Currently, it is possible to enter password indefinitely without inactivating the account. It appears to me that this is a safety ‘gap’, as someone with false intentions has lots of opportunities to try and hack an account.
Automatically inactivating an account after a number of wrongly entered passwords in a period of time (number and time-span should be configurable) would be a nice solution. This should be accompanied by a safe manner for the account owner to de-activate his account. For Zeeman employees this could be realised by sending an email with password reset code to the mailadress that is linked to the inactivated account.