Skip to content
Eudora Technology
Home  / Insights
Cybersecurity

Modern Password Security: New Rules That Actually Work

Netgear FVS336G network appliance inside, revealing JTAG interface.
Photo: Netgear ProSafe Dual WAN VPN Gigabit Firewall FVS336G JTAG interface by Zuzu, CC BY-SA 3.0, via Wikimedia Commons

Stop making people change their passwords every 90 days, stop demanding a capital letter and a symbol, and start requiring length plus a check against known-breached passwords. That is not a loosening of standards. It is what the current NIST guidance actually says, and it produces stronger passwords because it stops fighting the way people behave.

Netgear FVS336G network appliance inside.
The password rules most businesses still enforce were designed for a threat model that stopped being accurate about fifteen years ago.Photo: Netgear ProSafe Dual WAN VPN Gigabit Firewall FVS336G inside by Zuzu, CC BY-SA 3.0, via Wikimedia Commons

What NIST changed, and why it matters to you

NIST finalised revision 4 of SP 800-63B in August 2025. It is a US federal standard for digital authentication, but it has become the de facto reference everywhere, partly because auditors cite it and partly because it is one of the few documents in this field that shows its reasoning. If someone in your business insists on 90-day rotation because “compliance requires it”, this is the document that says otherwise.

The core requirements are short enough to summarise accurately. Verifiers must require at least 15 characters for a password that is the only authentication factor, and may allow as few as eight when the password sits inside a multi-factor process. They should accept at least 64 characters so passphrases work, should accept every printing ASCII character plus the space, and should accept Unicode. They must not impose composition rules. They must not require periodic changes, though they must force a change if there is evidence the credential has been compromised. They must not store password hints that an unauthenticated visitor can read, and must not use knowledge-based questions such as a first pet’s name.

NIST SP 800-63B-4 password length rules, in characters
Minimum when part of multi-factor sign-in8
Minimum when the password stands alone15
Maximum length verifiers should accept64
Source: NIST SP 800-63B-4, Password Verifiers requirements.

Read that chart as a pair of thresholds rather than a target. Eight characters is only acceptable because something else is also protecting the account. Fifteen is the floor when nothing else is. And the 64-character ceiling exists so that nobody has to shorten a passphrase to fit a badly written form.

The five rules that are now officially wrong

The five habits below are not merely out of fashion. Each is contradicted by a specific requirement in the current guidance, which is worth knowing when you have to defend the change to a sceptical colleague.

Old habitWhat the current guidance saysWhy it changed
Change every 60 or 90 daysVerifiers SHALL NOT require periodic changesRotation produces predictable increments and more reuse, not better passwords
Must contain upper case, a number and a symbolVerifiers SHALL NOT impose composition rulesUsers answer rules predictably: password becomes Password1, then Password1 plus a symbol
Maximum 12 or 16 charactersVerifiers SHOULD accept at least 64 charactersShort caps block passphrases, which are the easiest strong option to remember
Block spaces and unusual charactersAll printing ASCII and the space character SHOULD be acceptedArbitrary restrictions shrink the keyspace and frustrate password managers
Security questions as a recovery routeVerifiers SHALL NOT prompt for knowledge-based authenticationThe answers are usually public, guessable, or already in a previous breach
Requirements paraphrased from NIST SP 800-63B-4, Sections 3.1.1 and following.

NIST sets out the reasoning in its appendix on password strength, and the example it uses is the honest one: a user who would have chosen “password” will choose “Password1” when told to add a capital and a digit. The guidance concludes that blocklists, properly hashed storage, machine-generated random passwords and rate limiting do more against modern brute-force attacks than any amount of composition rule, so no further requirements are imposed. The published document is worth keeping a link to for exactly those conversations.

Length instead of complexity

Length is the only password property that reliably costs an attacker more. Complexity rules add a handful of bits and a lot of resentment. Four unrelated words give you something memorable that is long enough to be expensive to crack, which is why passphrases keep winning in practice.

The attack this defends against is not a hacker typing guesses. Microsoft’s Digital Defense Report for 2025 found that more than 97% of identity attacks are mass password-guessing attempts, and that identity-based attacks rose 32% in the first half of 2025 alone. That is automation at enormous scale, working through lists of common passwords and credentials from previous breaches. Length and uniqueness are what take you off those lists.

Why passwords alone keep failing
Identity attacks that are mass password guessing (Microsoft, 2025)over 97%
Breaches involving credential abuse (Verizon 2026 DBIR)13%
Ransomware victims whose credential leak fell within 95 days of the attack50%
Sources: Microsoft Digital Defense Report 2025; Verizon 2026 DBIR.

Credential abuse has actually fallen in the DBIR rankings, to 13% of breaches, and Verizon is transparent that part of that drop comes from reclassifying some cases as pretexting; without that change the figure would have been 16%. Either way it is still a top-three route in. Falling out of first place is not the same as being solved.

Netgear FVS336G network appliance being opened.
Perimeter controls do not help when the attacker signs in with a password that was already for sale.Photo: Netgear ProSafe Dual WAN VPN Gigabit Firewall FVS336G opening by Zuzu, CC BY-SA 3.0, via Wikimedia Commons

Screen against passwords that have already leaked

The single highest-value change you can make to a password policy is to check new passwords against a list of credentials that have already appeared in breaches, and to reject the matches. NIST requires verifiers to compare prospective passwords against a blocklist of unacceptable values, and notes the list does not need to be enormous: its job is to stop the very common choices that an online attack would try before rate limiting kicks in.

Two practical routes. If you run Microsoft Entra ID, turn on the banned password list and add your own terms: your company name, your product names, your town, your sports team. If you want a broader check, Pwned Passwords exposes a free API that lets you test a password against billions of breached credentials without ever sending the password itself, using a k-anonymity range query. OWASP’s authentication cheat sheet covers the implementation detail if you are building this into your own application.

What to put on your own blocklist
  • Your company and product names, with and without digits appended.
  • Your town, your street and your office building.
  • The current year and the two either side of it.
  • Anything a new starter sees on the office wall in their first hour.

The password manager is the enabling control

You cannot ask people to hold 60 long unique passwords in their head. A password manager is the control that makes the rest of the policy possible, and it is cheap enough that the argument is usually about change rather than money.

PlanList priceBilling basis
Bitwarden TeamsUSD 4.00 per user per monthBilled annually
Bitwarden EnterpriseUSD 6.00 per user per monthBilled annually
1Password Teams Starter PackUSD 24.95 per monthIncludes 10 members, paid annually
1Password BusinessUSD 8.99 per user per monthBilled annually
List prices taken from each vendor’s own pricing page on 1 October 2026. Prices change, so check before you budget.

For a ten-person business the starter tiers come in around USD 25 to USD 40 a month. Measured against the help-desk time a rotation policy consumes, it pays for itself inside a quarter. The features worth caring about are shared vaults with role-based access, a report showing reused and breached credentials, and clean offboarding when someone leaves.

The password manager is not a convenience purchase. It is the thing that makes a long, unique password per service physically possible.

One rollout note from experience: import people’s existing browser-saved passwords on day one, then run the reuse report, then fix the worst twenty. Starting with a clean vault and good intentions does not survive the second week.

Where passwords still matter in a passkey world

Passkeys are displacing passwords on the accounts that matter most, and that is the right direction. But passwords do not disappear. They remain the recovery path when a device is lost, the only option on older systems, the way service accounts authenticate, and the credential protecting the password manager itself.

So the policy splits. Where a password is backed by a second factor, NIST’s eight-character minimum is defensible and you can concentrate on blocklist screening. Where a password stands alone, treat 15 characters as the hard floor and ask why it is standing alone at all. The accounts in that second group are the ones to migrate first.

That migration order matters more than the policy wording. Our small-business cybersecurity checklist sets out which accounts to prioritise, and the guidance for remote and hybrid teams covers the device side, which is where saved credentials tend to leak from.

The 102d Strategic Signal Battalion (102d SSB), Network Enterprise Center (NEC) – Baumholder held a ribbon cutting ceremony on Smith Barracks, Oct. 17, to mark the successful compl
Service accounts and shared logins are where password policy quietly stops applying, which is exactly why attackers look for them.Photo: 102d SSB completes NETMOD in Baumholder- Enhanced cybersecurity, network performance for DoD operations in USAG Rheinland-Pfalz’s footprint by U.S. Army USAG-RP by Linda Lambiotte, Public domain, via Wikimedia Commons

Service accounts, shared logins and the forgotten credentials

Every business has credentials that no policy covers. The Wi-Fi password printed on a card in reception. The shared login for the courier portal. The database account configured in 2019 by someone who has left. The API key in a configuration file in version control. These are the credentials that turn a minor compromise into a long one, because nobody rotates them and nobody notices when they are used.

The DBIR’s third-party research makes the point at scale: looking inside third-party cloud environments, Verizon found that resolving weak password and excessive permission findings took almost eight months to clear half of them. Eight months is long enough for a leaked credential to be bought, tested and used twice.

  1. Inventory them. One spreadsheet, every non-personal credential, who owns it and where it is stored. This takes an afternoon and is always worse than expected.
  2. Move them into the password manager in a shared vault with named access, rather than in a document, a chat thread or somebody’s memory.
  3. Replace what can be replaced with managed identities, service principals or short-lived tokens that nobody has to remember.
  4. Rotate on departure, not on a schedule. When someone with access to a shared credential leaves, that credential changes the same week.
  5. Scan your repositories for keys and connection strings, and treat anything you find as already public.

A policy you could publish tomorrow

Here is a policy short enough that people will read it. Passwords are at least 15 characters, or at least 12 if the account also requires multi-factor authentication and your identity platform cannot enforce eight sensibly. Passphrases of four or more unrelated words are encouraged. No composition rules. No scheduled expiry. New passwords are screened against a breach list and against a company word list. Every password lives in the company password manager, and a credential is never reused across two services.

Then add the two clauses that do the real work. Any credential known or suspected to be compromised is changed immediately, and the account’s sessions are revoked. And every account that can move money, change DNS or administer the identity platform requires phishing-resistant authentication, not just a password of any length.

The UK survey found password policies are already among the most widely adopted controls, with 96% of large businesses having one, while only 47% of businesses require any form of two-factor authentication. That gap is the whole story. Nearly everyone has a password policy. Fewer than half have the control that makes a leaked password survivable. If you only have budget and attention for one change this quarter, it is not the password policy.

Frequently asked questions

Do we really stop forcing password changes?

Yes, unless there is evidence of compromise. NIST SP 800-63B-4 states that verifiers shall not require periodic changes, and shall force a change when a credential is known or suspected to be compromised. Rotation produces predictable increments like Summer2026, encourages reuse and generates help-desk load. Replace the schedule with breach monitoring and you get a better outcome for less effort.

Is 15 characters not excessive for a normal staff login?

It applies to passwords that stand alone. If the account also requires a second factor, NIST permits a minimum of eight, and most organisations settle somewhere between 12 and 14 with MFA enforced. The point of the 15-character floor is to make single-factor accounts uncomfortable, because they should be.

Which is better, a browser’s built-in password manager or a dedicated one?

A browser manager is much better than reuse and fine for personal use. For a business you want shared vaults with role-based access, a breach and reuse report, admin recovery and clean offboarding, which the dedicated products provide and browsers largely do not. Note too that infostealer malware specifically targets browser-saved credentials.

How do we handle the password manager’s own master password?

Make it long, unique and memorable, never reused anywhere, and protect the account with a second factor, ideally a hardware key. Store the recovery kit offline in a physically secure place. Set up the administrative recovery feature your product offers before anyone needs it, and test it once.

What should we do if a staff password turns up in a breach list?

Revoke the account’s active sessions first, because a valid session survives a password change. Then reset the password, check for new MFA methods and new mail-forwarding rules, and check whether the same password was used anywhere else. If the credential came from an infostealer on a personal device, treat that device as compromised too.

We write and implement password and authentication policy remotely for clients worldwide as part of our cybersecurity services, including breach-list screening, password manager rollout and cleaning up the shared credentials nobody owns. Get in touch with Eudora Technology to talk about your project.

Sources

  1. SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management NIST · August 2025
  2. 2026 Data Breach Investigations Report (19th edition) Verizon Business · 19 May 2026
  3. Microsoft Digital Defense Report 2025 findings Microsoft · January 2026
  4. Business password manager pricing Bitwarden · retrieved 1 October 2026
  5. Business and Teams pricing 1Password · retrieved 1 October 2026
  6. Cyber Security Breaches Survey 2025/2026 UK Department for Science, Innovation and Technology · April 2026
Keep reading

Related insights