Alpha Web Innovations logoAlpha WebInnovations
Back to Insights

Cyber Security

The password rules that quietly make you less safe

Girish Manchanda

Founder, Alpha Web Innovations · 7 Aug 2026 · 2 min read

A lot of office password advice is fifteen years out of date and working against you. Here's what to drop — forced monthly changes, complexity theatre, security questions — and the handful of things that actually stop an intruder.

Ask most offices about password policy and you'll hear the same rules: change it every 30 days, mix in a capital, a number and a symbol, and answer three security questions in case you forget. It sounds responsible. Much of it is actively making you less safe — and the guidance bodies that once recommended it have since reversed course.

Here's what to stop doing, and what to do instead.

Stop: forcing everyone to change passwords every month

Forced rotation feels prudent and backfires in practice. When people are made to change a password constantly, they don't invent strong new ones — they cycle predictable variants: Summer2026!, then Summer2026?, then Autumn2026!. An attacker who's seen one can guess the next. Modern guidance is clear: only force a change when there's evidence a password may be compromised. A strong password you keep beats a weak one you rotate.

Stop: complexity theatre

The P@ssw0rd! school of thought optimises for looking complex to a human while staying easy for a computer to crack. Length beats symbols. A memorable four-word passphrase — correct-battery-harbour-lamp — is both far harder to crack and far easier to remember than a short string of tortured substitutions. Set a sensible minimum length and let people breathe.

Stop: security questions

"Your first school," "mother's maiden name," "first car" — the answers are on social media, in public records, or guessable. Security questions are a second password that's weaker than the first. If a system offers them as recovery, they're a back door. Prefer real recovery: a verified email or phone, or an admin-assisted reset.

Start: the three that actually matter

  1. Turn on multi-factor authentication. This is the single highest-impact control there is. Even if a password leaks, MFA stops the login. Start with email and any remote access this week.
  2. Use a password manager. It's the honest fix for "strong and unique and remembered." One strong master password, everything else long, random and never reused. Reuse is what turns one breach into ten.
  3. Check your passwords against known breaches. Billions of leaked credentials are searchable. Knowing an old password is already out there is worth more than any complexity rule.

The one-line version

Stop punishing people with rules that push them toward weak, reused passwords. Make the strong path the easy path — a manager, long passphrases, and MFA everywhere it counts — and you'll be safer than any monthly-rotation policy ever made you.

If you'd like a plain-English review of your own access and password hygiene, that's part of what our cyber security team does. Get in touch — no jargon, no fear-selling.

Girish Manchanda

Founder, Alpha Web Innovations

Girish founded Alpha Web Innovations and works with organisations across India, the Middle East and Africa on print management, managed IT and cyber security.

Want help putting this into practice?

Alpha Web delivers print management, managed IT, cyber security and AI software across Asia, the Middle East and Africa.