Business IT, AI, & Cybersecurity Blog | Four Winds IT

The Password Guide: 7 Steps To Creating Unhackable Passwords

Written by Dylan Borden | Apr 11, 2025, 4:00:00 PM

A strong password in 2026 is long, unique to one account, stored in a password manager and backed by multi-factor authentication. The old rules, like forcing symbols, swapping letters for numbers and changing passwords every 90 days, are no longer recommended by NIST, the federal agency that sets the standard. Here are the seven steps that actually protect your business, and the old habits to drop.

What most businesses don't realize is that their password policy was probably written around rules that have since been retired. "P@$$w0rd1!" passes every complexity check and gets cracked in seconds, because attackers know exactly how people swap letters for symbols. The current guidance is simpler, and it's easier on your team.

Key takeaways

  • Length beats complexity. NIST now requires at least 15 characters for a password used on its own, and at least 8 when it's paired with MFA.
  • Mandatory symbol and number rules are out. So are scheduled password changes. Change a password when there's evidence it's been compromised.
  • Every account gets its own password. Reuse is how one breach turns into five.
  • A business password manager makes all of this realistic for a whole team, and MFA (or a passkey) protects you when a password leaks anyway.

Step 1: Go long, at least 15 characters

Length is the single biggest factor in how hard a password is to crack. NIST's current Digital Identity Guidelines (SP 800-63B, revision 4) say passwords used as a single factor "SHALL" be at least 15 characters, and systems "SHOULD" allow at least 64.

The easiest way to get there is a passphrase: four or five random, unrelated words. maple kayak ledger thunder is long, easy to type and far harder to guess than Tr0ub4dor!. Pick words at random, not a quote, song lyric or anything tied to you.

Step 2: Skip the symbol tricks

Swapping an "a" for "@" or tacking "!" on the end feels secure, but cracking tools try those substitutions first. NIST now says systems "SHALL NOT" force composition rules like requiring a mix of character types. You can still use symbols. They just aren't what makes a password strong. Length and randomness are.

Step 3: Never reuse a password

When a website you signed up for years ago gets breached, attackers take that email and password and try it everywhere else: your Microsoft 365 account, your bank, your practice management software. If every account has its own password, a breach stays contained to the one site that was breached.

No one can remember dozens of unique 15-character passwords. That's what Step 6 is for.

Step 4: Stop forced 90-day resets

The 90-day reset was supposed to limit damage from stolen passwords. In practice people cycled through Summer2025!, Fall2025!, Winter2025!, which attackers predict easily. NIST now says systems "SHALL NOT" require periodic password changes, but "SHALL" force a change when there's evidence a password has been compromised.

If your IT provider still enforces 90-day resets, it's worth asking why.

Step 5: Check passwords against breach lists

Instead of arbitrary resets, check whether a password is already known to attackers. NIST requires comparing new passwords against a blocklist of "commonly used, expected, or compromised passwords." For a business, that means dark web monitoring that alerts you when an employee's credentials show up in a breach, so you change that password right away instead of on a calendar.

Step 6: Use a business password manager

A password manager generates a long, random password for every account, stores it in an encrypted vault and fills it in automatically. Your team remembers one strong master password. Everything else is handled for them.

We use Keeper at Four Winds IT and roll it out for our clients. Keeper is zero-knowledge: its documentation states that "encryption and decryption of data always occurs locally on the user's device," and that Keeper "cannot decrypt customer data." For a business, the bigger wins are shared folders for team logins, instant access removal when someone leaves, and reporting that shows who still has weak or reused passwords.

Weighing whether a password manager is worth it? Our honest pros and cons of password managers covers the trade-offs.

Step 7: Put MFA on top, and move to passkeys where you can

Even a perfect password can be phished. Multi-factor authentication means a stolen password alone isn't enough to get in. Our guide to multi-factor authentication walks through the options.

The next step is passkeys, which replace the password entirely with a credential stored on your device and unlocked with your face, fingerprint or PIN. Microsoft calls passwords "the primary attack vector for modern adversaries" and recommends phishing-resistant passwordless sign-in such as Windows Hello for Business and passkeys. Most businesses can start with passkeys for Microsoft 365 today and phase them in elsewhere as apps support them.

What should your business password policy say?

Here's the policy we recommend for a 20 to 75 person business, based on NIST's current guidance:

Rule Old policy What to do now
Length8 characters minimum15+ characters, or 8+ only where MFA is required
ComplexityMust include a symbol, number and capitalNo forced character rules. Block common and breached passwords instead
ExpirationChange every 90 daysChange only when there's evidence of compromise
StorageMemory, sticky notes, spreadsheetsA business password manager for everyone
RecoveryPassword hints and security questionsNo hints or security questions. Verified reset through IT
Second factorOptionalMFA required on email, remote access and admin accounts, with passkeys where supported

This lines up with the "Insured" tier of our cybersecurity framework: a password manager, MFA and security awareness training are the controls cyber insurance carriers ask about. Not sure where your business lands? Take our cybersecurity tier quiz.

Frequently asked questions

How long should a password be in 2026?

At least 15 characters for any password used on its own, per NIST SP 800-63B revision 4. Passwords used alongside multi-factor authentication can be as short as 8 characters, but longer is still better. A passphrase of four or five random words is the easiest way to get there.

Do passwords still need special characters?

No. NIST says systems should not force rules like requiring a mix of uppercase, numbers and symbols. Those rules push people toward predictable patterns like "P@ssw0rd1!" Length and uniqueness matter far more.

Should we make employees change passwords every 90 days?

No. NIST says organizations should not require periodic password changes, and should force a change only when there's evidence a password has been compromised. Scheduled resets lead to weaker, predictable passwords.

Is it safe to keep all our passwords in a password manager?

A business password manager with zero-knowledge encryption, like Keeper, is far safer than reused passwords or spreadsheets. Your vault is encrypted on your own device, the provider can't read it, and it should be protected with a strong master password and MFA.

What is a passkey?

A passkey replaces a password with a cryptographic credential stored on your device and unlocked with your face, fingerprint or PIN. It can't be phished or reused, and Microsoft 365 supports passkeys through Windows Hello for Business and the Microsoft Authenticator app.

What should we do if an employee's password shows up in a breach?

Change that password immediately on every account it was used for, confirm MFA is turned on, and review recent sign-ins for anything unusual. Dark web monitoring in a business password manager can alert you automatically when this happens.

Want help rolling this out?

We get it. Changing how 50 people log in sounds like a week of help desk tickets. It doesn't have to be. Four Winds IT sets up Keeper, turns on MFA, updates your password policy and trains your team, with local engineers who answer the phone when someone gets stuck.

See how our business password management works, or talk to our team about your current setup.

Sources