Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
OPINION 23 JUN 2026 · 3 MIN

Why “change your password every 90 days” was always wrong

The forced quarterly reset felt responsible. In practice it produced Summer2024! and a sticky note, and it made people less safe, not more.

TOMOS BEVAN · FOUNDER
SHARE LinkedIn X Email
OPINION cover image

For years the sensible-sounding advice was to force everyone to change their password every ninety days. It felt like diligence. It was, in fact, one of the more counterproductive rules in security, and the people who study this - including the NCSC - now advise against it. We changed our own view on it years ago, and it is worth explaining why, because a lot of businesses still enforce it out of habit.

Here is what forced resets actually produce. Faced with inventing yet another password every three months, people do the only sane thing: they make a small, predictable change. Summer2024 becomes Autumn2024 becomes Winter2024. Or they write the new one on a note under the keyboard. The password gets weaker and more findable with each reset, which is the exact opposite of the intention.

The reason the rule made sense once was speed. If it took months to crack a stolen password, changing it periodically limited the damage. Modern cracking is fast, and modern breaches dump passwords in bulk, so a leaked password is abused within hours or not at all. Rotating it on a calendar does nothing about that. What does something is a long, unique password per account, and a second factor so that a stolen password is not enough on its own.

So our advice is the opposite of the old rule. Use long passphrases, one per important account, kept in a password manager so you never have to remember or reuse them. Turn on two-factor authentication where it matters. And only force a change when there is a reason to - a suspected breach, a shared password, someone leaving. Change for a reason, not for the calendar.

WHAT TO DO
  • ✓Stop forcing password changes on a fixed schedule with no reason behind it.
  • ✓Use long passphrases, one per account, stored in a password manager.
  • ✓Turn on two-factor authentication for email, banking and anything that matters.
  • ✓Change a password immediately when there is a real trigger: a breach, sharing, a leaver.