Most password rules were written for a world where people had five accounts. Staff now have dozens, and the old advice of complex passwords changed every few months produces sticky notes and reused passwords.

What matters now

Length matters more than complexity. A long passphrase is stronger and easier to remember than a short jumble of symbols. Uniqueness matters most: a password used on two sites is only as safe as the weaker site.

Stop forcing regular changes

Current guidance is to change a password when there is reason to think it has been exposed, not on a calendar. Forced changes lead people to predictable patterns.

Give staff a password manager

A business password manager generates and stores a unique password for every account, shares logins between team members without revealing them, and removes access when someone leaves. It is the single most practical fix for password reuse.

Multi-factor authentication is still required

A password alone is not enough for email, finance or remote access. Add an authenticator app, and prefer number matching or passkeys over text message codes, which can be intercepted.

What passkeys are

A passkey replaces the password with a key stored on your phone or laptop, unlocked by your fingerprint, face or PIN. There is nothing to type and nothing a fake website can steal. Microsoft 365 and many business applications now support them.

Shared and service accounts

Find the shared logins: the social media account, the supplier portal, the bank token. Move them into the password manager, give each a named owner and turn on multi-factor authentication wherever the service allows.

When someone leaves

Disable their account, remove them from the password manager and change any shared passwords they knew. A password manager turns that from guesswork into a list.

Want security handled as part of your IT? Managed cybersecurity

All resources