Ok, thanks for your help guys.
Regarding the reset password links that are sent to users:
1. Do these links expire and if so, how long do they remain valid for?
2.Assuming someone other than the intended recipient had access to the link (and it hadn’t been used already), is there anything to stop that person using the link to reset a password?