A strong password in 2026 is long, unique to one account, stored in a password manager and backed by multi-factor authentication. The old rules, like forcing symbols, swapping letters for numbers and changing passwords every 90 days, are no longer recommended by NIST, the federal agency that sets the standard. Here are the seven steps that actually protect your business, and the old habits to drop.
What most businesses don't realize is that their password policy was probably written around rules that have since been retired. "P@$$w0rd1!" passes every complexity check and gets cracked in seconds, because attackers know exactly how people swap letters for symbols. The current guidance is simpler, and it's easier on your team.
Key takeaways
Length is the single biggest factor in how hard a password is to crack. NIST's current Digital Identity Guidelines (SP 800-63B, revision 4) say passwords used as a single factor "SHALL" be at least 15 characters, and systems "SHOULD" allow at least 64.
The easiest way to get there is a passphrase: four or five random, unrelated words. maple kayak ledger thunder is long, easy to type and far harder to guess than Tr0ub4dor!. Pick words at random, not a quote, song lyric or anything tied to you.
Swapping an "a" for "@" or tacking "!" on the end feels secure, but cracking tools try those substitutions first. NIST now says systems "SHALL NOT" force composition rules like requiring a mix of character types. You can still use symbols. They just aren't what makes a password strong. Length and randomness are.
When a website you signed up for years ago gets breached, attackers take that email and password and try it everywhere else: your Microsoft 365 account, your bank, your practice management software. If every account has its own password, a breach stays contained to the one site that was breached.
No one can remember dozens of unique 15-character passwords. That's what Step 6 is for.
The 90-day reset was supposed to limit damage from stolen passwords. In practice people cycled through Summer2025!, Fall2025!, Winter2025!, which attackers predict easily. NIST now says systems "SHALL NOT" require periodic password changes, but "SHALL" force a change when there's evidence a password has been compromised.
If your IT provider still enforces 90-day resets, it's worth asking why.
Instead of arbitrary resets, check whether a password is already known to attackers. NIST requires comparing new passwords against a blocklist of "commonly used, expected, or compromised passwords." For a business, that means dark web monitoring that alerts you when an employee's credentials show up in a breach, so you change that password right away instead of on a calendar.
A password manager generates a long, random password for every account, stores it in an encrypted vault and fills it in automatically. Your team remembers one strong master password. Everything else is handled for them.
We use Keeper at Four Winds IT and roll it out for our clients. Keeper is zero-knowledge: its documentation states that "encryption and decryption of data always occurs locally on the user's device," and that Keeper "cannot decrypt customer data." For a business, the bigger wins are shared folders for team logins, instant access removal when someone leaves, and reporting that shows who still has weak or reused passwords.
Weighing whether a password manager is worth it? Our honest pros and cons of password managers covers the trade-offs.
Even a perfect password can be phished. Multi-factor authentication means a stolen password alone isn't enough to get in. Our guide to multi-factor authentication walks through the options.
The next step is passkeys, which replace the password entirely with a credential stored on your device and unlocked with your face, fingerprint or PIN. Microsoft calls passwords "the primary attack vector for modern adversaries" and recommends phishing-resistant passwordless sign-in such as Windows Hello for Business and passkeys. Most businesses can start with passkeys for Microsoft 365 today and phase them in elsewhere as apps support them.
Here's the policy we recommend for a 20 to 75 person business, based on NIST's current guidance:
| Rule | Old policy | What to do now |
|---|---|---|
| Length | 8 characters minimum | 15+ characters, or 8+ only where MFA is required |
| Complexity | Must include a symbol, number and capital | No forced character rules. Block common and breached passwords instead |
| Expiration | Change every 90 days | Change only when there's evidence of compromise |
| Storage | Memory, sticky notes, spreadsheets | A business password manager for everyone |
| Recovery | Password hints and security questions | No hints or security questions. Verified reset through IT |
| Second factor | Optional | MFA required on email, remote access and admin accounts, with passkeys where supported |
This lines up with the "Insured" tier of our cybersecurity framework: a password manager, MFA and security awareness training are the controls cyber insurance carriers ask about. Not sure where your business lands? Take our cybersecurity tier quiz.
At least 15 characters for any password used on its own, per NIST SP 800-63B revision 4. Passwords used alongside multi-factor authentication can be as short as 8 characters, but longer is still better. A passphrase of four or five random words is the easiest way to get there.
No. NIST says systems should not force rules like requiring a mix of uppercase, numbers and symbols. Those rules push people toward predictable patterns like "P@ssw0rd1!" Length and uniqueness matter far more.
No. NIST says organizations should not require periodic password changes, and should force a change only when there's evidence a password has been compromised. Scheduled resets lead to weaker, predictable passwords.
A business password manager with zero-knowledge encryption, like Keeper, is far safer than reused passwords or spreadsheets. Your vault is encrypted on your own device, the provider can't read it, and it should be protected with a strong master password and MFA.
A passkey replaces a password with a cryptographic credential stored on your device and unlocked with your face, fingerprint or PIN. It can't be phished or reused, and Microsoft 365 supports passkeys through Windows Hello for Business and the Microsoft Authenticator app.
Change that password immediately on every account it was used for, confirm MFA is turned on, and review recent sign-ins for anything unusual. Dark web monitoring in a business password manager can alert you automatically when this happens.
We get it. Changing how 50 people log in sounds like a week of help desk tickets. It doesn't have to be. Four Winds IT sets up Keeper, turns on MFA, updates your password policy and trains your team, with local engineers who answer the phone when someone gets stuck.
See how our business password management works, or talk to our team about your current setup.