← Prompt Library / Cybersecurity
Write a password and MFA policy aligned with current guidance — length over complexity theatre, MFA where it counts, and rules an SMB can actually follow.
Write a password and authentication policy for {{organisation}} ({{size}}, systems in use: {{systems}}).
Align with modern guidance (NIST-style): length over composition rules (passphrases, minimum 12+), no forced periodic rotation (rotate on compromise), block known-breached passwords where tooling allows, a password manager as the enabling tool (name the expectation), MFA mandatory on email, finance, admin, and remote access — with allowed methods ranked (app/hardware key over SMS), and account recovery that doesn't undermine everything. Write the policy itself in plain language, one page, plus a 5-line summary for the all-staff email.
Fields like {{ this }} are placeholders — replace them with your own details, or let Aria ask you for them.
This prompt runs with Aria connected to your email, files, CRM and 40+ other services — and you can schedule it to run automatically.
Start Free WeekA playbook for when someone clicks: immediate containment steps by scenario, communication, and the...
Assess a software vendor's security before trusting them with your data — the questions that matter,...
Run a quarterly access review: who has access to what, the leaver/mover gaps, and the deprovisioning...
Write a short security awareness briefing staff will actually absorb — current scams, what to do in...
Design a real recovery test — not 'backups ran' but 'we restored and it worked': scenarios, steps, s...
Pre-drafted communications for a security incident: staff notice, customer notification, and regulat...