tool to ensure that your data remains secure, whether it’s just an idea or already in use.

The simplest way to sort out your password length troubles and leave the worries of mixing them up behind is to get a tool that does it for you—and NordPass knows how to get it done right. NordPass is an intuitive password manager that keeps all your credentials securely encrypted.

Thanks to its built-in Password Generator, you won’t have to worry about coming up with passwords on your own ever again. You won’t need to remember them either, as the autofill feature will detect your login attempts and input your credentials for you in seconds. In fact, with NordPass, the only password you need to remember is the Master Password to access your vault. Everything else will be handled for you with our browser extension and mobile app.

Reinforce all your accounts with ease and embrace the long password lifestyle with NordPass.

 

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.