Forcing password changes every 90 days is no longer recommended by most security bodies — it tends to produce weaker, more predictable passwords, not stronger ones. A few things matter more.
Length beats complexity
A long passphrase (four unrelated words strung together) is harder to crack than a short, symbol-heavy password, and easier for people to actually remember.
A password manager, not a spreadsheet
If staff are reusing passwords across systems, it's almost always because remembering unique ones is genuinely hard. A password manager removes that tradeoff entirely — one strong master password protects everything else.
Check for exposure, don't guess
Free tools exist to check whether an email address has appeared in a known data breach. If it has, any password used with that account elsewhere should be assumed compromised.
MFA covers the rest
Even a reused or guessed password isn't enough to get in if multifactor authentication is required — see why MFA is the highest-leverage fix you can make.
Good password habits are less about strict rules and more about removing the reasons people cut corners in the first place.

