Password Security: What Actually Reduces Risk
Forced monthly resets and complexity rules were the old answer, and they made passwords worse, not better. Here is what current guidance actually recommends.
The business problem
For years, "strong password policy" meant forced complexity (a symbol, a number, a capital letter) and forced rotation every 60 or 90 days. Both rules are now known to backfire: complexity rules push people toward predictable substitutions ("Password1!" becomes "Password2!"), and forced rotation pushes people toward reusing a password across systems just to keep up — the opposite of the intended outcome.
What current guidance actually recommends
NIST’s current digital identity guidelines (SP 800-63B) dropped forced periodic rotation and complexity rules for a simpler standard: length over complexity, and rotation only when there is evidence of compromise.
- Length — a long passphrase is harder to crack than a short, complex password, and easier for people to actually remember
- Uniqueness — no password reused across more than one system, which is where a password manager becomes essential rather than optional
- Multi-factor authentication — the single highest-leverage control; even a compromised password is far less useful to an attacker with MFA in place
- Rotation on evidence, not on a calendar — change a password because it was involved in a breach, not because 90 days passed
“The old rules — complexity and forced rotation — made passwords harder to remember and easier to guess. Length, uniqueness, and MFA do more with less friction.”
Why it matters
Credential-based attacks — password spraying, credential stuffing from other companies’ breaches, simple guessing — remain one of the most common ways into an environment, precisely because password reuse across personal and work accounts is still the default behavior for most people. A policy that fights human nature loses; a policy that works with it (length, a password manager, MFA) actually reduces exposure.
Practical guidance
Adopt a password manager as standard company tooling, not an optional suggestion. Require MFA everywhere it is available, prioritizing email, VPN, and any system with financial or administrative access. Set a minimum length requirement (12+ characters) instead of complexity rules, and reserve forced resets for confirmed or suspected compromise.
See how identity controls fit into a full risk-based security program.
Explore Cyber Risk AdvisoryWhere to go from here
If the current policy still forces a password change every 90 days with complexity requirements, that policy is actively working against the outcome it is meant to produce — it is worth revisiting against current NIST guidance.
Questions, answered directly.
No. Current NIST guidance (SP 800-63B) recommends against mandatory periodic rotation for user-chosen passwords, in favor of rotation triggered by evidence of compromise.
For any organization asking employees to maintain unique passwords across dozens of systems, yes — without one, uniqueness and memorability are directly in conflict, and memorability usually wins.
In practical terms, yes. MFA blocks the large majority of credential-based attacks even when the underlying password is compromised, which makes it the higher-leverage investment when resources are limited.
A minimum length requirement, paired with a check against known-breached password lists, does more to prevent weak passwords than symbol and number requirements ever did.
Talk to a CISO about modernizing identity and password policy.
30 minutes. No obligation. No sales pitch.