For twenty years we forced staff to invent things like "P@ssw0rd1!" and change them every 90 days. The result: predictable patterns, passwords on sticky notes, and the same "complex" password reused on twelve sites. Modern guidance — from the ACSC and its international peers — has quietly reversed almost all of it.
What actually makes a password strong
Length. A four-word passphrase like "paddock-lantern-cricket-vivid" is both far stronger against cracking and far easier to remember than "Tr0ub4d0r!". Complexity rules mostly produce human-predictable substitutions that cracking tools try first. Aim for 14+ characters, and reserve your best, unique passphrases for the accounts that matter most.
Stop forcing rotation, start banning reuse
Scheduled password changes push people toward incremental patterns (Winter2025 → Winter2026) that attackers know intimately. Change passwords when there’s a reason — a breach, a departure, a suspicion — not on a calendar. The real enemy is reuse: one leaked password shouldn’t open five systems. That’s a policy you can’t enforce with rules, only with tooling.
The tooling: a team password manager
- Every account gets a unique, generated password nobody has to remember.
- Shared logins (the office Wi-Fi, the supplier portal) live in shared vaults instead of a spreadsheet called passwords.xlsx.
- Offboarding becomes real: remove one person, rotate what they touched, done.
- Combined with MFA, this closes the credential attack path almost completely.
A business-tier password manager costs a few dollars per user per month. Compared to the incident it prevents — and the hours staff burn on resets — it’s one of the clearest wins in all of security.
Want help with this in your business?
Book a free security check with our Sydney team — plain-English advice, no obligation.
Get a Free Security Check