Why Modern Password Security Is Simpler Than You Think

For years, password security advice followed the same familiar formula: use at least eight characters, include uppercase and lowercase letters, add a number, throw in a special character, and change it every 90 days.

The problem is that those rules were designed for a very different threat landscape.

Today, organisations such as NIST, CISA, and Microsoft's identity security teams recommend a different approach. The focus has shifted away from complexity and frequent password changes and toward something far more effective: long passwords, password screening, and multi-factor authentication (MFA).

Length Beats Complexity

Many businesses still believe that a password like P@ssw0rd01! is secure because it contains uppercase letters, lowercase letters, numbers, and symbols. Unfortunately, attackers know these patterns just as well as users do.

Modern password-cracking tools are incredibly efficient at testing common password formats. An eight-character password, even one that meets traditional complexity requirements, can often be cracked in a very short period of time when exposed in an offline attack.

A 16-character passphrase, on the other hand, dramatically increases the amount of work required. Every additional character expands the possible combinations an attacker must try. That's why a passphrase such as:

river-coffee-mountain-sunrise

is typically far more resistant to attack than a short, complex password packed with special characters.

In password security, length provides exponential protection, while complexity offers only incremental gains.

The Hidden Problem with Mandatory Password Rotation

One of the biggest changes in modern security guidance is the recommendation to stop forcing routine password changes.

At first glance, password rotation seems logical. If users change passwords every 60 or 90 days, attackers have less time to exploit a compromised credential.

In practice, however, mandatory rotation often creates new security problems.

When users are required to change passwords on a fixed schedule, they tend to choose predictable variations of their existing password:

  • Winter2024!
  • Winter2025!
  • Winter2026!
  • Password01!
  • Password02!
  • Password03!

These patterns are easy for attackers to anticipate and significantly reduce the security benefit of the change. Instead of creating stronger passwords, forced rotation frequently encourages users to make the smallest possible modification needed to satisfy policy requirements.

It also leads to behavioural workarounds that weaken security overall:

  • Writing passwords on sticky notes
  • Saving passwords in unsecured documents
  • Reusing passwords across multiple systems
  • Choosing shorter, easier-to-remember passwords

In many environments, forced password changes generate a large volume of help desk calls and user frustration while delivering very little measurable security improvement.

This is why modern guidance recommends changing passwords when there is evidence of compromise, suspicious activity, or a known breach, rather than on an arbitrary calendar schedule.

Complexity Rules Often Work Against Security

Traditional complexity requirements were intended to prevent users from choosing weak passwords.

Unfortunately, users respond predictably.

When told they must have one uppercase letter, one number, and one special character, most people create passwords that follow nearly identical structures:

  • CompanyName1!
  • Welcome1!
  • Spring2026!

Attackers know these patterns and build them directly into cracking dictionaries and password-spraying tools.

By enforcing complexity, organisations often push users toward predictable behaviour rather than genuinely strong passwords.

A better approach is to encourage longer passwords and passphrases that are memorable for users but difficult for attackers to guess.

What Your Password Policy Should Look Like Today

If you're reviewing your organisation's password standards, the update is surprisingly simple:

  • Set a minimum password length of 14 characters for general user accounts.
  • Require 16 characters or more for privileged, administrative, or sensitive accounts.
  • Eliminate mandatory password rotation requirements.
  • Remove traditional complexity requirements where possible.
  • Block passwords that appear in known breach databases or banned password lists.
  • Require MFA for every system and account that supports it.
  • Monitor for compromised credentials and trigger password resets only when risk is identified.

This approach improves security while reducing user frustration and administrative overhead.

Easier for Users, Harder for Attackers

Cybersecurity doesn't have to mean making life harder for your employees.

The strongest password policies today are often the simplest. Long passwords are easier for people to remember, harder for attackers to crack, and far more effective than the complexity-and-rotation rules many organisations still enforce.

If your business is still relying on eight-character passwords with quarterly rotation, you're effectively following security guidance from 2010.

The good news is that modern password standards are both more secure and more user-friendly. That's a rare win-win in cybersecurity.

Focus on length. Block known-bad passwords. Enable MFA. Everything else is secondary.

Need help with your IT? TechMan provides friendly, expert IT support for homes and small businesses across the Kฤpiti Coast, Wellington and Levin.

Get in Touch โ†’