Skip to main content
CybersecurityArticleBeginner2 min readUpdated

Password Habits That Actually Hold Up

Most password advice is outdated. Here's what actually reduces risk, without making staff dread every login.

Written by

Zach Swartz, Business Technology Advisor

Zach Swartz

Business Technology Advisor · Great Falls, Montana

Forcing password changes every 90 days is no longer recommended by most security bodies — it tends to produce weaker, more predictable passwords, not stronger ones. A few things matter more.

Length beats complexity

A long passphrase (four unrelated words strung together) is harder to crack than a short, symbol-heavy password, and easier for people to actually remember.

Short and symbol-heavyTr0ub4dor&311 characters · hard to remember, so it gets reusedFour unrelated wordsriver-cabin-quartz-lantern25 characters · one phrase, easy to recall
Length is what makes a credential expensive to crack, and the longer of these two is the one people can actually remember.

A password manager, not a spreadsheet

If staff are reusing passwords across systems, it's almost always because remembering unique ones is genuinely hard. A password manager removes that tradeoff entirely — one strong master password protects everything else.

Check for exposure, don't guess

Free tools exist to check whether an email address has appeared in a known data breach. If it has, any password used with that account elsewhere should be assumed compromised.

MFA covers the rest

Even a reused or guessed password isn't enough to get in if multifactor authentication is required — see why MFA is the highest-leverage fix you can make.

Good password habits are less about strict rules and more about removing the reasons people cut corners in the first place.

Not sure where your organization stands?

The Business Success Assessment covers this topic and more, with results in about 7–10 minutes.