πŸ›‘οΈ
Beveiliging

Secure password policy for web hosting: here’s how to do it

πŸ“… 8 October 2026 ✏️ 8 October 2026 ⏱ 5 min leestijd

Discover how to set up a secure password policy for your web hosting, email, and Plesk account, with concrete steps and practical tips.

A secure password policy is the easiest way to protect your website, email, and hosting environment from misuse. It revolves around strong, unique passwords, two-factor authentication, and clear agreements about who has access to what. In this article, you’ll learn step by step how to set this up for your web hosting account, Plesk, and business email.

Why password policy is crucial

Websites and email accounts are a popular target for attackers who automatically try weak passwords. One weak password on an FTP account, database, or mailbox can be enough to compromise your entire hosting environment. Think of stolen customer data, a website full of malware, or a mail server that suddenly starts sending spam on behalf of your domain.

A well-thought-out policy doesn’t prevent this entirely, but makes it significantly harder for attackers. It combines technical measures, such as two-factor authentication, with organizational agreements, such as regularly checking who still has access.

Characteristics of a strong password

A strong password is long, unique, and unpredictable. Below are the key characteristics:

  • At least 12 to 16 characters long, the longer the better.
  • A mix of uppercase letters, lowercase letters, numbers, and symbols, but most importantly: length matters more than complexity.
  • No recognizable words, names, birth dates, or common patterns like ‘Welcome2024’.
  • Unique per account: never reuse the same password for hosting, email, and other services.
  • Stored in a password manager instead of in a document or browser note.
Password managerUnique password+ 2FASecuredPlesk account
πŸ’‘ Tip: Use a phrase of four to five random words instead of a single password, for example ‘raincoat-bicyclebell-tuesday-coffee’. This is easier to remember and often longer and stronger than a short combination with symbols.

Setting up password policy in Plesk

In Plesk, the control panel that Tandata uses for web hosting, you can strengthen your password policy in multiple places. You’ll find this under Accounts and in the settings of individual FTP, database, and email accounts. Below is a practical step-by-step plan.

1

Check existing accounts

Log in to Plesk and review all FTP, database, and email accounts. Remove accounts that are no longer in use and note which passwords are outdated.

2

Set strong passwords

When creating or changing an account, use Plesk’s built-in password generator. This automatically generates a long, random password that you can immediately save in your password manager.

3

Enable two-factor authentication

Activate two-factor authentication for your Plesk account under your user settings. This way, a stolen password alone isn’t enough to log in.

4

Secure your email accounts separately

Give each mailbox account its own unique password. This is especially important for business email, as a hacked mailbox is often misused for phishing against customers.

If you work with business email hosting, make sure each account has its own password and, where possible, two-factor authentication. This prevents one leaked password from granting access to your entire mail environment.

Long-term management and monitoring

A password policy isn’t a one-time action, but an ongoing process. Periodically schedule a review to check who still has access to which systems, whether old accounts can be removed, and whether passwords that may have been leaked need to be replaced.

Also pay attention to the following points:

  • Immediately change passwords after an employee or freelancer with access leaves.
  • Use separate accounts per person instead of one shared account, so you can always trace who made a change.
  • Regularly check login attempts and notifications in Plesk for suspicious activity.
  • Make sure your domain registration and DNS management at domain names are just as well secured as your hosting, because whoever takes over your domain can also hijack your email and website.

Not sure whether your current hosting offers sufficient security options, such as daily backups and free SSL? Then switching to Tandata is often easier than you think, including help migrating accounts and passwords.

Frequently asked questions

How often should I change my hosting password?

There’s no fixed interval that applies to everyone. More important than periodic changes is replacing a password immediately when there’s suspicion of a leak, or when someone with access leaves the organization.

Is a password manager secure enough?

Yes, a reputable password manager is safer than remembering passwords or storing them in a document. You only need one strong master password to access all your other passwords.

Why do I need two-factor authentication if my password is already strong?

A strong password can still leak, for example through phishing or a data breach at another service. Two-factor authentication ensures that a password alone isn’t enough to log in.

Should I use a separate password for each email account?

Yes. If multiple mailboxes share the same password, one leaked password immediately grants access to all accounts. Separate passwords limit the damage in case of a leak.

What should I do if I suspect my account has been hacked?

Immediately change all relevant passwords, check recent login activity in Plesk, and contact support. Via the knowledge base you’ll find explanations on checking logs and restoring an account.

Conclusion

A secure password policy consists of long, unique passwords per account, two-factor authentication where possible, and periodic checks on who has access to your hosting, email, and domain. By applying this consistently in Plesk, you significantly reduce the risk of hacks and data breaches.

View web hosting β†’

Was dit artikel nuttig?