2026-08-24

SECURITY HINTS & TIPS:

SECURE PASSWORD HANDLING PRACTICES

This guide outlines our security standards to help you keep our team’s information safe.

Protecting Our Digital Perimeter

Protecting all sensitive information is our first line of defence. This includes passwords, financial documents, Personally Identifiable Information (PII), and sensitive internal reports.

Sharing credentials or a PIN is discouraged; however, in certain circumstances, such as sharing newly created credentials within the team, please use our company-approved secure tools such as https://nordpass.com/password-sharer/.

External Sharing Policy

The sharing of sensitive information, especially with external parties, is strictly discouraged and prohibited. To maintain our security standards, all such data must remain within the organization’s secure perimeter. If you receive a request for sensitive data from an external source, please verify it with the IT Service Desk before proceeding.

DOs

✅ Approved Channels: Please use our approved, secure tools for team passwords.
✅ Separate Data: Always send sensitive information (e.g., usernames or financial codes) and access links in separate communications.
✅ Use Secure Sharing Tools: When you need to share credentials, use the approved secure password sharing tool outlined in the FAQ under https://itportal.io/faq-items/secure-password-generation-and-sharing/
✅ Verify Requests: If you receive a request for sensitive data from an outside source, always verify the request first.

DON’Ts

❌ Do Not Share Externally: Sharing passwords, PII, credit card, financial records, or internal reports with external parties is strictly prohibited.
❌ Do Not Combine Communications: Do not send a username and its associated access link or password in the same email or message thread.
❌ Do Not Use Unapproved Methods: Do not use unapproved methods for managing or sharing sensitive data.
❌ Do Not Send In Plain Text: Do not send credentials in plain text, including in emails.

Protecting our company’s information is a shared responsibility.

for further information on this and other topics, please refer to the FAQ in ITPortal.

Manitoulin Group of Companies Security Team
Cybersecurity@manitoulingroup.com

Stop, Look, and Think. Don’t be fooled.