Back to Posts

Password Reset: A Business Guide to Password Security

Password Reset logo

Originally Published: Oct. 2, 2025
Last Updated: July 20, 2026

By Tracey Birkenhauer, journalist and Chief Impact Officer, STACK Cybersecurity

This guide has been substantially expanded to reflect current password guidance, emerging credential-theft tactics, and the growing use of password managers, phishing-resistant MFA, and passkeys. Password Security Hub

Executive Summary

Passwords remain the most common way employees access email, financial accounts, cloud applications, customer records, and business systems. They also remain a frequent target for hackers. Weak passwords, reused credentials, phishing, infostealer malware, password spraying, and passwords saved in web browsers can give criminals a direct path into a company.

This guide launches STACK Cybersecurity's Password Reset series that explains how modern password security has changed. Businesses should focus on longer passwords, unique credentials, dedicated password managers, multi-factor authentication (MFA), compromised-password screening, and a planned transition toward passkeys and phishing-resistant authentication.

Password advice has changed considerably over the years. Employees were once told to create short passwords filled with capital letters, numbers, and symbols, then change them every 30, 60, or 90 days. The result was often predictable passwords written on sticky notes, reused across accounts, or changed from something like Summer2025! to Fall2025!.

Current guidance focuses less on complicated character rules and more on length, uniqueness, secure storage, multi-factor authentication, and detecting compromised credentials. That shift matters because criminals don't need to break through a firewall when they can sign in with a password that was stolen, guessed, phished, or purchased online.

STACK Cybersecurity created the Password Reset series to help business leaders, IT teams, and employees understand how credentials are created, stored, protected, and stolen. Each article addresses a different part of password and identity security, from removing passwords saved in browsers to deploying a dedicated business password manager.

Password Security by the Numbers

  • 97% of identity attacks observed by Microsoft involved passwords.
  • Identity attacks increased 32% during the first half of 2025.
  • NIST now recommends passwords of at least 15 characters when passwords are the sole authentication factor.
  • Browser-stored passwords remain a common target of infostealer malware.

Why Password Security Still Matters

Passwords aren't disappearing as quickly as expected. Biometrics, passkeys, security keys, and passwordless authentication are gaining ground, but most companies still rely on passwords for at least some systems. Legacy applications, vendor portals, remote access tools, cloud platforms, and industry-specific software may continue requiring them for years.

This provides criminals a ripe opportunity. According to Microsoft's 2025 Digital Defense Report (PDF), identity-based attacks increased 32% during the first half of 2025, and more than 97 percent of those attacks involved passwords. Many were large-scale attempts to guess passwords or use credentials exposed through previous breaches.

A stolen password can lead to much more than access to one account. Passwords can be used to read email, reset other credentials, impersonate an executive, redirect payments, access customer information, install malware, or move deeper into a business network. Attackers may appear to be legitimate employees because their login credentials are legitimate.

Cybercriminals don't always break in. Often, they sign in. A valid username and password can let a criminal enter through the same login page employees use.

How Business Passwords Are Stolen

Password theft isn't limited to someone guessing an employee's favorite pet or hometown. Criminals use automated tools, deceptive messages, malware, previously breached credentials, and stolen browser data to target business accounts at scale.

Phishing

A phishing message may direct an employee to a convincing copy of a Microsoft 365, banking, payroll, or file-sharing login page. When you enter a username and password, the information is sent to the hacker. Some attacks also attempt to capture multi-factor authentication MFA codes or session information.

Credential Stuffing

Credential stuffing occurs when criminals take usernames and passwords exposed in one breach and test them against other services. The attack works because people frequently reuse the same credentials for personal and business accounts.

Password Spraying

Password spraying reverses the usual guessing strategy. Instead of trying hundreds of passwords against one account, the attacker tests a small number of common passwords against many accounts. This can avoid account lockouts while still finding employees who selected predictable credentials.

Infostealer Malware

Infostealers are designed to collect passwords, browser data, cookies, session tokens, cryptocurrency information, and other sensitive material from an infected device. This can allow an attacker to access an account even when the employee has changed the password or enabled some forms of multi-factor authentication.

Passwords Stored in Web Browsers

Browser password storage is convenient, but it can create unnecessary exposure when a device, browser profile, or synchronized account is compromised. Business credentials may also become mixed with an employee's personal accounts, making secure offboarding and access control more difficult.

Businesses that still permit browser-based password storage should review STACK's step-by-step guide explaining how to remove saved passwords from web browsers.

Business security risks of storing passwords in web browsers, including malware, limited access controls, synchronized data and physical device access

Modern Password Guidance Has Changed

The National Institute of Standards and Technology (NIST) no longer recommends many of the password practices businesses relied on for years. The current emphasis is on creating longer passwords, blocking known compromised passwords, supporting password managers, and avoiding forced periodic changes unless there's evidence the credential has been compromised.

Under current NIST digital identity guidance, a password used as the only authentication factor should contain at least 15 characters. Systems should allow passwords of at least 64 characters and shouldn't impose arbitrary composition rules requiring a specific mixture of uppercase letters, lowercase letters, numbers, and symbols.

NIST also says businesses shouldn't force users to change passwords on an arbitrary schedule. A password should be changed when there's evidence or reasonable suspicion of compromise, when it's been shared improperly, or when access must be revoked.

Modern Password Security Priorities

  • Require long passwords or passphrases.
  • Use a unique password for every account.
  • Block common, expected, and known compromised passwords.
  • Use a dedicated business password manager.
  • Turn on multi-factor authentication.
  • Use phishing-resistant authentication where available.
  • Remove passwords from unmanaged web browsers and spreadsheets.
  • Change passwords when compromise is suspected or confirmed.
  • Disable accounts and revoke access promptly when employees leave.
  • Move toward passkeys and passwordless authentication where systems support them.
  • Make password instruction part of staff onboarding and password removal part of offboarding.

Read New Password Guidance Shifts Toward Simplicity and Security for a closer look at how password policy recommendations have changed.

Long Passwords Better Than Complicated Passwords

Length is one of the most important elements of password strength. A short password containing a capital letter and symbol may still be easier to guess than a much longer passphrase.

For an account you must access without a password manager, a memorable passphrase made from several unrelated words may be easier to remember and harder to guess. It shouldn't use a common expression, song lyric, company slogan, address, family name, or other information someone could associate with you.

When a password manager is available, employees are no longer required to create or memorize passwords. Password managers can generate long, random, unique credentials for every account.

Why Every Business Needs a Password Manager

Employees may need credentials for Microsoft 365, accounting software, human resources systems, customer portals, banking, social media, cloud platforms, vendor accounts, security tools, and industry-specific applications. Expecting someone to remember a different strong password for every service isn't realistic.

A dedicated business password manager creates and stores unique credentials in an encrypted vault. It can also help a company securely share access, assign permissions, remove access when an employee leaves, and reduce the temptation to save passwords in browsers, documents, spreadsheets, chat messages, or email.

STACK Cybersecurity uses and deploys Keeper Security for business password management. Keeper can generate high-strength passwords, support shared team folders, restrict what individual users can view or change, and help companies manage credentials across teams.

For setup instructions, use the Keeper Password Manager Training and Onboarding Guide. The guide explains how to create an account, use the vault, change passwords with KeeperFill, and securely manage business credentials.

Password Managers Don't Replace MFA

Password managers and multi-factor authentication solve different problems. A password manager helps employees create and store unique credentials. Multi-factor authentication requires another form of verification before granting access.

Strong passwords are no longer enough on their own. If a password gets stolen through phishing, malware, or a third-party breach, MFA may stop the criminal from immediately accessing the account.

Not every form of MFA offers the same protection. Text messages and one-time codes are better than relying on a password alone, but they can still be targeted. The Cybersecurity and Information Security Agency (CISA) encourages businesses to move toward phishing-resistant methods, including security keys and properly implemented passkeys.

Learn more in Understanding Multi-Factor Authentication (MFA).

What Are Passkeys?

Passkeys are a newer sign-in method designed to replace passwords. Instead of entering a shared secret that can be guessed or phished, you sign in with a device, biometric check, PIN, or security key. The private credential remains protected on your device or within a secure credential provider.

Passkeys can greatly reduce phishing risk because they're tied to the legitimate website or application. A fake login page can't collect and reuse a passkey the same way it can steal a typed password.

Businesses shouldn't assume they can eliminate every password immediately. A safer approach is to inventory applications, enable passkeys and phishing-resistant MFA where available, maintain secure recovery procedures, and continue protecting passwords for systems that haven't yet made the transition.

How to Build a Better Password Policy

A modern password policy should be specific enough to create consistent behavior without forcing employees into workarounds. It also must cover more than password length.

  • Require unique passwords for every business account.
  • Prohibit sharing passwords through email, text messages, chat, or spreadsheets.
  • Provide a company-approved password manager.
  • Require MFA for email, remote access, financial systems, administrative accounts, and cloud applications.
  • Use phishing-resistant MFA for privileged and high-risk accounts whenever possible.
  • Block known compromised and commonly used passwords.
  • Prohibit saving business passwords in unmanaged browsers.
  • Document how shared and emergency credentials are managed.
  • Review privileged access regularly.
  • Revoke access immediately during offboarding.
  • Define what employees should do when they suspect a credential has been exposed.

Password policy should also connect to the company's incident response plan. Employees need a clear way to report unexpected MFA prompts, suspicious login alerts, phishing messages, account lockouts, or evidence that someone else has accessed an account.

Password Security and Compliance

Password and identity controls frequently appear in cybersecurity standards, customer agreements, cyber insurance applications, and regulatory requirements. The exact requirements depend on the systems, data, contracts, and industry involved.

Companies working toward Cybersecurity Maturity Model Certification (CMMC) or NIST SP 800-171 compliance must address identification and authentication controls, privileged access, account management, and multi-factor authentication. Businesses pursuing SOC 2 must show that access controls are designed, implemented, and operating consistently. Cyber insurance applications may also ask about MFA, password policies, privileged access, employee offboarding, and remote access security.

A written policy alone isn't enough. Auditors, customers, and insurers may expect evidence that controls are followed. That evidence can include account inventories, access reviews, password manager deployment records, MFA settings, offboarding tickets, cybersecurity awareness training, and incident response documentation.

The STACK Password Reset Series

The Password Reset series provides guidance businesses can use to strengthen password and identity security. This page serves as the starting point, while each supporting article explores a specific issue in greater detail.

Frequently Asked Questions (FAQs) About Password Security

How long should a business password be?

Current NIST guidance requires at least 15 characters when a password is used as the only authentication factor. A system may permit a minimum of eight characters when the password is part of a multi-factor authentication process. Businesses should allow much longer passwords and support passphrases and password managers.

Should employees change passwords every 90 days?

Not automatically. NIST advises against arbitrary periodic password changes because employees often respond by creating predictable variations. Passwords should be changed when there's evidence or reasonable suspicion of compromise, when a credential has been shared improperly, or when access must be revoked.

Why is password reuse dangerous?

Password reuse allows one breach to affect multiple accounts. Criminals can take a username and password exposed by one website and test the same combination against email, banking, cloud applications, social media, and business systems.

Are passwords saved in a web browser safe?

Browser password storage may offer some protection, but it usually lacks the business administration, access controls, secure sharing, reporting, and offboarding features of a dedicated business password manager. Synchronized browser accounts and malware-infected devices can also expose stored credentials and session information.

Should a business use a password manager?

Yes. A company-approved password manager helps employees create unique passwords, store them in an encrypted vault, and share access without sending credentials through email or chat. It also improves consistency when employees join, change roles, or leave the company.

Does a password manager eliminate the need for MFA?

No. A password manager protects the creation and storage of credentials. MFA provides another verification step when someone attempts to sign in. Businesses should use both, especially for email, administrative accounts, remote access, financial systems, and sensitive cloud applications.

What is credential stuffing?

Credential stuffing is an automated attack that leverages usernames and passwords stolen from one source to attempt logins on other websites and applications. Unique passwords prevent one exposed credential from unlocking several accounts.

What is password spraying?

Password spraying tests a small number of common or predictable passwords against many user accounts. It can avoid the account lockouts that would occur if an attacker tried hundreds of passwords against one person.

Are passkeys more secure than passwords?

Properly implemented passkeys are generally more resistant to phishing and password guessing because there's no reusable password for an employee to type into a fraudulent website. Businesses still need secure device management, account recovery, access reviews, and offboarding procedures.

Need Help Strengthening Password Security?

STACK Cybersecurity can help your business deploy Keeper Password Manager, remove credentials stored in browsers, implement MFA, review access controls, strengthen employee offboarding, and build a modern password policy.

Start with a Cybersecurity Risk Assessment, call (734) 744-5300, or contact STACK Cybersecurity to discuss password and identity security.

Cybersecurity Consultation

Is your company secure against cyber threats? If you're not sure, it's time for a cybersecurity risk assessment (CSRA). STACK Cybersecurity's CSRA will meticulously identify and evaluate vulnerabilities and risks within your IT environment. We'll assess your network, systems, applications, and devices. You'll get a detailed report and action plan to improve your security posture. Don't wait until it's too late.

Schedule a Consultation Explore our Risk Assessment