between 4 and 6 is characters is pretty bad, but only numbers as well? Thats begging to be brute force.
Well even 4 numbers of 10,000 combinations. Say they lock the account out after 100 wrong attempts (hopefully), then assuming you don't choose 1234 or 0000 then you're pretty safe from a brute force attack. I'm guessing they require this so you can type it in over the phone, that's the only sensible reason I can think of.
Lock what precisely?
If you lock the specific account from all login attempts, you have a DoS opportunity on your hands.
If you lock the specific account from specific IPs, botnets win.
And I doubt a company would have requirements like this, and cross-ip and cross-account attack validations in place.