What's Happening?
Lewis & Clark College's IT Security Team has initiated a mandatory password update phase to bolster the digital security of its campus community. All users are required to change their passwords by October 20, 2026, to prevent account deactivation. The
college has introduced an improved and more secure method for password changes, accessible via two SecureAuth methods: the SecureAuth Mobile App and the SecureAuth Dashboard. The mobile app offers a seamless way to update credentials and complete multi-factor verification, while the dashboard is available for users who have configured hardware security keys or biometric authentication. This initiative aims to protect individual accounts, college systems, and the work conducted within the institution from evolving cybersecurity threats. The new password policy mandates a minimum length of 15 characters and a maximum of 19, including at least one special character. Passwords cannot reuse the six most recent ones, contain personal information like first, last, or username, or include common password values or phrases. Additionally, passwords known to have been exposed in cyber breaches are prohibited, and all passwords will expire every 180 days.
Why It's Important?
This mandatory password update is a critical step in safeguarding the digital infrastructure of Lewis & Clark College. In an era of rapidly evolving cybersecurity threats, regular password changes are essential to mitigate risks such as unauthorized access, data breaches, and identity theft. The implementation of a robust password policy, including length requirements, character diversity, and restrictions on common or previously compromised passwords, significantly enhances the overall security posture of the institution. By requiring multi-factor authentication options, including biometric authentication, the college is adopting industry best practices to create multiple layers of defense against cyberattacks. This proactive measure protects not only the personal data of students and staff but also the integrity of academic and administrative systems. A secure digital environment fosters trust, ensures continuity of operations, and protects intellectual property, which are vital for the functioning and reputation of an educational institution. The policy also educates users on the importance of strong password hygiene, contributing to a more cyber-aware community.
What's Next?
Users at Lewis & Clark College will continue to receive email reminders until they update their passwords, with a strict deadline of October 20, 2026, to avoid account disabling. The IT Service Desk will remain available to assist users with any questions or issues encountered during the password update process. Following the initial mandatory update, the policy of password expiration every 180 days will ensure ongoing security. The college may also explore further enhancements to its cybersecurity measures, potentially integrating more advanced authentication technologies or expanding user training programs. The success of this initiative will likely be monitored through metrics such as compliance rates and incident reports, informing future security strategies. The continuous adaptation to new cyber threats will be a key focus, ensuring that the college's digital environment remains resilient and secure for its community.
Beyond the Headlines
The transition to mandatory password updates at Lewis & Clark College reflects a broader trend in cybersecurity, where organizations are moving beyond basic password requirements to implement more sophisticated authentication protocols. This shift acknowledges that human error and weak passwords are significant vulnerabilities. By integrating biometric authentication and hardware security keys, the college is embracing a future where identity verification is less reliant on memorized strings of characters and more on inherent or possessed factors. This move also highlights the ethical responsibility of institutions to protect user data, especially in educational settings where sensitive personal and academic information is stored. The regular expiration of passwords, while sometimes inconvenient for users, underscores the principle that security is an ongoing process, not a one-time fix. This initiative could also serve as a model for other educational institutions seeking to enhance their digital defenses against an increasingly complex threat landscape, emphasizing the balance between user convenience and robust security.













