Proposing that any 'forgotten password' reset requires the physical presence of the CEO and a sysadmin at a dedicated machine is a really good way to ensure that within six months all passwords are either stored in plain text or written down on a post-it note.