Security Awareness

Password Security: What Actually Reduces Risk

Forced monthly resets and complexity rules were the old answer, and they made passwords worse, not better. Here is what current guidance actually recommends.

Talk to a CISO

The business problem

For years, "strong password policy" meant forced complexity (a symbol, a number, a capital letter) and forced rotation every 60 or 90 days. Both rules are now known to backfire: complexity rules push people toward predictable substitutions ("Password1!" becomes "Password2!"), and forced rotation pushes people toward reusing a password across systems just to keep up — the opposite of the intended outcome.

What current guidance actually recommends

NIST’s current digital identity guidelines (SP 800-63B) dropped forced periodic rotation and complexity rules for a simpler standard: length over complexity, and rotation only when there is evidence of compromise.

  • Length — a long passphrase is harder to crack than a short, complex password, and easier for people to actually remember
  • Uniqueness — no password reused across more than one system, which is where a password manager becomes essential rather than optional
  • Multi-factor authentication — the single highest-leverage control; even a compromised password is far less useful to an attacker with MFA in place
  • Rotation on evidence, not on a calendar — change a password because it was involved in a breach, not because 90 days passed

“The old rules — complexity and forced rotation — made passwords harder to remember and easier to guess. Length, uniqueness, and MFA do more with less friction.”

Why it matters

Credential-based attacks — password spraying, credential stuffing from other companies’ breaches, simple guessing — remain one of the most common ways into an environment, precisely because password reuse across personal and work accounts is still the default behavior for most people. A policy that fights human nature loses; a policy that works with it (length, a password manager, MFA) actually reduces exposure.

Practical guidance

Adopt a password manager as standard company tooling, not an optional suggestion. Require MFA everywhere it is available, prioritizing email, VPN, and any system with financial or administrative access. Set a minimum length requirement (12+ characters) instead of complexity rules, and reserve forced resets for confirmed or suspected compromise.

See how identity controls fit into a full risk-based security program.

Explore Cyber Risk Advisory

Where to go from here

If the current policy still forces a password change every 90 days with complexity requirements, that policy is actively working against the outcome it is meant to produce — it is worth revisiting against current NIST guidance.

FAQ

Questions, answered directly.

No. Current NIST guidance (SP 800-63B) recommends against mandatory periodic rotation for user-chosen passwords, in favor of rotation triggered by evidence of compromise.

For any organization asking employees to maintain unique passwords across dozens of systems, yes — without one, uniqueness and memorability are directly in conflict, and memorability usually wins.

In practical terms, yes. MFA blocks the large majority of credential-based attacks even when the underlying password is compromised, which makes it the higher-leverage investment when resources are limited.

A minimum length requirement, paired with a check against known-breached password lists, does more to prevent weak passwords than symbol and number requirements ever did.

Talk to a CISO about modernizing identity and password policy.

30 minutes. No obligation. No sales pitch.

Talk to a CISO