All resources

16 February 2026 · Guide · CyberSec360 Australia

Passwords: Length Beats Complexity (and Managers Beat Memory)

For twenty years we forced staff to invent things like "P@ssw0rd1!" and change them every 90 days. The result: predictable patterns, passwords on sticky notes, and the same "complex" password reused on twelve sites. Modern guidance — from the ACSC and its international peers — has quietly reversed almost all of it.

What actually makes a password strong

Length. A four-word passphrase like "paddock-lantern-cricket-vivid" is both far stronger against cracking and far easier to remember than "Tr0ub4d0r!". Complexity rules mostly produce human-predictable substitutions that cracking tools try first. Aim for 14+ characters, and reserve your best, unique passphrases for the accounts that matter most.

Stop forcing rotation, start banning reuse

Scheduled password changes push people toward incremental patterns (Winter2025 → Winter2026) that attackers know intimately. Change passwords when there’s a reason — a breach, a departure, a suspicion — not on a calendar. The real enemy is reuse: one leaked password shouldn’t open five systems. That’s a policy you can’t enforce with rules, only with tooling.

The tooling: a team password manager

  • Every account gets a unique, generated password nobody has to remember.
  • Shared logins (the office Wi-Fi, the supplier portal) live in shared vaults instead of a spreadsheet called passwords.xlsx.
  • Offboarding becomes real: remove one person, rotate what they touched, done.
  • Combined with MFA, this closes the credential attack path almost completely.

A business-tier password manager costs a few dollars per user per month. Compared to the incident it prevents — and the hours staff burn on resets — it’s one of the clearest wins in all of security.

Want help with this in your business?

Book a free security check with our Sydney team — plain-English advice, no obligation.

Get a Free Security Check