Security Behaviour Database
/
All Behaviours > Using a separate passphrase for email account(s)

Using a separate passphrase for email account(s)

Separate passphrases should be used for important workplace accounts, like primary workplace email accounts and other accounts that access sensitive data. Passphrase re-use across lower value accounts reduces security friction without introducing disproportionate levels of risk.


Why is it important?

Email accounts are a crucial part of login systems. They hold lots of sensitive information.

Passphrases are stronger than passwords. This is due to their length and randomness.

Using a unique passphrase for each account creates resilience. Should a data breach occur, it is less likely all accounts will be able to be accessed. They'll be protected with different details.

Priority Tier

Behaviours in SebDB are ranked by their impact on risk. Tier 1 behaviours have the biggest impact, Tier 4 behaviours the least.

Tier 0

Risk Mitigated

Account Compromise

Account Compromise

Account compromise happens when unauthorised people access them.

Further reading

https://krebsonsecurity.com/password-dos-and-donts/ http://130.18.86.27/faculty/warkentin/SecurityPapers/Merrill/IvesWalshSchneider2004_CACM44_4_Domino%20Effect%20of%20Password%20Reuse.pdf https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/use-a-strong-and-separate-password-for-email https://www.us-cert.gov/ncas/tips/ST04-002

SebDB is brought to you byCybSafe| © 2022 CybSafe Ltd