Why “change your password every 90 days” was always wrong
The forced quarterly reset felt responsible. In practice it produced Summer2024! and a sticky note, and it made people less safe, not more.
For years the sensible-sounding advice was to force everyone to change their password every ninety days. It felt like diligence. It was, in fact, one of the more counterproductive rules in security, and the people who study this - including the NCSC - now advise against it. We changed our own view on it years ago, and it is worth explaining why, because a lot of businesses still enforce it out of habit.
Here is what forced resets actually produce. Faced with inventing yet another password every three months, people do the only sane thing: they make a small, predictable change. Summer2024 becomes Autumn2024 becomes Winter2024. Or they write the new one on a note under the keyboard. The password gets weaker and more findable with each reset, which is the exact opposite of the intention.
The reason the rule made sense once was speed. If it took months to crack a stolen password, changing it periodically limited the damage. Modern cracking is fast, and modern breaches dump passwords in bulk, so a leaked password is abused within hours or not at all. Rotating it on a calendar does nothing about that. What does something is a long, unique password per account, and a second factor so that a stolen password is not enough on its own.
So our advice is the opposite of the old rule. Use long passphrases, one per important account, kept in a password manager so you never have to remember or reuse them. Turn on two-factor authentication where it matters. And only force a change when there is a reason to - a suspected breach, a shared password, someone leaving. Change for a reason, not for the calendar.
- ✓Stop forcing password changes on a fixed schedule with no reason behind it.
- ✓Use long passphrases, one per account, stored in a password manager.
- ✓Turn on two-factor authentication for email, banking and anything that matters.
- ✓Change a password immediately when there is a real trigger: a breach, sharing, a leaver.
- Password policy: updating your approach NATIONAL CYBER SECURITY CENTRE ↗
- Cyber Aware: use a strong and separate password GOV.UK ↗
- Why forced password expiry does more harm than good THE REGISTER ↗
Links open each publisher’s live coverage of this topic.