Why the Password Rules Everyone Remembers Are No Longer the Best Rules
For years, employees were told to create short, complicated passwords and replace them every 60 or 90 days. Current guidance has moved in a different direction because those rules often produced predictable behavior instead of stronger security.
Modern Password Security Is Built Around Human Behavior
The old model treated password strength as a puzzle employees had to solve. Add a capital letter. Add a number. Add a symbol. Change the password again in 90 days. In practice, many people responded with predictable patterns such as changing Spring2026! to Summer2026!, reusing passwords across systems or saving them in insecure places.
Current NIST guidance emphasizes longer passwords, screening against commonly used or compromised values, support for password managers and changes triggered by evidence of compromise. It also makes clear that passwords are not phishing-resistant, which is why MFA, passkeys and security keys now play a larger role.
Use length
Require at least 15 characters when a password is used by itself and permit long passphrases.
Stop routine expiration
Change passwords when compromise is suspected or confirmed, not only because the calendar says so.
Add stronger layers
Use a business password manager, MFA and phishing-resistant authentication wherever supported.
Rules That Sound Secure but Often Produce Weak Results
Employees should change passwords every 90 days
Routine expiration can encourage small, predictable changes that attackers anticipate. Current NIST guidance says businesses should not require periodic password changes without evidence that a password has been compromised.
The better approach is to require an immediate change after suspected phishing, malware, unauthorized sharing, a breach alert or another credible sign of exposure.
Every password must contain uppercase letters, lowercase letters, numbers and symbols
These composition rules often lead to predictable choices such as capitalizing the first letter and adding a number and exclamation point at the end. NIST advises against arbitrary mixtures of character types.
The better approach is to prioritize length, uniqueness, compromised-password screening and password-manager-generated credentials.
A strong password can safely be reused
A password may be difficult to guess and still be dangerous when it is reused. If one website or vendor exposes it, criminals can test the same credentials against email, Microsoft 365, banking, payroll and other services.
The better approach is to use a unique password for every account and store those credentials in an approved business password manager.
A long password cannot be phished
Length helps resist guessing, but it does not stop an employee from typing a password into a fraudulent login page. It also does not stop infostealer malware or session token theft.
The better approach is to use MFA and move critical accounts toward phishing-resistant passkeys or FIDO2 security keys.
Saving passwords in a browser is the same as using a business password manager
Browser storage may protect some credentials, but it often lacks the centralized policies, secure sharing, reporting, access controls and offboarding features businesses need.
The better approach is to move company credentials into an approved business vault and remove unmanaged browser copies after migration is verified.
MFA makes password security irrelevant
MFA makes a stolen password less useful, but weaker MFA can still be bypassed through push fatigue, social engineering, or a stolen session token from an infected device.
The better approach is to use unique passwords and MFA together, then prioritize phishing-resistant methods for administrators, executives, remote access and high-risk systems.
A Short History of Business Password Advice
Password guidance did not change because security became less important. It changed because researchers, breach data and real-world behavior showed that some familiar rules were not producing the intended result.
Short passwords were common
Older systems often had strict technical limits on password length and storage. Advice focused on creating a secret that was difficult for another person to guess.
Character rules and frequent expiration became standard
Companies increasingly required capitals, numbers and symbols, often combined with 30-, 60- or 90-day password changes. These controls were easy to document, but employees frequently responded with repeatable patterns.
Exposed password data revealed predictable behavior
Large collections of breached passwords showed how commonly people reused credentials, followed keyboard patterns and modified familiar words to satisfy composition rules.
Length, blocklists and usability gained priority
NIST SP 800-63-4, released in 2025, shifted the emphasis toward longer passwords, screening for common or compromised values, support for password managers, syncable passkeys, and changes based on actual compromise rather than arbitrary schedules.
Businesses are reducing their dependence on reusable passwords
Passkeys and FIDO-based authentication can resist traditional phishing because the credential is bound to the legitimate website or application instead of being typed into a login form.
What a Modern Password Policy Should Require
- At least 15 characters when a password is used as a single authentication factor.
- Support for passwords and passphrases of at least 64 characters.
- No arbitrary requirement for a particular mixture of uppercase letters, lowercase letters, numbers and symbols.
- No routine password changes without evidence or reasonable suspicion of compromise.
- Screening against commonly used, expected or previously compromised passwords.
- Support for password managers, autofill and paste functionality.
- Failed-login throttling and other protections against automated guessing.
- MFA for critical accounts, with phishing-resistant methods prioritized where supported.
Password Length Is Important, but It Is Not Enough
A long password can still be phished, stolen by malware, exposed by a vendor or reused across multiple systems. Strong identity security combines passwords with password managers, MFA, passkeys, access controls, employee training and monitoring.
Read the Modern Password Security GuideWhat Business Leaders Should Ask
- Are employees still required to change passwords on a fixed schedule?
- Do systems allow long passwords and passphrases?
- Are new passwords checked against known compromised values?
- Does every employee have an approved password manager?
- Have company passwords been removed from unmanaged browser storage?
- Is MFA required for email, remote access, financial systems and administrative accounts?
- Are passkeys or security keys available for the highest-risk accounts?
- Can the company quickly remove vault, account and MFA access during offboarding?
Turn Modern Guidance Into a Written Policy
The STACK Cybersecurity Business Password and Authentication Policy Toolkit provides editable policy language, an implementation checklist and a password incident checklist.
Free Download
Business Password and Authentication Policy Toolkit
Download the editable Microsoft Word toolkit and customize it for your company, systems, contracts and compliance requirements.
Download the Word ToolkitPassword Myths and Policy Questions
Should employees change passwords every 90 days?
Not automatically. Passwords should be changed when there is evidence or reasonable suspicion of compromise, when a credential was entered into a phishing site, when malware is detected or when IT directs a reset after an incident.
Do passwords need uppercase letters, numbers and symbols?
Those characters may appear in a strong password, but current NIST guidance advises against requiring an arbitrary mixture. Length, uniqueness, compromised-password screening, password managers and MFA matter more.
How long should a business password be?
NIST requires at least 15 characters when a password is used as the only authentication factor. Systems should permit at least 64 characters so employees can use long generated passwords or passphrases.
Are password managers safe for business use?
A properly managed business password manager is safer than expecting employees to memorize or manually record unique passwords. The vault should use MFA, controlled sharing, role-based access and documented offboarding procedures.
Are passkeys replacing passwords?
Passkeys are replacing passwords on some services, but adoption is uneven. Businesses should begin with systems that support passkeys or FIDO2 security keys, especially for privileged and high-risk accounts.
Does MFA stop every account takeover?
No. MFA greatly reduces risk, but weaker methods can still be bypassed, including through stolen session tokens. Phishing-resistant MFA provides stronger protection because the authentication process is tied to the legitimate site or application.
Continue Through the Password Security Resource Center
Official Password and Authentication Guidance
- NIST SP 800-63-4 password requirements
- NIST explanation of password strength and composition rules
- NIST guidance for creating and managing passwords
- CISA guidance for requiring MFA
Need Help Replacing Outdated Password Practices?
STACK Cybersecurity can review password storage, MFA coverage, browser-stored credentials, shared accounts, employee onboarding and offboarding, and the written policies supporting those controls.
Schedule a Cybersecurity Risk AssessmentCybersecurity Consultation
Is your company secure against cyber threats? If you're not sure, it's time for a cybersecurity risk assessment (CSRA). STACK Cybersecurity's CSRA will meticulously identify and evaluate vulnerabilities and risks within your IT environment. We'll assess your network, systems, applications, and devices. You'll get a detailed report and action plan to improve your security posture. Don't wait until it's too late.