Security Policy¶
| Owner | Patrick Tolvstein |
| Version | 1.0 |
| Created | 2026-06-16 |
| Last reviewed | 2026-06-16 |
| Next review | 2027-06-16 |
Password manager¶
All employees must use Dashlane as their password manager for all work-related accounts. Storing passwords in browsers, notes apps, spreadsheets, or any other tool is not permitted.
- All work credentials must be saved in Dashlane immediately upon creation
- The company Dashlane account is provided by the company - do not use a personal Dashlane account for work credentials
- If you lose access to Dashlane, contact Nikolaj (NVA) or Patrick (PT) immediately
Passwords¶
- Always use the highest available password strength - use Dashlane's password generator for all new accounts
- Minimum length: 8 characters, with a mix of letters, numbers, and symbols
- Never reuse passwords across accounts
- Never share passwords via email, Slack, or any other messaging tool - use Dashlane's secure sharing feature instead
- If you suspect a password has been compromised, change it immediately and notify Nikolaj (NVA) or Patrick (PT)
Two-factor authentication (2FA)¶
- 2FA must be enabled on all accounts where it is available - this is mandatory, not optional
- Store 2FA codes in Dashlane alongside the login so the team is not locked out if someone is unavailable
- Prefer authenticator app-based 2FA (TOTP) over SMS-based 2FA where possible - SMS is vulnerable to SIM-swapping attacks
- Never share 2FA codes with anyone, and never approve 2FA prompts you did not initiate yourself
Unexpected 2FA prompts
If you receive a 2FA prompt you did not initiate, deny it immediately and notify Patrick (PT). This may indicate that your credentials have been compromised.
Account hygiene¶
- Use a unique email address for each service where possible. Do not share accounts whenever possible.
- Review and revoke access to unused accounts and integrations regularly
- Never create work accounts using personal email addresses
Devices¶
Work devices are managed through Kandji (MDM). This means security policies, FileVault encryption, and recovery keys are handled centrally — you do not need to manage these yourself.
- Lock your screen whenever you leave your device unattended — automatic lock is enforced via Iru after 5 minutes of inactivity
- Do not attempt to disable or work around MDM (Iru) policies on your device
- Do not use work devices for personal activities that could introduce security risks
- Report lost or stolen devices to Patrick (PT) or Nikolaj (NVA) immediately — remote wipe can be initiated via MDM
Phishing and social engineering¶
- Never click links or download attachments from unexpected or suspicious emails - verify with the sender via a separate channel if in doubt
- Legitimate services will never ask for your password via email or chat
- If you receive a suspicious message that appears to come from a colleague or internal system, verify via phone or in person before acting on it
- Report suspected phishing attempts to Patrick (PT) - see Incident Response if an account may have been compromised
Questions¶
If you are unsure whether something is permitted or how to handle a specific situation, contact Patrick (PT) before acting.