If your business still makes everyone change their password every 90 days, you're following advice that the security industry itself has moved away from.

Passwords, MFA, and Why Frequent Changes Do More Harm Than Good

That's not a dig. It was the standard for years. But the evidence is clear: forced password rotation makes things worse, not better. Here's what's changed and what to do instead.

Why Forced Password Changes Backfired

The logic seemed sound: if a password gets stolen, regular changes limit how long an attacker can use it. In practice, it created a different problem entirely.

When people have to change their password every few months, they do predictable things. They pick a base word and add a number - Summer2025 becomes Summer2026. They reuse the same password across systems with tiny variations. They write them on sticky notes. The constant churn doesn't produce stronger passwords - it produces weaker ones that follow obvious patterns.

This isn't just opinion. The major security bodies - including Australia's own Cyber Security Centre - now explicitly advise against mandatory periodic password changes. The reasoning is simple: forced rotation leads to predictable behaviour that's easier to exploit than a strong password that stays put.

What Actually Makes a Password Strong

The shift is simpler than you'd think:

  • Length matters more than complexity. A passphrase like correct-horse-battery-staple is dramatically harder to crack than P@ssw0rd! - and much easier to remember. Longer is stronger.
  • Only change it when there's a reason. No sign of trouble? Leave it alone. Suspected breach? Change it immediately.
  • Check against known breaches. New passwords should be screened against databases of previously stolen credentials. If someone picks a password that's already been exposed in a data breach, it should be blocked.
  • Use a password manager. Nobody can remember unique, strong passwords for dozens of accounts. Give your team a proper tool for this - don't leave it up to individuals.

Multi-Factor Authentication: The Biggest Win Available

If you only do one thing after reading this, turn on multi-factor authentication (MFA) everywhere you can.

MFA means that even if a password is stolen, the attacker still can't get in without a second step - usually a prompt on your phone or a code from an app. It's like having a deadlock as well as your front door handle.

The data on this is striking: MFA blocks over 99% of automated account attacks. You go from being an easy target to not being worth the effort.

Most of the services you already use support MFA - Microsoft 365, Google Workspace, Xero, your accounting software. It's usually just a matter of turning it on. The initial adjustment takes a day or two and then it's second nature.

One tip: an authenticator app on your phone (like Microsoft Authenticator) is more secure than getting a code via text message. It's the same amount of effort to set up, so go with the app if you have the choice.

Where This Is All Heading

The long-term direction is removing passwords entirely. It's already happening - you may have noticed websites and apps letting you log in with your fingerprint or face instead of typing a password.

These "passkeys" work by using the security built into your device (fingerprint reader, face recognition) to verify it's you. There's no password to remember, steal, or trick you into entering on a fake website.

Apple, Google, and Microsoft have all built this into their platforms. For most businesses, it's not something you need to rush into - but it's worth knowing it's coming and that it's both more secure and more convenient than passwords.

What to Do About It

You don't need to overhaul everything at once. A practical sequence:

  1. Stop enforcing regular password changes. Update your policy so passwords only change when there's a reason. This is a policy change, not a technology project.
  2. Turn on MFA everywhere. Start with email - it's the key to everything else. Then expand to your other business applications.
  3. Roll out a password manager. Give your team a proper tool for managing their logins. This stops password reuse and makes strong, unique passwords easy.
  4. Keep an eye on passwordless. As your tools start supporting fingerprint and face login, encourage your team to try it.

The Bigger Picture

The shift away from password-heavy security reflects a more honest understanding of how people behave. The old model assumed everyone would diligently juggle dozens of complex, frequently changing passwords. They didn't - and the workarounds were entirely predictable.

The current approach works with human nature rather than against it. Fewer passwords to remember, a second step that's hard to fake, and eventually no passwords at all. Better security, less hassle for your team.

Interested? Let's talk.

No pressure, no jargon - leave your details and we'll be in touch.

Protected by reCAPTCHA - Privacy & Terms