Passwords are the lock on almost every door your business owns, and most of those locks are weaker than people think. The good news is that fixing it doesn’t require memorising gibberish or changing everything every 30 days. The modern approach is actually easier than what most people do now.
Why passwords keep failing
Three habits cause most of the damage:
- Reuse. One password across many sites means one leak unlocks everything. Attackers take passwords stolen from some unrelated website and simply try them everywhere else. It works far too often.
- Predictability. Short passwords, names, and “Password1!” style patterns are trivially guessed by software that tries millions of combinations a second.
- The 30-day change rule. Forcing frequent changes just pushes people toward small, predictable tweaks (Summer2025, Summer2026). Guidance from bodies like the ACSC has moved away from routine forced expiry for exactly this reason.
Passphrases beat passwords
A long passphrase is both stronger and easier to remember than a short complex password. Four or five random words strung together (for example, river-cactus-lantern-koala) is genuinely hard to crack and easy to type. Length is what defeats guessing attacks, far more than swapping an “a” for an “@”.
Use a passphrase for the few accounts you must type from memory, such as your device login and your password manager.
Let a password manager do the work
For everything else, stop trying to remember passwords at all. A password manager generates a long, unique, random password for every account and fills it in for you. You remember one strong passphrase; it remembers the hundreds of others.
The benefits compound quickly:
- Every account gets a unique password, so one leak can’t cascade.
- Passwords can be long and random because you never type them.
- Most managers warn you if a saved password appears in a known breach.
- Onboarding and offboarding staff becomes far cleaner with a business plan and shared vaults.
Reputable options include 1Password and Bitwarden, among others. For a business, a team plan is well worth the small per-user cost.
Pair it with MFA
A password manager plus multi-factor authentication is the one-two punch. Even in the rare event a password is exposed, MFA stops the login. Turn MFA on for your manager itself and for every important account.
What to do this week
- Pick a password manager and roll it out (start with your own accounts, then the team).
- Set a strong passphrase for your device and your manager.
- Turn on MFA everywhere it’s offered.
- Stop forcing 30-day password changes; change passwords when there’s a reason to, not on a timer.
Want a hand choosing and rolling out a password manager across your team, cleanly and securely? Get in touch and we’ll make it painless.